CWE-212

Improper Removal of Sensitive Information Before Storage or Transfer

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.

115 vulnerabilities with CWE-212
CVE-2026-54421 MEDIUM
Openstack Ironic < 35.0.1 - Improper Removal of Sensitive Information Before Storage or Transfer
CVSS 6.8
CVE-2026-46657 HIGH
Bludit's persistent authentication tokens not revoked upon account disablement
CVSS 7.1
CVE-2026-36178 MEDIUM
GNCC GP5 7.1.76 - Sensitive Data Exposure via Incomplete Factory Reset
CVSS 4.6
CVE-2026-45046 MEDIUM
Gryph Agents Payload Filter Fails to Strip Tool Payload for Sensitive Content
CVSS 5.5
CVE-2026-27892 MEDIUM
FacturaScripts: Unstripped Image Metadata (EXIF) Leakage via Library Module File Upload/Download
CVSS 6.5
CVE-2026-42186 HIGH
OpenBao's Namespace Deletion May Not Delete Data Properly
CVSS 7.5
CVE-2026-42880 CRITICAL
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction
CVSS 9.6
CVE-2026-43528 MEDIUM
OpenClaw < 2026.4.14 - Redaction Bypass via sourceConfig and runtimeConfig Aliases
CVSS 6.5
CVE-2026-43824 HIGH
Argo CD 3.2.0-3.2.11 - Info Disclosure
CVSS 7.7
CVE-2026-20928 MEDIUM
Windows Recovery Environment Security Feature Bypass Vulnerability
CVSS 4.6
CVE-2026-39937 HIGH
Global vanishing does not completely remove user email
CVE-2026-34214 HIGH
Trino: Iceberg REST catalog static and vended credentials are accessible via query JSON
CVSS 7.7
CVE-2026-32891 CRITICAL
Anchorr Privilege Escalation: Jellyseerr User → Anchorr Admin via Stored XSS
CVSS 9.0
CVE-2026-1182 MEDIUM
GitLab 8.14.0-18.7.5, 18.8.0-18.8.5, 18.9.0-18.9.1 - Authenticated Unauthorized Access to Confidential Issue Titles
CVSS 4.3
CVE-2026-1732 MEDIUM
GitLab 12.6-18.7.5, 18.8-18.8.5, 18.9-18.9.1 - Authenticated Confidential Issue Title Disclosure via Improper Filtering
CVSS 4.3
CVE-2026-27640 HIGH
tfplan2md <1.26.1 - Info Disclosure
CVSS 7.5
CVE-2025-8860 LOW
Red Hat Enterprise Linux 6-9 - Information Disclosure via QEMU uefi-vars Device Buffer Reuse
CVSS 3.3
CVE-2025-61643 MEDIUM
MediaWiki <1.39.14, 1.43.4, 1.44.1 - Info Disclosure
CVSS 6.1
CVE-2025-59955 MEDIUM
Coolify <= 4.0.0-beta.420.8 - Authenticated Information Disclosure via Team Members API
CVSS 5.7
CVE-2025-68131 HIGH
cbor2 3.0.0-5.7.9 - Information Exposure via Shared Reference Tag
CVSS 7.5
CVE-2025-61594 HIGH
URI < 0.12.5, 0.13.0-0.13.2, 1.0.0-1.0.3 - Exposure of Sensitive Information via URI Combination Operator
CVSS 7.5
CVE-2025-14267 MEDIUM
M-Files Server <25.12.15491.7 - Info Disclosure
CVSS 4.9
CVE-2025-65000 MEDIUM
Checkmk <=2.4.0p18, <=2.3.0 - Info Disclosure
CVSS 5.3
CVE-2025-65965 HIGH
Grype 0.68.0-0.104.0 - Credential Disclosure via JSON Output File
CVE-2025-62483 MEDIUM
Zoom Client <6.5.10 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities 115