CWE-212— Improper Removal of Sensitive Information Before Storage or Transfer
The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.— MITRE CWE catalog
134 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-212page 1 of 3
- CVE-2022-2818CRITICALCVSS 9.8EG 9.82022-08-15
Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository cockpit-hq/cockpit prior to 2.2.2.
- CVE-2026-42880CRITICALCVSS 9.6EG 9.62026-05-07
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a missing authorization and data-masking gap in Argo CD's ServerSideDiff endpoint that allow…
- CVE-2020-11684CRITICALCVSS 9.1EG 9.12020-09-14
AT91bootstrap before 3.9.2 does not properly wipe encryption and authentication keys from memory before passing control to a less privileged software component. This can be exploited to disclose these keys and subsequently encrypt and sign…
- CVE-2026-32891CRITICALCVSS 9.0EG 9.02026-03-20
Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media server. Versions 1.4.1 and below contain a stored XSS vulnerability in the Jellyseerr user selector. Jellyseerr allows …
- CVE-2026-85094HIGHCVSS 8.8EG 8.82026-09-04
The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.
- CVE-2026-39937HIGHCVSS 8.8EG 8.82026-04-07
Improper removal of sensitive information before storage or transfer vulnerability in The Wikimedia Foundation Mediawiki - CentralAuth Extension allows Resource Leak Exposure. The issue has been remediated on the `master` branch, and in t…
- CVE-2022-30617HIGHCVSS 8.8EG 8.82022-05-19
An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, for other admin panel users that have a relationship (e.g., created by, updated by) with content acce…
- CVE-2022-0355HIGHCVSS 8.8EG 8.82022-01-26
Improper Removal of Sensitive Information Before Storage or Transfer in NPM simple-get prior to 4.0.1.
- CVE-2021-0340HIGHCVSS 8.8EG 8.82021-02-10
In parseNextBox of IsoInterface.java, there is a possible leak of unredacted location information due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User inter…
- CVE-2019-13402HIGHCVSS 8.8EG 8.82019-07-08
/usr/sbin/default.sh and /usr/apache/htdocs/cgi-bin/admin/hardfactorydefault.cgi on Dynacolor FCM-MB40 v1.2.0.0 devices implement an incomplete factory-reset process. A backdoor can persist because neither system accounts nor the set of se…
- CVE-2022-39393HIGHCVSS 8.6EG 8.62022-11-10
Wasmtime is a standalone runtime for WebAssembly. Prior to versions 2.0.2 and 1.0.2, there is a bug in Wasmtime's implementation of its pooling instance allocator where when a linear memory is reused for another instance the initial heap s…
- CVE-2025-65965HIGHCVSS 8.2EG 8.22025-11-25
Grype is a vulnerability scanner for container images and filesystems. A credential disclosure vulnerability was found in Grype, affecting versions 0.68.0 through 0.104.0. If registry credentials are defined and the output of grype is writ…
- CVE-2022-31112HIGHCVSS 8.2EG 8.22022-06-30
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In affected versions parse Server LiveQuery does not remove protected fields in classes, passing them to the client. The LiveQueryContr…
- CVE-2022-4734HIGHCVSS 8.1EG 8.12022-12-27
Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository usememos/memos prior to 0.9.1.
- CVE-2022-1650HIGHCVSS 8.1EG 8.12022-05-12
Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository eventsource/eventsource prior to v2.0.2.
- CVE-2019-11243HIGHCVSS 8.1EG 8.12019-04-22
In Kubernetes v1.12.0-v1.12.4 and v1.13.0, the rest.AnonymousClientConfig() method returns a copy of the provided config, with credentials removed (bearer token, username/password, and client certificate/key data). In the affected versions…
- CVE-2024-43384HIGHCVSS 8.0EG 8.02026-05-07
A low privileged remote attacker can gain the root password due to improper removal of sensitive information before storage or transfer.
