CWE-922— Insecure Storage of Sensitive Information
The product stores sensitive information without properly limiting read or write access by unauthorized actors.— MITRE CWE catalog
399 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-922page 1 of 8
- CVE-2025-12539CRITICALCVSS 10.0EG 10.02025-11-11
The TNC Toolbox: Web Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.2. This is due to the plugin storing cPanel API credentials (hostname, username, and API key) i…
- CVE-2023-32191CRITICALCVSS 9.9EG 9.92024-10-16
When RKE provisions a cluster, it stores the cluster state in a configmap called `full-cluster-state` inside the `kube-system` namespace of the cluster itself. The information available in there allows non-admin users to escalate to admin.
- CVE-2024-4995CRITICALCVSS 9.8EG 9.82024-12-18
Wapro ERP Desktop is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to data interception and modification. This issue affects Wapro ERP Desktop versions befor…
- CVE-2023-29727CRITICALCVSS 9.8EG 9.82023-05-30
The Call Blocker application 6.6.3 for Android allows unauthorized applications to use exposed components to delete data stored in its database that is related to user privacy settings and affects the implementation of the normal functiona…
- CVE-2021-42371CRITICALCVSS 9.8EG 9.82021-11-08
lpar2rrd is a hardcoded system account in XoruX LPAR2RRD and STOR2RRD before 7.30.
- CVE-2021-27170CRITICALCVSS 9.8EG 9.82021-02-10
An issue was discovered on FiberHome HG6245D devices through RP2613. By default, there are no firewall rules for IPv6 connectivity, exposing the internal management interfaces to the Internet.
- CVE-2020-8481CRITICALCVSS 9.8EG 9.82020-04-29
For ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Compact HMI versions 5.1 and 6.0, Control Builder Safe 1.0, 1.1 and 2.0, Symphony Plus -S+ Operations 3.0 to 3.2 Symphony Plus -S+ Engine…
- CVE-2017-5250CRITICALCVSS 9.8EG 9.82018-02-22
In version 1.9.7 and prior of Insteon's Insteon for Hub Android app, the OAuth token used by the app to authorize user access is not stored in an encrypted and secure manner.
- CVE-2017-5249CRITICALCVSS 9.8EG 9.82018-02-22
In version 6.1.0.19 and prior of Wink Labs's Wink - Smart Home Android app, the OAuth token used by the app to authorize user access is not stored in an encrypted and secure manner.
- CVE-2023-0580CRITICALCVSS 5.4EG 9.82023-04-06
Insecure Storage of Sensitive Information vulnerability in ABB My Control System (on-premise) allows an attacker who successfully exploited this vulnerability to gain access to the secure application data or take control of the applicatio…
- CVE-2024-7569CRITICALCVSS 9.6EG 9.62024-08-13
An information disclosure vulnerability in Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier allows an unauthenticated attacker to obtain the OIDC client secret via debug information.
- CVE-2021-28813CRITICALCVSS 9.6EG 9.62021-09-10
A vulnerability involving insecure storage of sensitive information has been reported to affect QSW-M2116P-2T2S and QNAP switches running QuNetSwitch. If exploited, this vulnerability allows remote attackers to read sensitive information b…
- CVE-2026-33407CRITICALCVSS 9.1EG 9.12026-03-24
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, Wallos endpoints/logos/search.php accepts HTTP_PROXY and HTTPS_PROXY environment variables without validation, enabling SSRF via proxy hijacking…
- CVE-2025-8699CRITICALCVSS 9.1EG 9.12025-09-12
Some "Stored Value" Unattended Payment Solutions of KioSoft use vulnerable NFC cards. Attackers could potentially use this vulnerability to change the balance on the cards and generate money. The account balance is stored on an insecure Mi…
- CVE-2024-53932CRITICALCVSS 9.1EG 9.12025-01-06
The com.remi.colorphone.callscreen.calltheme.callerscreen (aka Color Phone: Call Screen Theme) application through 21.1.9 for Android enables any application (with no permissions) to place phone calls without user interaction by sending a …
- CVE-2024-53931CRITICALCVSS 9.1EG 9.12025-01-06
The com.glitter.caller.screen (aka iCaller, Caller Theme & Dialer) application through 1.1 for Android enables any application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.glit…
- CVE-2024-30896CRITICALCVSS 9.1EG 9.12024-11-21
InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows authorized users with read access to the authorization resource of the default organization to retrieve the operator token…
- CVE-2024-10943CRITICALCVSS 9.1EG 9.12024-11-12
