CWE-922
Insecure Storage of Sensitive Information
Description
The product stores sensitive information without properly limiting read or write access by unauthorized actors.
Hierarchy (View 1000)
CVEs mapped to this weakness (381)
page 12 of 20| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-0639 | Med | 0.36 | 5.5 | 0.00 | Aug 17, 2021 | In multiple functions of libl3oemcrypto.cpp, there is a possible weakness in the existing obfuscation mechanism due to the way sensitive data is handled. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not… | ||
| CVE-2020-4871 | Med | 0.36 | 5.5 | 0.00 | Jan 19, 2021 | IBM Planning Analytics 2.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 190834. | ||
| CVE-2019-8790 | Med | 0.36 | 5.5 | 0.00 | Oct 27, 2020 | This issue was addresses by updating incorrect URLSession file descriptors management logic to match Swift 5.0. This issue is fixed in Swift 5.1.1 for Ubuntu. Incorrect management of file descriptors in URLSession could lead to inadvertent data disclosure. | ||
| CVE-2020-1493 | Med | 0.36 | 5.5 | 0.07 | Aug 17, 2020 | An information disclosure vulnerability exists when attaching files to Outlook messages. This vulnerability could potentially allow users to share attached files such that they are accessible by anonymous users where they should be restricted to specific users. To exploit this… | ||
| CVE-2019-5633 | Med | 0.36 | 5.5 | 0.00 | Aug 22, 2019 | An insecure storage of sensitive information vulnerability is present in Hickory Smart for iOS mobile devices from Belwith Products, LLC. The application's database was found to contain information that could be used to control the lock devices remotely. This issue affects… | ||
| CVE-2019-5632 | Med | 0.36 | 5.5 | 0.00 | Aug 22, 2019 | An insecure storage of sensitive information vulnerability is present in Hickory Smart for Android mobile devices from Belwith Products, LLC. The application's database was found to contain information that could be used to control the lock devices remotely. This issue affects… | ||
| CVE-2017-0493 | Med | 0.36 | 5.5 | 0.00 | May 12, 2017 | An information disclosure vulnerability in File-Based Encryption could enable a local malicious attacker to bypass operating system protections for the lock screen. This issue is rated as Moderate due to the possibility of bypassing the lock screen. Product: Android. Versions:… | ||
| CVE-2024-3717 | Med | 0.35 | 5.3 | 0.01 | May 2, 2024 | The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.7.7 via the '/wp-content/uploads/wp_dndcf7_uploads/wpcf7-files' directory. This makes it possible for… | ||
| CVE-2024-26559 | Med | 0.35 | 5.3 | 0.01 | Feb 28, 2024 | An issue in uverif v.2.0 allows a remote attacker to obtain sensitive information. | ||
| CVE-2023-0580 | Med | 0.35 | 5.4 | 0.00 | Apr 6, 2023 | Insecure Storage of Sensitive Information vulnerability in ABB My Control System (on-premise) allows an attacker who successfully exploited this vulnerability to gain access to the secure application data or take control of the application. Of the services that make up the My… | ||
| CVE-2022-2815 | Med | 0.35 | 6.5 | 0.01 | Jan 14, 2023 | Insecure Storage of Sensitive Information in GitHub repository publify/publify prior to 9.2.10. | ||
| CVE-2022-0724 | Med | 0.35 | 6.5 | 0.01 | Feb 23, 2022 | Insecure Storage of Sensitive Information in GitHub repository microweber/microweber prior to 1.3. | ||
| CVE-2020-5008 | Med | 0.35 | 5.3 | 0.01 | Jun 7, 2021 | IBM DataPower Gateway 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.14 stores sensitive information in GET request parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history.… | ||
| CVE-2019-4549 | Med | 0.35 | 5.3 | 0.01 | Oct 2, 2019 | IBM Security Directory Server 6.4.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 165951. | ||
| CVE-2019-14957 | Med | 0.35 | 5.3 | 0.01 | Oct 1, 2019 | The JetBrains Vim plugin before version 0.52 was storing individual project data in the global vim_settings.xml file. This xml file could be synchronized to a publicly accessible GitHub repository. | ||
| CVE-2026-5666 | Med | 0.34 | 5.3 | 0.00 | Apr 6, 2026 | A vulnerability was detected in code-projects Online FIR System 1.0. Affected by this issue is some unknown functionality of the file /complaints.sql of the component SQL Database Backup File Handler. The manipulation results in insecure storage of sensitive information. The… | ||
| CVE-2026-5650 | Med | 0.34 | 5.3 | 0.00 | Apr 6, 2026 | A vulnerability was found in code-projects Online Application System for Admission 1.0. Impacted is an unknown function of the file /enrollment/database/oas.sql. Performing a manipulation results in insecure storage of sensitive information. The attack is possible to be carried… | ||
| CVE-2025-10734 | Med | 0.34 | 5.3 | 0.00 | Mar 23, 2026 | The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.12 via the syncedData function. This makes it possible… | ||
| CVE-2025-35054 | Med | 0.34 | 5.3 | 0.00 | Oct 9, 2025 | Newforma Info Exchange (NIX) stores credentials used to configure NPCS in 'HKLM\Software\WOW6432Node\Newforma\\Credentials'. The credentials are encrypted but the encryption key is stored in the same registry location. Authenticated users can access both the… | ||
| CVE-2025-46660 | Med | 0.34 | 5.3 | 0.00 | Aug 6, 2025 | An issue was discovered in 4C Strategies Exonaut 21.6. Passwords, stored in the database, are hashed without a salt. |
- risk 0.36cvss 5.5epss 0.00
In multiple functions of libl3oemcrypto.cpp, there is a possible weakness in the existing obfuscation mechanism due to the way sensitive data is handled. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…
- risk 0.36cvss 5.5epss 0.00
IBM Planning Analytics 2.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 190834.
