The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.
Volume of CVEs assigned to CWE-201 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
360 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-60188HIGH Insertion of Sensitive Information Into Sent Data vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Retrieve Embedded Sensitive Data.This issue affects Atarim: | Nov 6, 2025 | 7.5 | 46 | NO | YES |
CVE-2026-42880CRITICAL Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a missing authorization and data- | May 7, 2026 | 9.6 | 42 | NO | NO |
CVE-2025-62039HIGH Insertion of Sensitive Information Into Sent Data vulnerability in Ays Pro AI ChatBot with ChatGPT and Content Generator by AYS ays-chatgpt-assistant allows Retrieve Embedded Sensi | Nov 6, 2025 | 7.5 | 37 | NO | YES |
CVE-2026-13380CRITICAL VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthenticated endpoints. The credentials are present in these respo | Jul 20, 2026 | 9.0 | 36 | NO | NO |
CVE-2026-5483CRITICAL A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in the `odh-dashboard` component of Red Hat OpenShift AI (RHOAI) allows for the disclosure of Kubernet | Apr 10, 2026 | 9.9 | 36 | NO | NO |
CVE-2026-24477HIGH AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. If AnythingLLM prior to version 1.10.0 is configured to | Jan 27, 2026 | 7.5 | 36 | NO | YES |
CVE-2026-54848HIGH Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal APIExperts Square for WooCommerce allows Retrieve Embedded Sensitive Data.
This issue affects APIExpe | Jun 25, 2026 | 8.3 | 35 | NO | NO |
CVE-2025-41118CRITICAL Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Tencent Cloud Object Storage (COS).
If the database is configu | Apr 15, 2026 | 9.1 | 35 | NO | NO |
CVE-2026-7189HIGH Insertion of sensitive information into sent data vulnerability in Proliz Software Ltd. Co. Proliz's OBS allows Accessing Functionality Not Properly Constrained by ACLs.
This issu | Jul 17, 2026 | 7.5 | 34 | NO | NO |
CVE-2026-54821HIGH Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.3.1 versions. | Jun 25, 2026 | 7.4 | 34 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.