CWE-922

Insecure Storage of Sensitive Information

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

368 vulnerabilities with CWE-922
CVE-2023-43633 HIGH
Pillar eve - Config Injection
CVSS 8.8
CVE-2023-43631 HIGH
Pillar eve - Privilege Escalation
CVSS 8.8
CVE-2023-43630 HIGH
PCR14 - Info Disclosure
CVSS 8.8
CVE-2023-32184 HIGH
opensuse-welcome <0.1.9+git.35.4b9444a - Code Injection
CVSS 7.8
CVE-2023-41965 HIGH
Vulnerable Device - Info Disclosure
CVSS 7.5
CVE-2023-40728 HIGH
QMS Automotive <V12.39 - Code Injection
CVSS 7.3
CVE-2023-37879 MEDIUM
Wing FTP Server <= 7.2.0 - Info Disclosure
CVSS 6.5
CVE-2023-29261 MEDIUM
IBM Sterling Secure Proxy <6.1.0 - Info Disclosure
CVSS 5.1
CVE-2023-37439 MEDIUM
Arubanetworks Edgeconnect Sd-wan Orchestrator < 9.1.8 - XSS
CVSS 6.1
CVE-2023-28864 MEDIUM
Progress Chef Infra Server <15.7 - Info Disclosure
CVSS 5.5
CVE-2023-37563 MEDIUM
ELECOM wireless LAN routers - Info Disclosure
CVSS 6.5
CVE-2023-23348 MEDIUM
HCL Launch - Info Disclosure
CVSS 5.1
CVE-2023-32415 MEDIUM
Apple Ipados < 16.5 - Denial of Service
CVSS 5.5
CVE-2023-26427 LOW
Properties File - Info Disclosure
CVSS 3.2
CVE-2023-29757 HIGH
Blue Light Filter <1.5.5 - Privilege Escalation
CVSS 7.8
CVE-2023-29755 HIGH
Twilight <13.3 - Privilege Escalation
CVSS 7.8
CVE-2023-3064 HIGH
Mobatime AMXGT100 <1.3.20 - Info Disclosure
CVSS 7.5
CVE-2023-29727 CRITICAL
Call Blocker app 6.6.3 - Privilege Escalation
CVSS 9.8
CVE-2023-2665 HIGH
GitHub francoisjacquet/rosariosis <11.0 - Info Disclosure
CVSS 7.5
CVE-2023-31150 HIGH
SEL RTAC - Info Disclosure
CVSS 8.0
CVE-2023-27942 MEDIUM
Apple Ipados < 16.4 - Denial of Service
CVSS 5.5
CVE-2023-23542 MEDIUM
macOS Ventura <13.3 - Info Disclosure
CVSS 5.5
CVE-2023-23541 LOW
Apple Ipados < 15.7.4 - Denial of Service
CVSS 3.3
CVE-2023-22687 LOW
Jose Mortellaro Freesoul Deactivate Plugins <= 1.9.4.0 - Info Discl...
CVSS 3.7
CVE-2023-0580 MEDIUM
ABB My Control System <5.1 - Info Disclosure
CVSS 5.4
Details
Vulnerabilities 368