- risk 0.36cvss 5.5epss 0.00
This issue was addresses by updating incorrect URLSession file descriptors management logic to match Swift 5.0. This issue is fixed in Swift 5.1.1 for Ubuntu. Incorrect management of file descriptors in URLSession could lead to inadvertent data disclosure.
- risk 0.36cvss 5.5epss 0.07
An information disclosure vulnerability exists when attaching files to Outlook messages. This vulnerability could potentially allow users to share attached files such that they are accessible by anonymous users where they should be restricted to specific users. To exploit this…
- risk 0.36cvss 5.5epss 0.00
An insecure storage of sensitive information vulnerability is present in Hickory Smart for iOS mobile devices from Belwith Products, LLC. The application's database was found to contain information that could be used to control the lock devices remotely. This issue affects…
- risk 0.36cvss 5.5epss 0.00
An insecure storage of sensitive information vulnerability is present in Hickory Smart for Android mobile devices from Belwith Products, LLC. The application's database was found to contain information that could be used to control the lock devices remotely. This issue affects…
- risk 0.36cvss 5.5epss 0.00
An information disclosure vulnerability in File-Based Encryption could enable a local malicious attacker to bypass operating system protections for the lock screen. This issue is rated as Moderate due to the possibility of bypassing the lock screen. Product: Android. Versions:…
- risk 0.35cvss 5.3epss 0.01
The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.7.7 via the '/wp-content/uploads/wp_dndcf7_uploads/wpcf7-files' directory. This makes it possible for…
- risk 0.35cvss 5.3epss 0.01
An issue in uverif v.2.0 allows a remote attacker to obtain sensitive information.
- risk 0.35cvss 5.4epss 0.00
Insecure Storage of Sensitive Information vulnerability in ABB My Control System (on-premise) allows an attacker who successfully exploited this vulnerability to gain access to the secure application data or take control of the application. Of the services that make up the My…
- risk 0.35cvss 6.5epss 0.01
Insecure Storage of Sensitive Information in GitHub repository publify/publify prior to 9.2.10.
- risk 0.35cvss 6.5epss 0.01
Insecure Storage of Sensitive Information in GitHub repository microweber/microweber prior to 1.3.
- risk 0.35cvss 5.3epss 0.01
IBM DataPower Gateway 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.14 stores sensitive information in GET request parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history.…
- risk 0.35cvss 5.3epss 0.01
IBM Security Directory Server 6.4.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 165951.
- risk 0.35cvss 5.3epss 0.01
The JetBrains Vim plugin before version 0.52 was storing individual project data in the global vim_settings.xml file. This xml file could be synchronized to a publicly accessible GitHub repository.
- risk 0.34cvss 5.3epss 0.00
A vulnerability was detected in code-projects Online FIR System 1.0. Affected by this issue is some unknown functionality of the file /complaints.sql of the component SQL Database Backup File Handler. The manipulation results in insecure storage of sensitive information. The…
- risk 0.34cvss 5.3epss 0.00
A vulnerability was found in code-projects Online Application System for Admission 1.0. Impacted is an unknown function of the file /enrollment/database/oas.sql. Performing a manipulation results in insecure storage of sensitive information. The attack is possible to be carried…
- risk 0.34cvss 5.3epss 0.00
The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.12 via the syncedData function. This makes it possible…
- risk 0.34cvss 5.3epss 0.00
Newforma Info Exchange (NIX) stores credentials used to configure NPCS in 'HKLM\Software\WOW6432Node\Newforma\\Credentials'. The credentials are encrypted but the encryption key is stored in the same registry location. Authenticated users can access both the…
- risk 0.34cvss 5.3epss 0.00
An issue was discovered in 4C Strategies Exonaut 21.6. Passwords, stored in the database, are hashed without a salt.