CWE-922

Insecure Storage of Sensitive Information

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

373 vulnerabilities with CWE-922
CVE-2025-20886 MEDIUM
softsim trustlet <SMR Jan-2025 Release 1 - Info Disclosure
CVSS 4.1
CVE-2025-24117 MEDIUM
iPadOS < 17.7.4 - Insecure Storage of Sensitive Information
CVSS 5.5
CVE-2025-24101 MEDIUM
macOS Sequoia <15.3 - Info Disclosure
CVSS 5.5
CVE-2025-21299 HIGH
Windows Kerberos - Privilege Escalation
CVSS 7.1
CVE-2025-22984 HIGH
iceCMS 2.2.0 - Unauthenticated Sensitive Information Exposure via /api/squareComment/DelectSquareById
CVSS 7.5
CVE-2025-22983 HIGH
iceCMS 2.2.0 - Unauthenticated Sensitive Information Exposure via /square/getAllSquare/circle Endpoint
CVSS 7.5
CVE-2024-13954 MEDIUM
ASPECT-Enterprise <3.* - Info Disclosure
CVSS 6.5
CVE-2024-12315 HIGH
Export All Posts, Products, Orders, Refunds & Users <= 2.9.3 - Sensitive Information Exposure
CVSS 7.5
CVE-2024-57436 HIGH
RuoYi 4.8.0 - Unauthenticated Sensitive Information Exposure via Session ID Disclosure
CVSS 7.2
CVE-2024-57546 HIGH
CMSimple 5.16 - Insecure Storage of Sensitive Information via Validate Link Function
CVSS 7.5
CVE-2024-54728 MEDIUM
BYD QIN PLUS DM-i Dilink OS 3.0_13.1.7.2204050.1 - Info Disclosure
CVSS 6.5
CVE-2024-54549 MEDIUM
macOS Sequoia <15.2 - Info Disclosure
CVSS 5.5
CVE-2024-54541 MEDIUM
iPadOS < 18.2 - Unprotected User Data Exposure via State Management Issue
CVSS 5.5
CVE-2024-56972 MEDIUM
Midea Home iOS 9.3.12 - Info Disclosure
CVSS 6.5
CVE-2024-56971 MEDIUM
Shuqi Novel iOS 5.3.8 - Info Disclosure
CVSS 6.5
CVE-2024-56969 MEDIUM
Pixocial Technology (Singapore) Pte. Ltd BeautyPlus <7.8.010 - Info...
CVSS 6.5
CVE-2024-56968 MEDIUM
Govee Home iOS 6.5.01 - Info Disclosure
CVSS 6.5
CVE-2024-56967 MEDIUM
PolyBuzz iOS 2.0.20 - Info Disclosure
CVSS 6.5
CVE-2024-56966 MEDIUM
Qidian Reader <5.9.384 - Info Disclosure
CVSS 6.5
CVE-2024-56965 MEDIUM
Shihuo iOS 8.16.0 - Info Disclosure
CVSS 6.5
CVE-2024-56964 MEDIUM
Guazi Used Car iOS 10.15.1 - Info Disclosure
CVSS 6.5
CVE-2024-56963 MEDIUM
Sogou Input iOS 12.2.0 - Info Disclosure
CVSS 6.5
CVE-2024-56962 MEDIUM
Tencent Technology (Shanghai) Co., Ltd WeSing <9.3.39 - Info Disclo...
CVSS 6.5
CVE-2024-56960 MEDIUM
Tianjin Xiaowu Information technology Co., Ltd BeiKe Holdings iOS 1...
CVSS 6.5
CVE-2024-56959 MEDIUM
Mashang Consumer Finance Co., Ltd Anyihua iOS 3.6.2 - Info Disclosure
CVSS 6.5
Details
Vulnerabilities 373