CWE-922
Insecure Storage of Sensitive Information
The product stores sensitive information without properly limiting read or write access by unauthorized actors.
373 vulnerabilities with CWE-922
CVE-2026-46511
HIGH
HAXcms: Mass Token Exfiltration and Cross-Tenant Hijack
CVE-2026-5515
MEDIUM
IBM App Connect Enterprise is vulnerable to a confidential disclosure
CVSS 5.5
CVE-2026-7257
MEDIUM
Zyxel WRE6505 v2 firmware V1.00(ABDV.3)C0 - Insecure Storage of Sensitive Information in Configuration File
CVSS 4.4
CVE-2026-40868
HIGH
kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token
CVSS 8.1
CVE-2026-26152
HIGH
Microsoft Cryptographic Services Elevation of Privilege Vulnerability
CVSS 7.0
CVE-2026-5666
MEDIUM
code-projects Online FIR System SQL Database Backup File complaints.sql sensitive information
CVSS 5.3
CVE-2026-5650
MEDIUM
code-projects Online Application System for Admission oas.sql sensitive information
CVSS 5.3
CVE-2026-33407
CRITICAL
Wallos: SSRF via HTTP Proxy Environment Variable
CVSS 9.1
CVE-2026-20629
MEDIUM
macOS Tahoe <26.3 - Info Disclosure
CVSS 5.5
CVE-2025-32751
MEDIUM
Dell PowerFlex Manager (Appliance) - Insecure Storage of Sensitive Information
CVSS 5.5
CVE-2025-32746
MEDIUM
Dell PowerFlex Manager (Appliance) - Insecure Storage of Sensitive Information
CVSS 4.0
CVE-2025-10734
MEDIUM
ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.12 - Unauthenticated Sensitive Information Exposure
CVSS 5.3
CVE-2025-10464
MEDIUM
Birtech Senseway <09022026 - Info Disclosure
CVSS 6.5
CVE-2025-70963
HIGH
gophish <= 0.12.1 - Incorrect Access Control and Insecure Storage of Sensitive API Keys
CVSS 7.6
CVE-2025-14376
HIGH
Verve Asset Manager - Info Disclosure
CVE-2025-10971
HIGH
MeetMe <= v2.2.5 - Insecure Storage of Sensitive Information
CVE-2025-12539
CRITICAL
WordPress TNC Toolbox: Web Performance <1.4.2 - Info Disclosure
CVSS 10.0
CVE-2025-61482
HIGH
NetKnights GmbH privacyIDEA Authenticator v.4.3.0 - Auth Bypass
CVSS 7.2
CVE-2025-60856
MEDIUM
Reolink Video Doorbell WiFi DB_566128M5MP_W - RCE
CVSS 6.8
CVE-2025-11645
LOW
Tomofun Furbo Mobile App <7.57.0a - Info Disclosure
CVSS 2.4
CVE-2025-11644
LOW
Furbo 360 Dog Camera Firmware < 036 and Furbo Mini Firmware < 074 - Sensitive Information Exposure via UART Interface
CVSS 2.0
CVE-2025-11639
LOW
Furbo 360 Dog Camera <036 & Mini <074 - Sensitive Information Exposure in Debug Log
CVSS 3.3
CVE-2025-21045
MEDIUM
Galaxy Watch <SMR Oct-2025 Release 1 - Info Disclosure
CVSS 4.0
CVE-2025-35054
MEDIUM
Newforma Info Exchange - Privilege Escalation
CVSS 5.3
CVE-2025-34189
HIGH
Vasion Print <1.0.735-20.0.1330 - Code Injection
CVSS 7.8
Details
Vulnerabilities
373