CWE-922— Insecure Storage of Sensitive Information
The product stores sensitive information without properly limiting read or write access by unauthorized actors.— MITRE CWE catalog
399 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-922page 2 of 8
- CVE-2025-45242HIGHCVSS 7.7EG 7.72025-05-05
Rhymix v2.1.22 was discovered to contain an arbitrary file deletion vulnerability via the procFileAdminEditImage method in /file/file.admin.controller.php.
- CVE-2024-42018HIGHCVSS 7.7EG 7.72024-10-11
An issue was discovered in Atos Eviden SMC xScale before 1.6.6. During initialization of nodes, some configuration parameters are retrieved from management nodes. These parameters embed credentials whose integrity and confidentiality may b…
- CVE-2024-29968HIGHCVSS 7.7EG 7.72024-04-19
An information disclosure vulnerability exists in Brocade SANnav before v2.3.1 and v2.3.0a when Brocade SANnav instances are configured in disaster recovery mode. SQL Table names, column names, and SQL queries are collected in DR standby S…
- CVE-2020-5262HIGHCVSS 7.7EG 7.72020-03-19
In EasyBuild before version 4.1.2, the GitHub Personal Access Token (PAT) used by EasyBuild for the GitHub integration features (like `--new-pr`, `--fro,-pr`, etc.) is shown in plain text in EasyBuild debug log files. This issue is fixed i…
- CVE-2025-70963HIGHCVSS 7.6EG 7.62026-02-06
Gophish <=0.12.1 is vulnerable to Incorrect Access Control. The administrative dashboard exposes each user’s long-lived API key directly inside the rendered HTML/JavaScript of the page on every login. This makes permanent API credentials…
- CVE-2023-45859HIGHCVSS 7.6EG 7.62024-02-28
In Hazelcast through 4.1.10, 4.2 through 4.2.8, 5.0 through 5.0.5, 5.1 through 5.1.7, 5.2 through 5.2.4, and 5.3 through 5.3.2, some client operations don't check permissions properly, allowing authenticated users to access data stored in …
- CVE-2024-12315HIGHCVSS 7.5EG 7.52025-02-12
The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.3 via the exports directory. This makes it possible for unauthenticated …
- CVE-2024-57546HIGHCVSS 7.5EG 7.52025-01-27
An issue in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to the validate link function.
- CVE-2025-22984HIGHCVSS 7.5EG 7.52025-01-14
An access control issue in the component /api/squareComment/DelectSquareById of iceCMS v2.2.0 allows unauthenticated attackers to access sensitive information.
- CVE-2025-22983HIGHCVSS 7.5EG 7.52025-01-14
An access control issue in the component /square/getAllSquare/circle of iceCMS v2.2.0 allows unauthenticated attackers to access sensitive information.
- CVE-2024-56113HIGHCVSS 7.5EG 7.52025-01-09
Smart Toilet Lab - Motius 1.3.11 is running with debug mode turned on (DEBUG = True) and exposing sensitive information defined in Django settings file through verbose error page.
- CVE-2024-47043HIGHCVSS 7.5EG 7.52024-12-06
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could enable an attacker to correlate a device serial number and the user's phone number and part of the email address.
- CVE-2024-48939HIGHCVSS 7.5EG 7.52024-11-11
Insufficient validation performed on the REST API License file in Paxton Net2 before 6.07.14023.5015 (SR4) enables use of the REST API with an invalid License File. Attackers may be able to retrieve access-log data.
- CVE-2024-10028HIGHCVSS 7.5EG 7.52024-11-06
The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.13 via the exposed process stats file during …
- CVE-2024-48353HIGHCVSS 7.5EG 7.52024-11-01
Yealink Meeting Server before V26.0.0.67 allows attackers to obtain static key information from a front-end JS file and decrypt the plaintext passwords based on the obtained key information.
- CVE-2024-48352HIGHCVSS 7.5EG 7.52024-11-01
Yealink Meeting Server before V26.0.0.67 is vulnerable to sensitive data exposure in the server response via sending HTTP request with enterprise ID.
