VYPR

CWE-212

Improper Removal of Sensitive Information Before Storage or Transfer

BaseIncomplete

Description

The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-168

CVEs mapped to this weakness (122)

page 4 of 7
  • CVE-2025-59955MedJan 5, 2026
    risk 0.37cvss 5.7epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions prior to and including v4.0.0-beta.420.8 have an information disclosure vulnerability in the `/api/v1/teams/{team_id}/members` and `/api/v1/teams/current/members`…

  • CVE-2024-56353MedDec 20, 2024
    risk 0.36cvss 5.5epss 0.00

    In JetBrains TeamCity before 2024.12 backup file exposed user credentials and session cookies

  • CVE-2024-43554MedOct 8, 2024
    risk 0.36cvss 5.5epss 0.01

    Windows Kernel-Mode Driver Information Disclosure Vulnerability

  • CVE-2021-28689MedJun 11, 2021
    risk 0.36cvss 5.5epss 0.00

    x86: Speculative vulnerabilities with bare (non-shim) 32-bit PV guests 32-bit x86 PV guest kernels run in ring 1. At the time when Xen was developed, this area of the i386 architecture was rarely used, which is why Xen was able to use it to implement paravirtualisation, Xen's…

  • CVE-2020-8696MedNov 12, 2020
    risk 0.36cvss 5.5epss 0.00

    Improper removal of sensitive information before storage or transfer in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2020-15024MedSep 10, 2020
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in the Login Password feature of the Password Manager component in Avast Antivirus 20.1.5069.562. An entered password continues to be stored in Windows main memory after a logout, and after a Lock Vault operation.

  • CVE-2020-13179MedAug 11, 2020
    risk 0.36cvss 5.5epss 0.00

    Broker Protocol messages in Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows prior to 20.04.1 are not cleaned up in server memory, which may allow an attacker to read confidential information from a memory dump via forcing a crashing during the single…

  • CVE-2020-11740MedApr 14, 2020
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS users (without active profiling) to obtain sensitive information about other guests. Unprivileged guests can request to map xenoprof buffers, even if profiling has not been enabled for those guests.…

  • CVE-2005-0406MedFeb 14, 2005
    risk 0.36cvss 5.5epss 0.00

    A design flaw in image processing software that modifies JPEG images might not modify the original EXIF thumbnail, which could lead to an information leak of potentially sensitive visual information that had been removed from the main JPEG image.

  • CVE-2026-27892MedMay 18, 2026
    risk 0.35cvss 6.5epss 0.00

    FacturaScripts is an open source accounting and invoicing software. In versions prior to 2026, the Library module stores and serves uploaded images byte-for-byte, without stripping EXIF/XMP/IPTC metadata. Any authenticated user who downloaded an image could extract the…

  • CVE-2026-43528MedMay 5, 2026
    risk 0.35cvss 6.5epss 0.00

    OpenClaw before 2026.4.14 contains a redaction bypass vulnerability that allows authenticated gateway clients to receive unredacted secrets through sourceConfig and runtimeConfig alias fields. Attackers with config read access can exploit this to obtain provider API keys,…

  • CVE-2022-25187MedFeb 15, 2022
    risk 0.35cvss 6.5epss 0.01

    Jenkins Support Core Plugin 2.79 and earlier does not redact some sensitive information in the support bundle.

  • CVE-2021-38554MedAug 13, 2021
    risk 0.35cvss 5.3epss 0.01

    HashiCorp Vault and Vault Enterprise’s UI erroneously cached and exposed user-viewed secrets between sessions in a single shared browser. Fixed in 1.8.0 and pending 1.7.4 / 1.6.6 releases.

  • CVE-2020-3874MedFeb 27, 2020
    risk 0.35cvss 5.3epss 0.01

    An issued existed in the naming of screenshots. The issue was corrected with improved naming. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1. Screenshots of the Messages app may reveal additional message content.

  • CVE-2018-1062MedMar 6, 2018
    risk 0.35cvss 5.3epss 0.01

    A vulnerability was discovered in oVirt 4.1.x before 4.1.9, where the combination of Enable Discard and Wipe After Delete flags for VM disks managed by oVirt, could cause a disk to be incompletely zeroed when removed from a VM. If the same storage blocks happen to be later…

  • CVE-2026-45737MedJul 15, 2026
    risk 0.34cvss 6.3epss 0.00

    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 3.2.0 until 3.2.12, 3.3.10, and 3.4.2, Argo CD ServerSideDiff can expose Kubernetes Secret values embedded in the kubectl.kubernetes.io/last-applied-configuration annotation because…

  • CVE-2025-65000MedDec 18, 2025
    risk 0.34cvss 5.3epss 0.00

    SSH private keys of the "Remote alert handlers (Linux)" rule were exposed in the rule page's HTML source in Checkmk <= 2.4.0p18 and all versions of Checkmk 2.3.0. This potentially allowed unauthorized triggering of predefined alert handlers on hosts where the handler was…

  • CVE-2025-62483MedNov 13, 2025
    risk 0.34cvss 5.3epss 0.00

    Improper removal of sensitive information in certain Zoom Clients before version 6.5.10 may allow an unauthenticated user to conduct a disclosure of information via network access.

  • CVE-2025-14267MedDec 19, 2025
    risk 0.32cvss 4.9epss 0.00

    Incomplete removal of sensitive information before transfer vulnerability in M-Files Corporation M-Files Server allows data leak exposure affecting versions before 25.12.15491.7

  • CVE-2026-67354MedAug 1, 2026
    risk 0.31cvss 5.9epss 0.00

    guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When the optional allow_redirects.referer setting is enabled, the middleware copies the URI fragment (the portion after '#') from the referring request into the…