CWE-922

Insecure Storage of Sensitive Information

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

368 vulnerabilities with CWE-922
CVE-2024-29953 MEDIUM
Brocade Fabric OS <9.2.1-9.1.1d - Info Disclosure
CVSS 4.3
CVE-2024-35526 MEDIUM
Daemon PTY Limited FarCry Core <7.2.14 - Info Disclosure
CVSS 5.9
CVE-2024-6295 LOW
udn News Android APP - Info Disclosure
CVSS 3.9
CVE-2024-37654 MEDIUM
BAS-IP <3.9.2 - Info Disclosure
CVSS 6.1
CVE-2024-38312 MEDIUM
Firefox for iOS < 127 - Info Disclosure
CVSS 6.5
CVE-2024-23445 MEDIUM
Elasticsearch - Info Disclosure
CVSS 6.5
CVE-2024-3723 MEDIUM
Advanced Contact Form 7 DB <2.0.2 - Info Disclosure
CVSS 5.3
CVE-2024-31404 MEDIUM
Cybozu Garoon <6.0.0 - Info Disclosure
CVSS 4.3
CVE-2024-31400 MEDIUM
Cybozu Garoon <5.15.0 - Info Disclosure
CVSS 6.5
CVE-2024-36788 MEDIUM
Netgear WNR614 - Info Disclosure
CVSS 4.8
CVE-2024-5599 HIGH
FileOrganizer - Info Disclosure
CVSS 7.5
CVE-2024-5206 MEDIUM
scikit-learn <1.5.0 - Info Disclosure
CVSS 4.7
CVE-2024-35311 LOW
Yubico YubiKey <5.7.0 - Info Disclosure
CVSS 3.3
CVE-2024-33004 MEDIUM
SAP Business Objects - Info Disclosure
CVSS 4.3
CVE-2024-4213 MEDIUM
Shopping Cart & eCommerce Store <5.6.4 - Info Disclosure
CVSS 5.3
CVE-2024-27789 MEDIUM
iOS <16.7.8 - Info Disclosure
CVSS 5.5
CVE-2024-23229 MEDIUM
macOS <14.4 - Info Disclosure
CVSS 5.5
CVE-2024-28132 MEDIUM
GSLB - Info Disclosure
CVSS 4.4
CVE-2024-3717 MEDIUM
Contact Form 7 <1.3.7.7 - Info Disclosure
CVSS 5.3
CVE-2024-32211 MEDIUM
LOGINT LoMag Inventory Management <1.0.20.120 - Info Disclosure
CVSS 5.5
CVE-2024-3678 MEDIUM
Blog2Social: Social Media Auto Post & Scheduler - Info Disclosure
CVSS 5.3
CVE-2024-32236 LOW
CmsEasy <7.7 - Info Disclosure
CVSS 3.5
CVE-2024-3733 MEDIUM
Essential Addons for Elementor - Info Disclosure
CVSS 5.3
CVE-2024-22808 HIGH
Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 - DoS
CVSS 7.5
CVE-2024-29968 HIGH
Brocade SANnav <2.3.1-2.3.0a - Info Disclosure
CVSS 7.7
Details
Vulnerabilities 368