VYPR

CWE-922

Insecure Storage of Sensitive Information

ClassIncomplete

Description

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

If read access is not properly restricted, then attackers can steal the sensitive information. If write access is not properly restricted, then attackers can modify and possibly delete the data, causing incorrect results and possibly a denial of service.

Hierarchy (View 1000)

Parents

CVEs mapped to this weakness (381)

page 19 of 20
  • CVE-2025-11645LowOct 12, 2025
    risk 0.16cvss 2.4epss 0.00

    A security vulnerability has been detected in Tomofun Furbo Mobile App up to 7.57.0a on Android. This affects an unknown part of the component Authentication Token Handler. The manipulation leads to insecure storage of sensitive information. It is possible to launch the attack…

  • CVE-2024-54485LowDec 12, 2024
    risk 0.16cvss 2.4epss 0.00

    The issue was addressed by adding additional logic. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2. An attacker with physical access to an iOS device may be able to view notification content from the lock screen.

  • CVE-2020-10368LowNov 10, 2024
    risk 0.16cvss 3.5epss 0.00

    Certain Cypress (and Broadcom) Wireless Combo chips, when a January 2021 firmware update is not present, allow memory read access via a "Spectra" attack.

  • CVE-2024-22193LowJan 30, 2024
    risk 0.16cvss 3.5epss 0.00

    The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). There are no checks on whether the input is encrypted if a task is created in an encrypted collaboration. Therefore, a user may…

  • CVE-2022-39043LowMar 27, 2023
    risk 0.16cvss 2.4epss 0.00

    Juiker app stores debug logs which contains sensitive information to mobile external storage. An unauthenticated physical attacker can access these files to acquire partial user information such as personal contacts.

  • CVE-2022-32867LowNov 1, 2022
    risk 0.16cvss 2.4epss 0.00

    This issue was addressed with improved data protection. This issue is fixed in iOS 16, macOS Ventura 13. A user with physical access to an iOS device may be able to read past diagnostic logs.

  • CVE-2021-27456LowMar 23, 2022
    risk 0.16cvss 2.4epss 0.00

    Philips Gemini PET/CT family software stores sensitive information in a removable media device that does not have built-in access control.

  • CVE-2019-19561LowNov 16, 2020
    risk 0.16cvss 2.4epss 0.00

    A misconfiguration in the debug interface in Mercedes-Benz HERMES 1.5 allows an attacker with direct physical access to device hardware to obtain cellular modem information.

  • CVE-2019-19557LowNov 16, 2020
    risk 0.16cvss 2.4epss 0.00

    A misconfiguration in the debug interface in Mercedes-Benz HERMES 1 allows an attacker with direct physical access to device hardware to obtain cellular modem information.

  • CVE-2020-4197LowMar 3, 2020
    risk 0.16cvss 2.4epss 0.00

    IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 174908.

  • CVE-2019-4265LowOct 10, 2019
    risk 0.16cvss 2.4epss 0.00

    IBM Maximo Anywhere 7.6.0, 7.6.1, 7.6.2, and 7.6.3 does not have device root detection which could result in an attacker gaining sensitive information about the device. IBM X-Force ID: 160198.

  • CVE-2023-37521LowJan 16, 2024
    risk 0.15cvss 2.3epss 0.00

    HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower can sometimes include sensitive information in a query string which could allow an attacker to execute a malicious attack.

  • CVE-2025-11644LowOct 12, 2025
    risk 0.13cvss 2.0epss 0.00

    A weakness has been identified in Tomofun Furbo 360 and Furbo Mini. Affected by this issue is some unknown functionality of the component UART Interface. Executing manipulation can lead to insecure storage of sensitive information. The physical device can be targeted for the…

  • CVE-2018-25031MedMar 11, 2022
    risk 0.03cvss 4.3epss 0.42

    Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could exploit this vulnerability to display remote OpenAPI definitions. Note: This was originally claimed to be resolved in 4.1.3.…

  • CVE-2024-52519LowNov 15, 2024
    risk 0.00cvss 2.7epss 0.00

    Nextcloud Server is a self hosted personal cloud system. The OAuth2 client secrets were stored in a recoverable way, so that an attacker that got access to a backup of the database and the Nextcloud config file, would be able to decrypt them. It is recommended that the Nextcloud…

  • CVE-2024-43427LowNov 11, 2024
    risk 0.00cvss 3.7epss 0.00

    A flaw was found in moodle. When creating an export of site administration presets, some sensitive secrets and keys are not being excluded from the export, which could result in them unintentionally being leaked if the presets are shared with a third party.

  • CVE-2023-22469MedJan 10, 2023
    risk 0.00cvss 5.8epss 0.01

    Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. When getting the reference preview for Deck cards the user has no access to, unauthorized user could eventually get the cached data of a user that…

  • CVE-2022-1021MedAug 19, 2022
    risk 0.00cvss 5.4epss 0.01

    Insecure Storage of Sensitive Information in GitHub repository chatwoot/chatwoot prior to 2.6.0.

  • CVE-2022-1044MedMay 12, 2022
    risk 0.00cvss 6.5epss 0.01

    Sensitive Data Exposure Due To Insecure Storage Of Profile Image in GitHub repository polonel/trudesk prior to v1.2.1.

  • CVE-2021-46440HigMay 3, 2022
    risk 0.00cvss 7.5epss 0.03

    Storing passwords in a recoverable format in the DOCUMENTATION plugin component of Strapi before 3.6.9 and 4.x before 4.1.5 allows an attacker to access a victim's HTTP request, get the victim's cookie, perform a base64 decode on the victim's cookie, and obtain a cleartext…