- CVE-2020-15094HIGHCVSS 8.0EG 8.02020-09-02
In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient class from the HttpClient Symfony component relies on the HttpCache class to handle requests. HttpCache uses internal headers like X-Body-Eval and X-Body-File to control th…
- CVE-2026-43824HIGHCVSS 7.7EG 7.72026-05-02
In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data.
- CVE-2022-31090HIGHCVSS 7.7EG 7.72022-06-27
Guzzle, an extensible PHP HTTP client. `Authorization` headers on requests are sensitive information. In affected versions when using our Curl handler, it is possible to use the `CURLOPT_HTTPAUTH` option to specify an `Authorization` heade…
- CVE-2026-42186HIGHCVSS 7.5EG 7.52026-05-14
OpenBao is an open source identity-based secrets management system. Prior to 2.5.3, when OpenBao's initial namespace deletion fails, subsequent retries fail to properly remove all data before marking the namespace as deleted. This can affe…
- CVE-2026-40895HIGHCVSS 7.5EG 7.52026-04-21
follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. Prior to 1.16.0, when an HTTP request follows a cross-domain redirect (301/302/307/308), follow-redirects o…
- CVE-2026-27640HIGHCVSS 7.5EG 7.52026-02-25
tfplan2md is software for converting Terraform plan JSON files into human-readable Markdown reports. Prior to version 1.26.1, a bug in tfplan2md affected several distinct rendering paths: AzApi resource body properties, AzureDevOps variabl…
- CVE-2025-68131HIGHCVSS 7.5EG 7.52025-12-31
cbor2 provides encoding and decoding for the Concise Binary Object Representation (CBOR) serialization format. Starting in version 3.0.0 and prior to version 5.8.0, whhen a CBORDecoder instance is reused across multiple decode operations, …
- CVE-2025-61594HIGHCVSS 7.5EG 7.52025-12-30
URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) 0.13.2 and earlier (bundled in Ruby 3.3 series), 1.0.3 and earlier (bundled in Ruby 3.4 series), when usi…
- CVE-2025-62483HIGHCVSS 7.5EG 7.52025-11-13
Improper removal of sensitive information in certain Zoom Clients before version 6.5.10 may allow an unauthenticated user to conduct a disclosure of information via network access.
- CVE-2025-58049HIGHCVSS 7.5EG 7.52025-08-28
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions from 14.4.2 to before 16.4.8, 16.5.0-rc-1 to before 16.10.7, and 17.0.0-rc-1 to before 17.4.0-rc-1, the PDF export jobs st…
- CVE-2024-8474HIGHCVSS 7.5EG 7.52025-01-06
OpenVPN Connect before version 3.5.0 can contain the configuration profile's clear-text private key which is logged in the application log, which an unauthorized actor can use to decrypt the VPN traffic
- CVE-2024-49997HIGHCVSS 7.5EG 7.52024-10-21
In the Linux kernel, the following vulnerability has been resolved: net: ethernet: lantiq_etop: fix memory disclosure When applying padding, the buffer is not zeroed, which results in memory disclosure. The mentioned data is observed on …
- CVE-2023-52376HIGHCVSS 7.5EG 7.52024-02-18
Information management vulnerability in the Gallery module.Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2022-3460HIGHCVSS 7.5EG 7.52023-01-03
In affected versions of Octopus Deploy it is possible for certain types of sensitive variables to inadvertently become unmasked when viewed in variable preview.
- CVE-2022-31162HIGHCVSS 7.5EG 7.52022-07-22
Slack Morphism is an async client library for Rust. Prior to 0.41.0, it was possible for Slack OAuth client information to leak in application debug logs. Stricter and more secure debug formatting was introduced in v0.41.0 for OAuth secret…
- CVE-2021-46813HIGHCVSS 7.5EG 7.52022-06-13
Vulnerability of residual files not being deleted after an update in the ChinaDRM module. Successful exploitation of this vulnerability may affect availability.