An authentication bypass vulnerability exists in the affected product. The vulnerability exists due to shared secrets across accounts and could allow a threat actor to impersonate a user if the threat actor is able to enumerate additional …
- CVE-2024-3502CRITICALCVSS 8.1EG 9.12024-11-14
In lunary-ai/lunary versions up to and including 1.2.5, an information disclosure vulnerability exists where account recovery hashes of users are inadvertently exposed to unauthorized actors. This issue occurs when authenticated users insp…
- CVE-2024-3501CRITICALCVSS 8.1EG 9.12024-11-14
In lunary-ai/lunary versions up to and including 1.2.5, an information disclosure vulnerability exists due to the inclusion of single-use tokens in the responses of `GET /v1/users/me` and `GET /v1/users/me/org` API endpoints. These tokens,…
- CVE-2025-10971HIGHCVSS 8.8EG 8.82025-12-02
Insecure Storage of Sensitive Information vulnerability in MeetMe on iOS, Android allows Retrieve Embedded Sensitive Data. This issue affects MeetMe: through v2.2.5.
- CVE-2025-28244HIGHCVSS 8.8EG 8.82025-07-10
Insecure Permissions vulnerability in the Local Storage in Alteryx Server 2023.1.1.460 allows remote attackers to obtain valid user session tokens from localStorage, leading to account takeover
- CVE-2023-42913HIGHCVSS 8.8EG 8.82024-03-28
This issue was addressed through improved state management. This issue is fixed in macOS Sonoma 14.2. Remote Login sessions may be able to obtain full disk access permissions.
- CVE-2023-43634HIGHCVSS 8.8EG 8.82023-09-21
When sealing/unsealing the “vault” key, a list of PCRs is used, which defines which PCRs are used. In a previous project, CYMOTIVE found that the configuration is not protected by the secure boot, and in response Zededa implemented m…
- CVE-2023-43633HIGHCVSS 8.8EG 8.82023-09-21
On boot, the Pillar eve container checks for the existence and content of “/config/GlobalConfig/global.json”. If the file exists, it overrides the existing configuration on the device on boot. This allows an attacker to change the s…
- CVE-2023-43631HIGHCVSS 8.8EG 8.82023-09-21
On boot, the Pillar eve container checks for the existence and content of “/config/authorized_keys”. If the file is present, and contains a supported public key, the container will go on to open port 22 and enable sshd with the given…
- CVE-2023-43630HIGHCVSS 8.8EG 8.82023-09-20
PCR14 is not in the list of PCRs that seal/unseal the “vault” key, but due to the change that was implemented in commit “7638364bc0acf8b5c481b5ce5fea11ad44ad7fd4”, fixing this issue alone would not solve the problem of the config p…
- CVE-2017-7253HIGHCVSS 8.8EG 8.82017-03-30
Dahua IP Camera devices 3.200.0001.6 can be exploited via these steps: 1. Use the default low-privilege credentials to list all users via a request to a certain URI. 2. Login to the IP camera with admin credentials so as to obtain full con…
- CVE-2026-46511HIGHCVSS 8.7EG 8.72026-05-19
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an attack chain utilizing Stored XSS alongside dynamic token exposure in the `/system/api/connectionSettings` endpoint allows an authenticated at…
- CVE-2025-14376HIGHCVSS 8.6EG 8.62026-01-20
A security issue was discovered within the legacy ADI server component of Verve Asset Manager, caused by plaintext secrets stored in environment variables on the ADI server. This component has been retired and has been optional since the …
- CVE-2020-13937HIGHCVSS 5.3EG 8.62020-10-19
Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3.0.0-alpha, 3.0.0-alpha2, 3.0.0-beta, 3.0.0, 3.0.1, 3.0.2, 3.1.0, 4.0.0-alpha has one restful api w…
- CVE-2026-5047HIGHCVSS 8.2EG 8.22026-10-08
A vulnerability in Brocade SANnav before 2.4.0b and 3.0.0 prints encoded passwords and authentication tokens in log files. The vulnerability could allow an authenticated attacker with access to the log file including the SANnav supportsa…
- CVE-2025-46627HIGHCVSS 8.2EG 8.22025-05-01
Use of weak credentials in the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated attacker to authenticate to the telnet service by calculating the root password based on easily-obtained device information. The password is based on the la…
- CVE-2025-2241HIGHCVSS 8.2EG 8.22025-03-17
A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. User…
- CVE-2024-37144HIGHCVSS 8.2EG 8.22024-12-10
Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8.1.0 (for RCM 3.8.x train) and prior to RCM 3.7.6.0 (for RCM 3.7.x train), Dell PowerFlex custom node using PowerFlex Ma…
- CVE-2024-48770HIGHCVSS 8.2EG 8.22024-10-11
An issue in Plug n Play Camera com.wisdomcity.zwave 1.1.0 allows a remote attacker to obtain sensitive information via the firmware update process.