- CVE-2024-48783HIGHCVSS 7.5EG 7.52024-10-15
An issue in Ruijie NBR3000D-E Gateway allows a remote attacker to obtain sensitive information via the /tool/shell/postgresql.conf component.
- CVE-2024-47197HIGHCVSS 7.5EG 7.52024-09-26
Exposure of Sensitive Information to an Unauthorized Actor, Insecure Storage of Sensitive Information vulnerability in Maven Archetype Plugin. This issue affects Maven Archetype Plugin: from 3.2.1 before 3.3.0. Users are recommended to u…
- CVE-2024-39339HIGHCVSS 7.5EG 7.52024-09-18
A vulnerability has been discovered in all versions of Smartplay headunits, which are widely used in Suzuki and Toyota cars. This misconfiguration can lead to information disclosure, leaking sensitive details such as diagnostic log traces,…
- CVE-2024-37728HIGHCVSS 7.5EG 7.52024-09-10
Arbitrary File Read vulnerability in Xi'an Daxi Information Technology Co., Ltd OfficeWeb365 v.7.18.23.0 and v8.6.1.0 allows a remote attacker to obtain sensitive information via the "Pic/Indexes" interface
- CVE-2024-38453HIGHCVSS 7.5EG 7.52024-07-03
The Avalara for Salesforce CPQ app before 7.0 for Salesforce allows attackers to read an API key. NOTE: the current version is 11 as of mid-2024.
- CVE-2024-5598HIGHCVSS 7.5EG 7.52024-06-29
The Advanced File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.2.4 via the 'fma_local_file_system' function. This makes it possible for unauthenticated attackers to ex…
- CVE-2024-5599HIGHCVSS 7.5EG 7.52024-06-07
The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.7 via the 'fileorganizer_ajax_handler' function. This makes it possible…
- CVE-2024-22808HIGHCVSS 7.5EG 7.52024-04-22
An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to cause a Denial of Service (DoS) by disrupting the communication between the PathPilot controller and the CNC router via overwriting the card's name in t…
- CVE-2024-28069HIGHCVSS 7.5EG 7.52024-03-16
A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct an information disclosure attack due to improper configuration. A successful exploit could …
- CVE-2024-1936HIGHCVSS 7.5EG 7.52024-03-04
The encrypted subject of an email message could be incorrectly and permanently assigned to an arbitrary other email message in Thunderbird's local cache. Consequently, when replying to the contaminated email message, the user might acciden…
- CVE-2024-25728HIGHCVSS 7.5EG 7.52024-02-11
ExpressVPN before 12.73.0 on Windows, when split tunneling is used, sends DNS requests according to the Windows configuration (e.g., sends them to DNS servers operated by the user's ISP instead of to the ExpressVPN DNS servers), which may …
- CVE-2023-50298HIGHCVSS 7.5EG 7.52024-02-09
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr.This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.4.1. Solr Streaming Expressions allows users to extract data from other…
- CVE-2023-45184HIGHCVSS 7.5EG 7.52023-12-14
IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacker to obtain a decryption key due to improper authority checks. IBM X-Force ID: 268270.
- CVE-2023-41965HIGHCVSS 7.5EG 7.52023-09-18
Sending some requests in the web application of the vulnerable device allows information to be obtained due to the lack of security in the authentication process.
- CVE-2022-46484HIGHCVSS 7.5EG 7.52023-08-02
Information disclosure in password protected surveys in Data Illusion Survey Software Solutions NGSurvey v2.4.28 and below allows attackers to view the password to access and arbitrarily submit surveys.
- CVE-2023-3064HIGHCVSS 7.5EG 7.52023-06-05
Anonymous user may get the list of existing users managed by the application, that could ease further attacks (see CVE-2023-3065 and 3066)This issue affects Mobatime mobile application AMXGT100 through 1.3.20.
- CVE-2023-2665HIGHCVSS 7.5EG 7.52023-05-12
Storage of Sensitive Data in a Mechanism without Access Control in GitHub repository francoisjacquet/rosariosis prior to 11.0.
- CVE-2021-36546HIGHCVSS 7.5EG 7.52023-02-03
Incorrect Access Control issue discovered in KiteCMS 1.1 allows remote attackers to view sensitive information via path in application URL.