- CVE-2022-31043HIGHCVSS 7.5EG 7.52022-06-10
Guzzle is an open source PHP HTTP client. In affected versions `Authorization` headers on requests are sensitive information. On making a request using the `https` scheme to a server which responds with a redirect to a URI with the `http` …
- CVE-2022-31042HIGHCVSS 7.5EG 7.52022-06-10
Guzzle is an open source PHP HTTP client. In affected versions the `Cookie` headers on requests are sensitive information. On making a request using the `https` scheme to a server which responds with a redirect to a URI with the `http` sch…
- CVE-2022-30618HIGHCVSS 7.5EG 7.52022-05-19
An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, for API users if content types accessible to the authenticated user contain relationships to API user…
- CVE-2022-24798HIGHCVSS 7.5EG 7.52022-03-31
Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL format. IRRd did not always filter password hashes in query responses relating to `mntner` objects and database exports. This may have…
- CVE-2020-36476HIGHCVSS 7.5EG 7.52021-08-23
An issue was discovered in Mbed TLS before 2.24.0 (and before 2.16.8 LTS and before 2.7.17 LTS). There is missing zeroization of plaintext buffers in mbedtls_ssl_read to erase unused application data from memory.
- CVE-2021-31780HIGHCVSS 7.5EG 7.52021-04-23
In app/Model/MispObject.php in MISP 2.4.141, an incorrect sharing group association could lead to information disclosure on an event edit. When an object has a sharing group associated with an event edit, the sharing group object is ignore…
- CVE-2019-20637HIGHCVSS 7.5EG 7.52020-04-08
An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This s…
- CVE-2020-1940HIGHCVSS 7.5EG 7.52020-01-28
The optional initial password change and password expiration features present in Apache Jackrabbit Oak 1.2.0 to 1.22.0 are prone to a sensitive information disclosure vulnerability. The code mandates the changed password to be passed as an…
- CVE-2018-6337HIGHCVSS 7.5EG 7.52018-12-31
folly::secureRandom will re-use a buffer between parent and child processes when fork() is called. That will result in multiple forked children producing repeat (or similar) results. This affects HHVM 3.26 prior to 3.26.3 and the folly lib…
- CVE-2002-0704HIGHCVSS 7.5EG 7.52002-07-26
The Network Address Translation (NAT) capability for Netfilter ("iptables") 1.2.6a and earlier leaks translated IP addresses in ICMP error messages.
- CVE-2022-23633HIGHCVSS 7.4EG 7.42022-02-11
Action Pack is a framework for handling and responding to web requests. Under certain circumstances response bodies will not be closed. In the event a response is *not* notified of a `close`, `ActionDispatch::Executor` will not know to res…
- CVE-2017-15113HIGHCVSS 7.2EG 7.22018-07-27
ovirt-engine before version 4.1.7.6 with log level set to DEBUG includes passwords in the log file without masking. Only administrators can change the log level and only administrators can access the logs. This presents a risk when debug-l…
- CVE-2026-90860HIGHCVSS 7.1EG 7.12026-09-21
The Canva Mobile App for HarmonyOS before v1.15.1 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.
- CVE-2026-53604HIGHCVSS 7.1EG 7.12026-07-14
nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.8, the web handler renderMobileBundle passes the real *pki.CAResolver directly into mobilebundle.Build. Inside Build, resolver.LoadByID decrypts the…
- CVE-2026-46657HIGHCVSS 7.1EG 7.12026-06-08
Bludit is a content management system. Versions prior to 3.22.0 have a vulnerability in the user management logic that allows deactivated accounts to maintain access via persistent authentication tokens. When an administrator disables a us…
- CVE-2022-33740HIGHCVSS 7.1EG 7.12022-07-05
Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions befo…
- CVE-2026-96879MEDIUMCVSS 6.9EG 6.92026-09-25
Improper removal of sensitive information before storage or transfer vulnerability in Wikimedia Foundation's Mediawiki - FlaggedRevs extension through 1.46.0.
Map vulnerabilities like CWE-212 to your infrastructure
EchelonGraph correlates every CVE — across CWE-212 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →