VYPR

CWE-922

Insecure Storage of Sensitive Information

ClassIncomplete

Description

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

If read access is not properly restricted, then attackers can steal the sensitive information. If write access is not properly restricted, then attackers can modify and possibly delete the data, causing incorrect results and possibly a denial of service.

Hierarchy (View 1000)

Parents

CVEs mapped to this weakness (381)

page 17 of 20
  • CVE-2024-5206MedJun 6, 2024
    risk 0.24cvss 4.7epss 0.00

    A sensitive data leakage vulnerability was identified in scikit-learn's TfidfVectorizer, specifically in versions up to and including 1.4.1.post1, which was fixed in version 1.5.0. The vulnerability arises from the unexpected storage of all tokens present in the training data…

  • CVE-2023-22687LowApr 16, 2023
    risk 0.24cvss 3.7epss 0.01

    Insecure Storage of Sensitive Information vulnerability in Jose Mortellaro Freesoul Deactivate Plugins – Plugin manager and cleanup plugin <= 1.9.4.0 versions.

  • CVE-2024-32236LowApr 25, 2024
    risk 0.23cvss 3.5epss 0.00

    An issue in CmsEasy v.7.7 and before allows a remote attacker to obtain sensitive information via the update function in the index.php component.

  • CVE-2025-11639LowOct 12, 2025
    risk 0.21cvss 3.3epss 0.00

    A vulnerability has been found in Tomofun Furbo 360 and Furbo Mini. The impacted element is an unknown function of the file collect_logs.sh of the component Debug Log S3 Bucket Handler. The manipulation leads to insecure storage of sensitive information. An attack has to be…

  • CVE-2025-2157LowMar 15, 2025
    risk 0.21cvss 3.3epss 0.00

    A flaw was found in Foreman/Red Hat Satellite. Improper file permissions allow low-privileged OS users to monitor and access temporary files under /var/tmp, exposing sensitive command outputs, such as /etc/shadow. This issue can lead to information disclosure and privilege…

  • CVE-2024-44298LowDec 20, 2024
    risk 0.21cvss 3.3epss 0.00

    A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.1. An app may be able to access information about a user's contacts.

  • CVE-2024-49201MedDec 18, 2024
    risk 0.21cvss 4.3epss 0.00

    Keyfactor Remote File Orchestrator (aka remote-file-orchestrator) 2.8 before 2.8.1 allows Information Disclosure: sensitive information could be exposed at the debug logging level.

  • CVE-2024-44200LowDec 12, 2024
    risk 0.21cvss 3.3epss 0.00

    This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An app may be able to read sensitive location information.

  • CVE-2024-8899MedNov 26, 2024
    risk 0.21cvss 4.3epss 0.00

    The Jeg Elementor Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.9 via the render_content function in class/elements/views/class-tabs-view.php. This makes it possible for authenticated attackers, with…

  • CVE-2024-44222LowOct 28, 2024
    risk 0.21cvss 3.3epss 0.00

    This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. An app may be able to read sensitive location information.

  • CVE-2024-40832LowJul 29, 2024
    risk 0.21cvss 3.3epss 0.00

    The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6. An app may be able to view a contact's phone number in system logs.

  • CVE-2024-39459MedJun 26, 2024
    risk 0.21cvss 4.3epss 0.00

    In rare cases Jenkins Plain Credentials Plugin 182.v468b_97b_9dcb_8 and earlier stores secret file credentials unencrypted (only Base64 encoded) on the Jenkins controller file system, where they can be viewed by users with access to the Jenkins controller file system (global…

  • CVE-2024-35311LowMay 29, 2024
    risk 0.21cvss 3.3epss 0.00

    Yubico YubiKey 5 Series before 5.7.0, Security Key Series before 5.7.0, YubiKey Bio Series before 5.6.4, and YubiKey 5 FIPS before 5.7.2 have Incorrect Access Control.

  • CVE-2024-23232LowMar 8, 2024
    risk 0.21cvss 3.3epss 0.00

    A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sonoma 14.4. An app may be able to capture a user's screen.

  • CVE-2024-0037LowFeb 16, 2024
    risk 0.21cvss 3.3epss 0.00

    In applyCustomDescription of SaveUi.java, there is a possible way to view images belonging to a different user due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for…

  • CVE-2024-23217LowJan 23, 2024
    risk 0.21cvss 3.3epss 0.00

    A privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, macOS Ventura 13.6.5, watchOS 10.3. An app may be able to bypass certain Privacy preferences.

  • CVE-2023-23437LowDec 29, 2023
    risk 0.21cvss 3.3epss 0.00

    Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak

  • CVE-2023-26427LowJun 20, 2023
    risk 0.21cvss 3.2epss 0.00

    Default permissions for a properties file were too permissive. Local system users could read potentially sensitive information. We updated the default permissions for noreply.properties set during package installation. No publicly available exploits are known.

  • CVE-2023-23541LowMay 8, 2023
    risk 0.21cvss 3.3epss 0.00

    A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 15.7.4 and iPadOS 15.7.4, iOS 16.4 and iPadOS 16.4. An app may be able to access information about a user’s contacts.

  • CVE-2022-33973LowNov 11, 2022
    risk 0.21cvss 3.3epss 0.00

    Improper access control in the Intel(R) WAPI Security software for Windows 10/11 before version 22.2150.0.1 may allow an authenticated user to potentially enable information disclosure via local access.