- CVE-2022-41876HIGHCVSS 7.5EG 7.52022-11-10
ezplatform-graphql is a GraphQL server implementation for Ibexa DXP and Ibexa Open Source. Versions prior to 2.3.12 and 1.0.13 are subject to Insecure Storage of Sensitive Information. Unauthenticated GraphQL queries for user accounts can …
- CVE-2022-37835HIGHCVSS 7.5EG 7.52022-09-12
Torguard VPN 4.8, has a vulnerability that allows an attacker to dump sensitive information, such as credentials and information about the server, without admin privileges.
- CVE-2022-35513HIGHCVSS 7.5EG 7.52022-09-07
The Blink1Control2 application <= 2.2.7 uses weak password encryption and an insecure method of storage.
- CVE-2022-28168HIGHCVSS 7.5EG 7.52022-06-27
In Brocade SANnav before Brocade SANnav v2.2.0.2 and Brocade SANnav2.1.1.8, encoded scp-server passwords are stored using Base64 encoding, which could allow an attacker able to access log files to easily decode the passwords.
- CVE-2022-25264HIGHCVSS 7.5EG 7.52022-02-25
In JetBrains TeamCity before 2021.2.3, environment variables of the "password" type could be logged in some cases.
- CVE-2021-42913HIGHCVSS 7.5EG 7.52021-12-20
The SyncThru Web Service on Samsung SCX-6x55X printers allows an attacker to gain access to a list of SMB users and cleartext passwords by reading the HTML source code. Authentication is not required.
- CVE-2021-39289HIGHCVSS 7.5EG 7.52021-08-23
Certain NetModule devices have Insecure Password Handling (cleartext or reversible encryption), These models with firmware before 4.3.0.113, 4.4.0.111, and 4.5.0.105 are affected: NB800, NB1600, NB1601, NB1800, NB1810, NB2700, NB2710, NB28…
- CVE-2021-36786HIGHCVSS 7.5EG 7.52021-08-13
The miniorange_saml (aka Miniorange Saml) extension before 1.4.3 for TYPO3 allows Sensitive Data Exposure of API credentials and private keys.
- CVE-2021-22914HIGHCVSS 7.5EG 7.52021-06-16
Citrix Cloud Connector before 6.31.0.62192 suffers from insecure storage of sensitive information due to sensitive information being stored in the Citrix Cloud Connector installation log files. Such information could be used by an maliciou…
- CVE-2021-25776HIGHCVSS 7.5EG 7.52021-02-03
In JetBrains TeamCity before 2020.2, an ECR token could be exposed in a build's parameters.
- CVE-2020-25966HIGHCVSS 7.5EG 7.52020-10-28
Sectona Spectra before 3.4.0 has a vulnerable SOAP API endpoint that leaks sensitive information about the configured assets without proper authentication. This could be used by unauthorized parties to get configured login credentials of t…
- CVE-2020-26104HIGHCVSS 7.5EG 7.52020-09-25
In cPanel before 88.0.3, an insecure SRS secret is used on a templated VM (SEC-552).
- CVE-2020-15775HIGHCVSS 7.5EG 7.52020-09-18
An issue was discovered in Gradle Enterprise 2017.1 - 2020.2.4. The /usage page of Gradle Enterprise conveys high level build information such as project names and build counts over time. This page is incorrectly viewable anonymously.
- CVE-2020-7000HIGHCVSS 7.5EG 7.52020-04-03
VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow an unauthenticated attacker to discover the cryptographic key from the web server and gain information about the login and the encryption/decryption mechanism, which…
- CVE-2019-20060HIGHCVSS 7.5EG 7.52020-02-10
MFScripts YetiShare v3.5.2 through v4.5.4 places sensitive information in the Referer header. If this leaks, then third parties may discover password-reset hashes, file-delete links, or other sensitive information.
- CVE-2019-12914HIGHCVSS 7.5EG 7.52019-07-17
Redbrick Shift through 3.4.3 allows an attacker to extract authentication tokens of services (such as Gmail, Outlook, etc.) used in the application.
Map vulnerabilities like CWE-922 to your infrastructure
EchelonGraph correlates every CVE — across CWE-922 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →