A sensitive information leak issue has been discovered in GitLab EE affecting all versions starting from 16.0 before 16.
An issue has been discovered in GitLab EE affecting all versions starting from 14.1 before 16.0.8, all versions starting
An issue has been discovered in GitLab affecting all versions starting from 11.3 before 16.4.3, all versions starting fr
An issue has been discovered in GitLab DAST scanner affecting all versions starting from 3.0.29 before 4.0.5, in which t
An information disclosure vulnerability exists in the challenge functionality of instipod DuoUniversalKeycloakAuthentica
An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.0 before 16.3.6, all versions start
HashiCorp Nomad Enterprise 1.2.11 up to 1.5.6, and 1.4.10 ACL policies using a block without a label generates unexpecte
An issue has been discovered in GitLab EE affecting all versions starting from 15.7 before 15.10.8, all versions startin
ZGR TPS200 NG in its 2.00 firmware version and 1.01 hardware version, allows a remote attacker with access to the web ap
A CSRF token visible in the URL may possibly lead to information disclosure vulnerability.
BigBlueButton is an open source web conferencing system. Versions prior to 2.4-rc-6 are vulnerable to Insertion of Sensi
An information exposure vulnerability exists in the Palo Alto Networks GlobalProtect app on Windows and MacOS where the
Clusters using Calico (version 3.22.1 and below), Calico Enterprise (version 3.12.0 and below), may be vulnerable to rou
A vulnerability was found in the Linux kernel, where accessing a deallocated instance in printer_ioctl() printer_ioctl()
libcurl wrongly allows cookies to be set for Top Level Domains (TLDs) if thehost name is provided with a trailing dot.cu
Some Dahua software products have a vulnerability of sensitive information leakage. After obtaining the permissions of a
Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an a
Insertion of sensitive information into sent data vulnerability in synorelayd in Synology DiskStation Manager (DSM) befo
The NGINX Controller 2.0.0 thru 2.9.0 and 3.x before 3.15.0 Administrator password may be exposed in the systemd.txt fil
A flaw was found in the xdg-email component of xdg-utils-1.1.0-rc1 and newer. When handling mailto: URIs, xdg-email allo
A vulnerability in the CLI parser of Cisco IOS XR Software could allow an authenticated, local attacker to view more inf
A vulnerability in the Cisco IOS XR Software CLI could allow an authenticated, local attacker to view more information t
A vulnerability in the authentication for the general purpose APIs implementation of Cisco Email Security Appliance (ESA
Nextcloud Server is a Nextcloud package that handles data storage. Nextcloud Server versions prior to 19.0.11, 20.0.10,
Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an a
Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an a
Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an a
Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an a
Clusters using Calico (version 3.14.0 and below), Calico Enterprise (version 2.8.2 and below), may be vulnerable to info
Dell EMC Isilon OneFS versions 8.2.2 and earlier contain an SNMPv2 vulnerability. The SNMPv2 services is enabled, by def
The participants table download in Moodle always included user emails, but should have only done so when users' emails a
When user downloads PGP or S/MIME keys/certificates, exported file has same name for private and public keys. Therefore
All trailer Power Line Communications are affected. PLC bus traffic can be sniffed reliably via an active antenna up to
Support bundle generated files could contain sensitive information that might be unwanted to be disclosed. This issue af
An information exposure vulnerability exists in gitlab.com <v12.3.2, <v12.2.6, and <v12.1.10 when using the blocking mer
A vulnerability was found in 3scale before version 2.6, did not set the HTTPOnly attribute on the user session cookie. A
Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are us
A vulnerability was found in the ping functionality of the ws module before 1.0.0 which allowed clients to allocate memo
A security issue was found in bittorrent-dht before 5.1.3 that allows someone to send a specific series of messages to a
It was found that while parsing the SAML messages the StaxParserUtil class of keycloak before 2.5.1 replaces special str
Request is an http client. If a request is made using ```multipart```, and the body type is a ```number```, then the spe
Frequently Asked Questions
What is CWE-201?
CWE-201 (CWE-201) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-201?
There are 396 CVE records associated with CWE-201 in our database. Of these, 12 are critical severity, 103 are high severity, and 244 are medium severity.
How can I protect against CWE-201 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-201 using AI-powered security agents.
Detect CWE-201 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-201 vulnerabilities across your infrastructure.
Get Started