CWE-223
Omission of Security-relevant Information
Description
The product does not record or display information that would be important for identifying the source or nature of an attack, or determining if an action is safe.
Hierarchy (View 1000)
CVEs mapped to this weakness (12)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-31191 | Cri | 0.60 | 9.3 | 0.00 | Jul 11, 2023 | DroneScout ds230 Remote ID receiver from BlueMark Innovations is affected by an information loss vulnerability through traffic injection. An attacker can exploit this vulnerability by injecting, on carefully selected channels, high power spoofed Open Drone ID (ODID) messages… | ||
| CVE-2023-29156 | Med | 0.31 | 4.7 | 0.00 | Jul 11, 2023 | DroneScout ds230 Remote ID receiver from BlueMark Innovations is affected by an information loss vulnerability through traffic injection. An attacker can exploit this vulnerability by injecting, at the right times, spoofed Open Drone ID (ODID) messages which force the… | ||
| CVE-2026-31890 | Med | 0.29 | 5.5 | 0.00 | Mar 12, 2026 | Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. Prior to 0.50.1, in a situation where the ring-buffer of a gadget is – incidentally or maliciously – already full, the gadget will… | ||
| CVE-2022-22563 | Med | 0.29 | 4.4 | 0.00 | Apr 8, 2022 | Dell EMC Powerscale OneFS 8.2.x - 9.2.x omit security-relevant information in /etc/master.passwd. A high-privileged user can exploit this vulnerability to not record information identifying the source of account information changes. | ||
| CVE-2025-35987 | Med | 0.28 | — | 0.00 | Aug 11, 2026 | Omission of security-relevant information for some Intel(R) Software Guard Extensions Data Center Attestation Primitives within Ring 0: Kernel may allow a denial of service. Authorized adversary with a privileged user combined with a high complexity attack may enable data… | ||
| CVE-2023-28360 | Med | 0.28 | 4.3 | 0.01 | May 11, 2023 | An omission of security-relevant information vulnerability exists in Brave desktop prior to version 1.48.171 when a user was saving a file there was no download safety check dialog presented to the user. | ||
| CVE-2026-91859 | Med | 0.27 | — | 0.00 | Sep 15, 2026 | Affected versions of MISP can record incorrect access-log data for requests that terminate in an exception. Because CakeErrorController extends AppController, exception rendering runs the application startup path a second time. As a result, __accessMonitor() calls… | ||
| CVE-2026-90955 | Med | 0.23 | — | 0.00 | Sep 14, 2026 | Affected versions of MISP’s interactive CLI shell do not reliably preserve the identity of the impersonated MISP user across audit logging. The shell is designed to run actions as a supplied MISP user ID. However, the legacy SysLogLogable behavior stored that identity in… | ||
| CVE-2026-49426 | Low | 0.21 | 3.3 | 0.00 | Aug 19, 2026 | When auditing a system call executed via ptrace(PT_SC_REMOTE), the kernel passed the return value of an internal setup function to AUDIT_SYSCALL_EXIT() rather than the actual result of the executed system call. As a result, committed audit records for system calls which… | ||
| CVE-2024-52813 | Med | 0.21 | 4.3 | 0.00 | Jan 7, 2025 | matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. Versions of the matrix-sdk-crypto Rust crate before 0.8.0 lack a dedicated mechanism to notify that a user's cryptographic identity has changed from a verified to an unverified one, which could cause… | ||
| CVE-2022-44646 | Low | 0.14 | 2.2 | 0.00 | Nov 3, 2022 | In JetBrains TeamCity version before 2022.10, no audit items were added upon editing a user's settings | ||
| CVE-2025-52926 | Low | 0.11 | 2.7 | 0.00 | Jun 23, 2025 | In scan.rs in spytrap-adb before 0.3.5, matches for known stalkerware are not rendered in the interactive user interface. |
- risk 0.60cvss 9.3epss 0.00
DroneScout ds230 Remote ID receiver from BlueMark Innovations is affected by an information loss vulnerability through traffic injection. An attacker can exploit this vulnerability by injecting, on carefully selected channels, high power spoofed Open Drone ID (ODID) messages…
- risk 0.31cvss 4.7epss 0.00
DroneScout ds230 Remote ID receiver from BlueMark Innovations is affected by an information loss vulnerability through traffic injection. An attacker can exploit this vulnerability by injecting, at the right times, spoofed Open Drone ID (ODID) messages which force the…
- risk 0.29cvss 5.5epss 0.00
Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. Prior to 0.50.1, in a situation where the ring-buffer of a gadget is – incidentally or maliciously – already full, the gadget will…
- risk 0.29cvss 4.4epss 0.00
Dell EMC Powerscale OneFS 8.2.x - 9.2.x omit security-relevant information in /etc/master.passwd. A high-privileged user can exploit this vulnerability to not record information identifying the source of account information changes.
- risk 0.28cvss —epss 0.00
Omission of security-relevant information for some Intel(R) Software Guard Extensions Data Center Attestation Primitives within Ring 0: Kernel may allow a denial of service. Authorized adversary with a privileged user combined with a high complexity attack may enable data…
- risk 0.28cvss 4.3epss 0.01
An omission of security-relevant information vulnerability exists in Brave desktop prior to version 1.48.171 when a user was saving a file there was no download safety check dialog presented to the user.
- risk 0.27cvss —epss 0.00
Affected versions of MISP can record incorrect access-log data for requests that terminate in an exception. Because CakeErrorController extends AppController, exception rendering runs the application startup path a second time. As a result, __accessMonitor() calls…
- risk 0.23cvss —epss 0.00
Affected versions of MISP’s interactive CLI shell do not reliably preserve the identity of the impersonated MISP user across audit logging. The shell is designed to run actions as a supplied MISP user ID. However, the legacy SysLogLogable behavior stored that identity in…
- risk 0.21cvss 3.3epss 0.00
When auditing a system call executed via ptrace(PT_SC_REMOTE), the kernel passed the return value of an internal setup function to AUDIT_SYSCALL_EXIT() rather than the actual result of the executed system call. As a result, committed audit records for system calls which…
- risk 0.21cvss 4.3epss 0.00
matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. Versions of the matrix-sdk-crypto Rust crate before 0.8.0 lack a dedicated mechanism to notify that a user's cryptographic identity has changed from a verified to an unverified one, which could cause…
- risk 0.14cvss 2.2epss 0.00
In JetBrains TeamCity version before 2022.10, no audit items were added upon editing a user's settings
- risk 0.11cvss 2.7epss 0.00
In scan.rs in spytrap-adb before 0.3.5, matches for known stalkerware are not rendered in the interactive user interface.