Skip to main content

CWE archive

CWE-201 CVEs

Programmatic archive

359 CVEs tagged with CWE-20114 Critical, 94 High, 232 Medium, 18 Low, 1 Unrated.

CVE-2025-48261

Published Jun 9, 2025

Insertion of Sensitive Information Into Sent Data vulnerability in MultiVendorX MultiVendorX dc-woocommerce-multi-vendor allows Retrieve Embedded Sensitive Data.This issue affects…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-49294

Published Jun 6, 2025

Insertion of Sensitive Information Into Sent Data vulnerability in CodeRevolution Crawlomatic Multisite Scraper Post Generator crawlomatic-multipage-scraper-post-generator allows…

CVSS 5.3 · Medium

CVE-2025-5733

Published Jun 6, 2025

The Modern Events Calendar Lite plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 7.21.9. This is due improper or insufficient valid…

CVSS 5.3 · Medium

CVE-2025-48934

Published Jun 4, 2025

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to versions 2.1.13 and 2.2.13, the `Deno.env.toObject` method ignores any variables listed in the `--deny-env` opt…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-31134

Published Jun 4, 2025

FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, an attacker can gain additional information about the server by checking if certain directories exist. An a…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-48996

Published Jun 2, 2025

HAX open-apis provides microservice apis for HAX webcomponents repo that are shared infrastructure calls. An unauthenticated information disclosure vulnerability exists in the Pen…

CVSS 5.3 · Medium

CVE-2025-48331

Published May 30, 2025

Insertion of Sensitive Information Into Sent Data vulnerability in vanquish WooCommerce Orders & Customers Exporter woocommerce-orders-customers-exporter allows Retrieve Embedded…

CVSS 7.5 · High

CVE-2025-48381

Published May 30, 2025

Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. In versions starting from 2.4.0 to before 2.38.0, an authenticated CV…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-48045

Published May 29, 2025

An unauthenticated HTTP GET request to the /client.php endpoint will disclose the default administrator user credentials.

CVSS 8.7 · High

CVE-2025-48749

Published May 28, 2025

Netwrix Directory Manager (formerly Imanami GroupID) v11.0.0.0 and before & after v.11.1.25134.03 inserts Sensitive Information into Sent Data.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-39498

Published May 26, 2025

Insertion of Sensitive Information Into Sent Data vulnerability in Spotlight Spotlight - Social Media Feeds (Premium) allows Retrieve Embedded Sensitive Data.This issue affects Sp…

CVSS 5.3 · Medium

CVE-2025-47541

Published May 23, 2025

Insertion of Sensitive Information Into Sent Data vulnerability in WPFunnels Mail Mint mail-mint allows Retrieve Embedded Sensitive Data.This issue affects Mail Mint: from n/a thr…

CVSS 7.5 · High

CVE-2025-48219

Published May 18, 2025

O2 UK before 2025-05-19 allows subscribers to determine the Cell ID of other subscribers by initiating an IMS (IP Multimedia Subsystem) call and then reading the utran-cell-id-3gp…

CVSS 3.5 · Low

CVE-2025-47775

Published May 14, 2025

Bullfrog is a GithHb Action to block unauthorized outbound traffic in GitHub workflows. Prior to version 0.8.4, using tcp breaks blocking and allows DNS exfiltration. This can res…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-3529

Published Apr 23, 2025

The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.1.2 via the 'file_url' parameter. T…

CVSS 8.2 · High

CVE-2025-32635

Published Apr 17, 2025

Insertion of Sensitive Information Into Sent Data vulnerability in Hive Support Hive Support hive-support allows Retrieve Embedded Sensitive Data.This issue affects Hive Support:…

CVSS 7.5 · High

CVE-2025-32594

Published Apr 17, 2025

Insertion of Sensitive Information Into Sent Data vulnerability in WPMinds Simple WP Events simple-wp-events allows Retrieve Embedded Sensitive Data.This issue affects Simple WP E…

CVSS 7.5 · High

CVE-2025-26335

Published Apr 11, 2025

Dell PowerProtect Cyber Recovery, versions prior to 19.18.0.2, contains an Insertion of Sensitive Information Into Sent Data vulnerability. A high privileged attacker with remote…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-27244

Published Apr 2, 2025

AssetView and AssetView CLOUD contain an issue with acquiring sensitive information from sent data to the developer. If exploited, sensitive information may be obtained by a remot…

CVSS 5.9 · Medium

CVE-2025-31842

Published Apr 1, 2025

Insertion of Sensitive Information Into Sent Data vulnerability in viralloops Viral Loops WP Integration viral-loops-wp-integration allows Retrieve Embedded Sensitive Data.This is…

CVSS 5.3 · Medium

CVE-2025-27001

Published Mar 28, 2025

Insertion of Sensitive Information Into Sent Data vulnerability in Shipmondo Shipmondo – A complete shipping solution for WooCommerce pakkelabels-for-woocommerce allows Retrieve E…

CVSS 6.5 · Medium

CVE-2025-30609

Published Mar 24, 2025

Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal AppExperts appexperts allows Retrieve Embedded Sensitive Data.This issue affects AppExperts: from n/a…

CVSS 5.3 · Medium

CVE-2024-7872

Published Mar 6, 2025

Insertion of Sensitive Information Into Sent Data vulnerability in ExtremePACS Extreme XDS allows Retrieve Embedded Sensitive Data. This issue affects Extreme XDS: before 3933.

CVSS 7.6 · High

CVE-2025-26318

Published Mar 4, 2025

hb.exe in TSplus Remote Access before 17.30 2024-10-30 allows remote attackers to retrieve a list of all domain accounts currently connected to the application.

CVSS 5.8 · Medium
Showing 226-250 of 359 CVEsPage 10 of 15