CWE-922

Insecure Storage of Sensitive Information

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

373 vulnerabilities with CWE-922
CVE-2024-25360 MEDIUM
Motorola CX2L Router <1.0.1 - Info Disclosure
CVSS 5.3
CVE-2024-25728 HIGH
ExpressVPN <12.73.0 - Info Disclosure
CVSS 7.5
CVE-2024-22773 HIGH
Intelbras Action RF <1.2.2 & Action RG <2.1.7 - Auth Bypass
CVSS 8.1
CVE-2024-22193 LOW
vantage6 < 4.2.0 - Insecure Storage of Sensitive Information
CVSS 3.5
CVE-2024-23217 LOW
iPadOS < 17.3 - Privacy Preference Bypass via Temporary File Handling
CVSS 3.3
CVE-2023-32191 CRITICAL
RKE 1.4.18-1.4.18, 1.5.9-1.5.9 - Insecure Storage of Sensitive Information in Cluster State ConfigMap
CVSS 9.9
CVE-2023-6748 MEDIUM
Custom Field Template <2.6.1 - Info Disclosure
CVSS 4.3
CVE-2023-6962 MEDIUM
WP Meta SEO <4.5.12 - Info Disclosure
CVSS 5.3
CVE-2023-52345 MEDIUM
Android - Local Information Disclosure via Modem Driver Input Validation
CVSS 6.0
CVE-2023-42913 HIGH
macOS Sonoma <14.2 - Info Disclosure
CVSS 8.8
CVE-2023-6565 MEDIUM
InfiniteWP Client <1.12.3 - Info Disclosure
CVSS 5.9
CVE-2023-45859 HIGH
Hazelcast <5.3.2 - Privilege Escalation
CVSS 7.6
CVE-2023-37540 LOW
HCL Sametime 11.5-12.0.1 - Insecure Storage of Sensitive Information via Eclipse Secure Storage
CVSS 3.9
CVE-2023-42878 MEDIUM
iPadOS < 17.1 - Unprotected User Data Exposure via Log Entry Redaction
CVSS 5.5
CVE-2023-42840 MEDIUM
macOS 12.0-12.7.1 - Unprotected User Data Exposure
CVSS 5.5
CVE-2023-42839 MEDIUM
iPadOS < 17.1 - Unprotected User Data Exposure via State Management Issue
CVSS 5.5
CVE-2023-42823 MEDIUM
iPadOS < 16.7.2 - Unprotected User Data Exposure via Logging
CVSS 5.5
CVE-2023-40093 MEDIUM
Android - Local Information Disclosure via PDF Trimming Logic Error
CVSS 5.5
CVE-2023-50298 HIGH
Apache Solr 6.0.0-8.11.2, 9.0.0-9.4.0 - Exposure of Sensitive Information via Streaming Expression zkHost Parameter
CVSS 7.5
CVE-2023-49515 MEDIUM
TP Link TC70 and C200 WIFI Camera <1.3.4 - Info Disclosure
CVSS 4.6
CVE-2023-37521 LOW
HCL BigFix Bare OSD Metal Server WebUI <311.19 - Info Disclosure
CVSS 2.3
CVE-2023-5879 MEDIUM
Aladdin Connect Mobile App <5.65.2075 - Info Disclosure
CVSS 6.8
CVE-2023-23437 LOW
hihonor vmall < 2.3.3.300 - Insecure Storage of Sensitive Information
CVSS 3.3
CVE-2023-45182 HIGH
IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 - Information Disclosure
CVSS 7.4
CVE-2023-45184 MEDIUM
IBM i Access Client Solutions <1.1.2, 1.1.4.3-1.1.9.3 - Info Disclo...
CVSS 6.2
Details
Vulnerabilities 373