CWE-922

Insecure Storage of Sensitive Information

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

373 vulnerabilities with CWE-922
CVE-2022-28170 MEDIUM
Brocade Fabric OS Web Application <9.1.0-7.4.2j - Info Disclosure
CVSS 6.5
CVE-2022-41320 MEDIUM
Veritas System Recovery <21 - Privilege Escalation
CVSS 6.5
CVE-2022-37835 HIGH
Torguard VPN 4.8 - Unauthenticated Sensitive Information Exposure
CVSS 7.5
CVE-2022-35513 HIGH
Blink1Control2 <= 2.2.7 - Weak Password Encryption
CVSS 7.5
CVE-2022-1021 MEDIUM
chatwoot < 2.6.0 - Stored Cross-Site Scripting
CVSS 5.4
CVE-2022-28168 HIGH
Brocade SANnav <2.2.0.2-2.1.1.8 - Info Disclosure
CVSS 7.5
CVE-2022-30740 MEDIUM
Samsung Internet <17.0.1.69 - Info Disclosure
CVSS 4.1
CVE-2022-1044 MEDIUM
GitHub polonel/trudesk <1.2.1 - Info Disclosure
CVSS 6.5
CVE-2022-1257 MEDIUM
McAfee Agent < 5.7.6 - Insecure Storage of Sensitive Information in ma.db
CVSS 6.1
CVE-2022-0881 MEDIUM
GitHub repository chocobozzz/peertube <4.1.1 - Info Disclosure
CVSS 6.5
CVE-2022-25264 HIGH
JetBrains TeamCity <2021.2.3 - Info Disclosure
CVSS 7.5
CVE-2022-0724 MEDIUM
microweber/microweber <1.3 - Info Disclosure
CVSS 6.5
CVE-2022-21823 MEDIUM
Ivanti Workspace Control <2021.2 - Info Disclosure
CVSS 5.5
CVE-2021-42718 MEDIUM
Replicated Classic <2.53.1 - Info Disclosure
CVSS 4.9
CVE-2021-36546 HIGH
KiteCMS 1.1 - Unauthenticated Sensitive Information Exposure via URL Path
CVSS 7.5
CVE-2021-43512 MEDIUM
FlightRadar24 <8.10.4 - Info Disclosure
CVSS 5.5
CVE-2021-25266 LOW
Sophos Authenticator <3.4 - Info Disclosure
CVSS 3.9
CVE-2021-27456 LOW
Philips Gemini PET/CT - Info Disclosure
CVSS 2.4
CVE-2021-25524 MEDIUM
Samsung Contacts <12.7.05.24 - Info Disclosure
CVSS 4.0
CVE-2021-25523 MEDIUM
Samsung Dialer <12.7.05.24 - Info Disclosure
CVSS 4.0
CVE-2021-25522 MEDIUM
Smart Capture <4.8.02.10 - Info Disclosure
CVSS 5.3
CVE-2021-42371 CRITICAL
XoruX LPAR2RRD & STOR2RRD <7.30 - Info Disclosure
CVSS 9.8
CVE-2021-28813 CRITICAL
QSW-M2116P-2T2S, QNAP switches - Info Disclosure
CVSS 9.6
CVE-2021-0639 MEDIUM
Android - Insecure Storage of Sensitive Information in libl3oemcrypto.cpp
CVSS 5.5
CVE-2021-36786 HIGH
Miniorange Saml <1.4.3 - Info Disclosure
CVSS 7.5
Details
Vulnerabilities 373