CWE-223— Omission of Security-relevant Information
The product does not record or display information that would be important for identifying the source or nature of an attack, or determining if an action is safe.— MITRE CWE catalog
10 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-223page 1 of 1
- CVE-2022-22563MEDIUMCVSS 4.4EG 4.42022-04-08
Dell EMC Powerscale OneFS 8.2.x - 9.2.x omit security-relevant information in /etc/master.passwd. A high-privileged user can exploit this vulnerability to not record information identifying the source of account information changes.
- CVE-2022-44646MEDIUMCVSS 2.2EG 5.32022-11-03
In JetBrains TeamCity version before 2022.10, no audit items were added upon editing a user's settings
- CVE-2023-28360MEDIUMCVSS 4.3EG 4.32023-05-11
An omission of security-relevant information vulnerability exists in Brave desktop prior to version 1.48.171 when a user was saving a file there was no download safety check dialog presented to the user.
- CVE-2023-29156MEDIUMCVSS 4.7EG 4.72023-07-11
DroneScout ds230 Remote ID receiver from BlueMark Innovations is affected by an information loss vulnerability through traffic injection. An attacker can exploit this vulnerability by injecting, at the right times, spoofed Open Drone ID …
- CVE-2023-31191CRITICALCVSS 9.3EG 9.32023-07-11
DroneScout ds230 Remote ID receiver from BlueMark Innovations is affected by an information loss vulnerability through traffic injection. An attacker can exploit this vulnerability by injecting, on carefully selected channels, high power …
- CVE-2024-52813MEDIUMCVSS 4.3EG 4.32025-01-07
matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. Versions of the matrix-sdk-crypto Rust crate before 0.8.0 lack a dedicated mechanism to notify that a user's cryptographic identity has changed from a verified…
- CVE-2025-35987MEDIUMCVSS 4.3EG 4.32026-08-11
Omission of security-relevant information for some Intel(R) Software Guard Extensions Data Center Attestation Primitives within Ring 0: Kernel may allow a denial of service. Authorized adversary with a privileged user combined with a high …
- CVE-2025-52926LOWCVSS 2.7EG 2.72025-06-23
In scan.rs in spytrap-adb before 0.3.5, matches for known stalkerware are not rendered in the interactive user interface.
- CVE-2026-31890MEDIUMCVSS 5.5EG 5.52026-03-12
Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. Prior to 0.50.1, in a situation where the ring-buffer of a gadget is – incidentally or maliciou…
- CVE-2026-49426UnratedEG not assessed2026-08-19
When auditing a system call executed via ptrace(PT_SC_REMOTE), the kernel passed the return value of an internal setup function to AUDIT_SYSCALL_EXIT() rather than the actual result of the executed system call. As a result, committed audi…
Map vulnerabilities like CWE-223 to your infrastructure
EchelonGraph correlates every CVE — across CWE-223 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →