CWE-922

Insecure Storage of Sensitive Information

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

368 vulnerabilities with CWE-922
CVE-2024-3502 HIGH
lunary-ai/lunary <1.2.5 - Info Disclosure
CVSS 8.1
CVE-2024-3501 HIGH
lunary-ai/lunary <1.2.6 - Info Disclosure
CVSS 8.1
CVE-2024-10943 CRITICAL
An - Auth Bypass
CVSS 9.1
CVE-2024-43427 LOW
Moodle - Info Disclosure
CVSS 3.7
CVE-2024-48939 HIGH
Paxton Net2 <6.07.14023.5015 - Info Disclosure
CVSS 7.5
CVE-2024-34677 MEDIUM
System UI <SMR Nov-2024 Release 1 - Info Disclosure
CVSS 4.0
CVE-2024-10028 HIGH
Everest Backup - WordPress Cloud <2.2.13 - Info Disclosure
CVSS 7.5
CVE-2024-48353 HIGH
Yealink Meeting Server <V26.0.0.67 - Info Disclosure
CVSS 7.5
CVE-2024-48352 HIGH
Yealink Meeting Server <V26.0.0.67 - Info Disclosure
CVSS 7.5
CVE-2024-51399 MEDIUM
Altai Technologies Ltd Altai IX500 Indoor - Info Disclosure
CVSS 5.7
CVE-2024-44257 MEDIUM
macOS Ventura <13.7.1 - Info Disclosure
CVSS 5.5
CVE-2024-44216 MEDIUM
macOS Ventura <13.7.1 - Info Disclosure
CVSS 5.5
CVE-2024-44275 MEDIUM
macOS Ventura <13.7.1 - Info Disclosure
CVSS 5.5
CVE-2024-44263 MEDIUM
Apple Ipados < 18.1 - Denial of Service
CVSS 5.5
CVE-2024-44222 LOW
macOS Ventura <13.7.1 - Info Disclosure
CVSS 3.3
CVE-2024-44213 MEDIUM
macOS Ventura <13.7.1 - Info Disclosure
CVSS 5.9
CVE-2024-44175 MEDIUM
Apple Macos < 14.7.1 - Symlink Following
CVSS 5.5
CVE-2024-44174 MEDIUM
Apple Macos < 15.0 - Improper Condition Check
CVSS 5.5
CVE-2024-30122 MEDIUM
HCL Sametime - Info Disclosure
CVSS 5.8
CVE-2024-10041 MEDIUM
PAM - Memory Corruption
CVSS 4.7
CVE-2024-20462 MEDIUM
Cisco ATA 190 Series - Info Disclosure
CVSS 5.5
CVE-2024-48783 HIGH
Ruijie NBR3000D-E - Info Disclosure
CVSS 7.5
CVE-2024-21258 MEDIUM
Oracle E-Business Suite <12.2.15 - Info Disclosure
CVSS 5.3
CVE-2024-21211 LOW
Oracle Java SE <23 - Compiler Vuln
CVSS 3.7
CVE-2024-48770 HIGH
Plug n Play Camera com.wisdomcity.zwave <1.1.0 - Info Disclosure
CVSS 8.2
Details
Vulnerabilities 368