VYPR

CWE-212

Improper Removal of Sensitive Information Before Storage or Transfer

BaseIncomplete

Description

The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-168

CVEs mapped to this weakness (122)

page 6 of 7
  • CVE-2025-8860LowFeb 18, 2026
    risk 0.21cvss 3.3epss 0.00

    A flaw was found in QEMU in the uefi-vars virtual device. When the guest writes to register UEFI_VARS_REG_BUFFER_SIZE, the .write callback `uefi_vars_write` is invoked. The function allocates a heap buffer without zeroing the memory, leaving the buffer filled with residual data…

  • CVE-2025-0011LowSep 6, 2025
    risk 0.21cvss 3.3epss 0.00

    Improper removal of sensitive information before storage or transfer in AMD Crash Defender could allow an attacker to obtain kernel address information potentially resulting in loss of confidentiality.

  • CVE-2020-9780LowApr 1, 2020
    risk 0.21cvss 3.3epss 0.00

    The issue was resolved by clearing application previews when content is deleted. This issue is fixed in iOS 13.4 and iPadOS 13.4. A local user may be able to view deleted content in the app switcher.

  • CVE-2024-32028MedApr 12, 2024
    risk 0.20cvss 4.1epss 0.00

    OpenTelemetry dotnet is a dotnet telemetry framework. In affected versions of `OpenTelemetry.Instrumentation.Http` and `OpenTelemetry.Instrumentation.AspNetCore` the `url.full` writes attribute/tag on spans (`Activity`) when tracing is enabled for outgoing http requests and…

  • CVE-2024-41156LowOct 29, 2024
    risk 0.18cvss 2.7epss 0.00

    Profile files from TRO600 series radios are extracted in plain-text and encrypted file formats. Profile files provide potential attackers valuable configuration information about the Tropos network. Profiles can only be exported by authenticated users with higher privilege of…

  • CVE-2023-41967LowDec 18, 2023
    risk 0.16cvss 2.4epss 0.00

    Sensitive information uncleared after debug/power state transition in the Controller 6000 could be abused by an attacker with knowledge of the Controller's default diagnostic password and physical access to the Controller to view its configuration through the diagnostic web…

  • CVE-2025-27221LowMar 4, 2025
    risk 0.14cvss 3.2epss 0.00

    In the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.join, URI#merge, URI#+) have an inadvertent leakage of authentication credentials because userinfo is retained even after changing the host.

  • CVE-2025-64326LowNov 6, 2025
    risk 0.10cvss 2.6epss 0.00

    Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users.…

  • CVE-2022-24719LowMar 1, 2022
    risk 0.10cvss 2.6epss 0.01

    Fluture-Node is a FP-style HTTP and streaming utils for Node based on Fluture. Using `followRedirects` or `followRedirectsWith` with any of the redirection strategies built into fluture-node 4.0.0 or 4.0.1, paired with a request that includes confidential headers such as…

  • CVE-2022-0536LowFeb 9, 2022
    risk 0.10cvss 2.6epss 0.01

    Improper Removal of Sensitive Information Before Storage or Transfer in NPM follow-redirects prior to 1.14.8.

  • CVE-2025-48066MedMay 22, 2025
    risk 0.00cvss 6.0epss 0.00

    wire-webapp is the web application for the open-source messaging service Wire. A bug fix caused a regression causing an issue with function to delete local data. Instructing the client to delete its local database on user logout does not result in deletion. This is the case for…

  • CVE-2023-48308LowDec 22, 2023
    risk 0.00cvss 3.5epss 0.01

    Nextcloud/Cloud is a calendar app for Nextcloud. An attacker can gain access to stacktrace and internal paths of the server when generating an exception while editing a calendar appointment. It is recommended that the Nextcloud Calendar app is upgraded to 4.5.3

  • CVE-2023-3006MedMay 31, 2023
    risk 0.00cvss 5.5epss 0.00

    A known cache speculation vulnerability, known as Branch History Injection (BHI) or Spectre-BHB, becomes actual again for the new hw AmpereOne. Spectre-BHB is similar to Spectre v2, except that malicious code uses the shared branch history (stored in the CPU Branch History…

  • CVE-2023-28834LowApr 3, 2023
    risk 0.00cvss 3.5epss 0.01

    Nextcloud Server is an open source personal cloud server. Nextcloud Server 24.0.0 until 24.0.6 and 25.0.0 until 25.0.4, as well as Nextcloud Enterprise Server 23.0.0 until 23.0.11, 24.0.0 until 24.0.6, and 25.0.0 until 25.0.4, have an information disclosure vulnerability. A user…

  • CVE-2023-1637MedMar 27, 2023
    risk 0.00cvss 5.5epss 0.00

    A flaw that boot CPU could be vulnerable for the speculative execution behavior kind of attacks in the Linux kernel X86 CPU Power management options functionality was found in the way user resuming CPU from suspend-to-RAM. A local user could use this flaw to potentially get…

  • CVE-2022-0171MedAug 26, 2022
    risk 0.00cvss 5.5epss 0.00

    A flaw was found in the Linux kernel. The existing KVM SEV API has a vulnerability that allows a non-root (host) user-level application to crash the host kernel by creating a confidential guest VM instance in AMD CPU that supports Secure Encrypted Virtualization (SEV).

  • CVE-2022-1893MedMay 31, 2022
    risk 0.00cvss 4.6epss 0.01

    Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository polonel/trudesk prior to 1.2.3.

  • CVE-2022-23605MedFeb 4, 2022
    risk 0.00cvss 4.4epss 0.00

    Wire webapp is a web client for the wire messaging protocol. In versions prior to 2022-01-27-production.0 expired ephemeral messages were not reliably removed from local chat history of Wire Webapp. In versions before 2022-01-27-production.0 ephemeral messages and assets might…

  • CVE-2021-32658MedJun 8, 2021
    risk 0.00cvss 4.7epss 0.00

    Nextcloud Android is the Android client for the Nextcloud open source home cloud system. Due to a timeout issue the Android client may not properly clean all sensitive data on account removal. This could include sensitive key material such as the End-to-End encryption keys. It…

  • CVE-2020-25635MedOct 5, 2020
    risk 0.00cvss 5.0epss 0.00

    A flaw was found in Ansible Base when using the aws_ssm connection plugin as garbage collector is not happening after playbook run is completed. Files would remain in the bucket exposing the data. This issue affects directly data confidentiality.