- CVE-2022-44619HIGHCVSS 8.2EG 8.22023-05-10
Insecure storage of sensitive information in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2026-40868HIGHCVSS 8.1EG 8.12026-04-21
Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to 1.16.4, kyverno’s apiCall servicecall helper implicitly injects Authorization: Bearer ... using the kyverno controller serviceaccount token when a …
- CVE-2024-22773HIGHCVSS 8.1EG 8.12024-02-06
Intelbras Action RF 1200 routers 1.2.2 and earlier and Action RG 1200 routers 2.1.7 and earlier expose the Password in Cookie resulting in Login Bypass.
- CVE-2023-31150HIGHCVSS 8.0EG 8.02023-05-10
A Storing Passwords in a Recoverable Format vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) database system could allow an authenticated attacker to retrieve passwords. See SEL Service B…
- CVE-2026-44629HIGHCVSS 7.9EG 7.92026-08-27
Improper access control to the Synergis Softwire installation folder. This vulnerability affects Streamvault all-in-one appliances (SV-100E and SV-300E series) and Synergis Softwire installed on Windows servers.
- CVE-2025-34189HIGHCVSS 7.8EG 7.82025-09-19
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 1.0.735 and Application versions prior to 20.0.1330 (macOS/Linux client deployments) contain a vulnerability in the local inter-process communication (IPC) mecha…
- CVE-2023-32184HIGHCVSS 7.8EG 7.82023-09-19
A Insecure Storage of Sensitive Information vulnerability in openSUSE opensuse-welcome allows local attackers to execute code as the user that runs opensuse-welcome if a custom layout is chosen This issue affects opensuse-welcome: from 0.1…
- CVE-2023-29757HIGHCVSS 7.8EG 7.82023-06-09
An issue found in Blue Light Filter v.1.5.5 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the SharedPreference files.
- CVE-2023-29755HIGHCVSS 7.8EG 7.82023-06-09
An issue found in Twilight v.13.3 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the SharedPreference files.
- CVE-2020-8482HIGHCVSS 7.8EG 7.82020-05-29
Insecure storage of sensitive information in ABB Device Library Wizard versions 6.0.X, 6.0.3.1 and 6.0.3.2 allows unauthenticated low privilege user to read file that contains confidential data
- CVE-2019-5627HIGHCVSS 7.8EG 7.82019-05-22
The iOS mobile application BlueCats Reveal before 5.14 stores the username and password in the app cache as base64 encoded strings, i.e. clear text. These persist in the cache even if the user logs out. This can allow an attacker to compro…
- CVE-2019-5626HIGHCVSS 7.8EG 7.82019-05-22
The Android mobile application BlueCats Reveal before 3.0.19 stores the username and password in a clear text file. This file persists until the user logs out or the session times out from non-usage (30 days of no user activity). This can …
- CVE-2023-40728HIGHCVSS 7.3EG 7.82023-09-12
A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application stores sensitive application data in an external insecure storage. This could allow an attacker to alter conte…
- CVE-2025-37100HIGHCVSS 7.7EG 7.72025-06-10
A vulnerability in the APIs of HPE Aruba Networking Private 5G Core could potentially expose sensitive information to unauthorized users. A successful exploitation could allow an attacker to iteratively navigate through the filesystem an…
Map vulnerabilities like CWE-922 to your infrastructure
EchelonGraph correlates every CVE — across CWE-922 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →