CVEs classified under CWE-201, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (50)
CVE-2025-49408 — CVSS 10.0 (critical): Insertion of Sensitive Information Into Sent Data vulnerability in WPDeveloper Templately allows Retrieve Embedded Sensitive Data. This…
CVE-2024-7205: When the device is shared, the homepage module are before 2.19.0 in eWeLink Cloud Service allows Secondary user to take over devices as…
CVE-2026-8924 — CVSS 9.1 (critical): A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set "super cookies" that bypass the Public Suffix List check…
CVE-2026-39912 — CVSS 9.1 (critical): V2Board 1.6.1 through 1.7.4 and Xboard through 0.1.9 expose authentication tokens in HTTP response bodies of the loginWithMailLink endpoint…
CVE-2025-48749 — CVSS 9.1 (critical): Netwrix Directory Manager (formerly Imanami GroupID) v11.0.0.0 and before & after v.11.1.25134.03 inserts Sensitive Information into Sent…
CVE-2025-11500: Tinycontrol devices such as tcPDU and LAN Controllers LK3.5, LK3.9 and LK4 have two separate authentication mechanisms - one solely for…
CVE-2025-48045: An unauthenticated HTTP GET request to the /client.php endpoint will disclose the default administrator user credentials.
CVE-2026-67425 — CVSS 8.6 (high): Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, llm.chat reads provider keys such as…
CVE-2026-6267 — CVSS 8.5 (high): GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1…
CVE-2026-5483 — CVSS 8.5 (high): A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in the `odh-dashboard` component of Red Hat OpenShift AI…
CVE-2023-3399 — CVSS 8.5 (high): An issue has been discovered in GitLab EE affecting all versions starting from 11.6 before 16.3.6, all versions starting from 16.4 before…
CVE-2026-101322: In Eclipse BaSyx AAS Web UI versions v2-241220 through releases before v2-260924, the shared request handler attached the selected…
CVE-2026-54848 — CVSS 8.3 (high): Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal APIExperts Square for WooCommerce allows Retrieve Embedded…
CVE-2026-46481 — CVSS 8.3 (high): OpenMetadata is a unified metadata platform. Prior to version 1.12.4, a non-admin SSO user can trigger a TEST_CONNECTION workflow for a…
CVE-2025-58098 — CVSS 8.3 (high): Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query…
CVE-2025-24858: Develocity (formerly Gradle Enterprise) before 2024.3.1 allows an attacker who has network access to a Develocity server to obtain the…
CVE-2026-82209 — CVSS 8.2 (high): When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where…
CVE-2025-66566: yawkat LZ4 Java provides LZ4 compression for Java. Insufficient clearing of the output buffer in Java-based decompressor implementations in…
CVE-2025-3529 — CVSS 8.2 (high): The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and…
CVE-2024-3502 — CVSS 8.1 (high): In lunary-ai/lunary versions up to and including 1.2.5, an information disclosure vulnerability exists where account recovery hashes of…
CVE-2024-8890 — CVSS 8.0 (high): An attacker with access to the network where the CIRCUTOR Q-SMT is located in its firmware version 1.0.4, could obtain legitimate…
CVE-2026-105849: Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before…
CVE-2026-4035 — CVSS 7.7 (high): A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolution of environment variables in AI Gateway secrets, which…
CVE-2026-42379 — CVSS 7.7 (high): Insertion of Sensitive Information Into Sent Data vulnerability in WPDeveloper Templately allows Retrieve Embedded Sensitive Data.This…
CVE-2026-40161 — CVSS 7.7 (high): Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions…
CVE-2025-66035: Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior…
CVE-2025-9958 — CVSS 7.7 (high): An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1…
CVE-2025-43768 — CVSS 7.7 (high): Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through…
CVE-2024-23506 — CVSS 7.7 (high): Insertion of Sensitive Information Into Sent Data vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP…
CVE-2024-7872 — CVSS 7.6 (high): Insertion of Sensitive Information Into Sent Data vulnerability in ExtremePACS Extreme XDS allows Retrieve Embedded Sensitive Data. This…
CVE-2023-28117 — CVSS 7.6 (high): Sentry SDK is the official Python SDK for Sentry, real-time crash reporting software. When using the Django integration of versions prior…
CVE-2026-42413 — CVSS 7.5 (high): Unauthenticated Sensitive Data Exposure in Snapshotify – All-in-One Backup & Restore & Migrate <= 1.3.2 versions.
CVE-2026-103334 — CVSS 7.5 (high): Insertion of Sensitive Information Into Sent Data vulnerability in Etoile Web Design Incorporated Five Star Restaurant Reservations…
CVE-2026-97307 — CVSS 7.5 (high): Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Cost Calculator Builder cost-calculator-builder allows…
CVE-2026-86450 — CVSS 7.5 (high): Insertion of sensitive information into sent data vulnerability in Parla Auto Automotive Trading Limited Company DetaWix Mobile Web Portal…
CVE-2026-78336 — CVSS 7.5 (high): Insertion of sensitive information into sent data vulnerability in Apache Syncope. Any authenticated user can query for the list of…
CVE-2026-81804 — CVSS 7.5 (high): Unauthenticated Sensitive Data Exposure in ZHBackup – Backup, Restore & Migration <= 2.4.2 versions.
CVE-2026-80255 — CVSS 7.5 (high): A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute…
CVE-2026-75953 — CVSS 7.5 (high): Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 - Recipient address was taken from the request…
CVE-2026-73386 — CVSS 7.5 (high): Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users Using Contact Form 7 <= 3.0.2 versions.