VYPR

CWE-922

Insecure Storage of Sensitive Information

ClassIncomplete

Description

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

If read access is not properly restricted, then attackers can steal the sensitive information. If write access is not properly restricted, then attackers can modify and possibly delete the data, causing incorrect results and possibly a denial of service.

Hierarchy (View 1000)

Parents

CVEs mapped to this weakness (381)

page 3 of 20
  • CVE-2024-42018HigOct 11, 2024
    risk 0.50cvss 7.7epss 0.00

    An issue was discovered in Atos Eviden SMC xScale before 1.6.6. During initialization of nodes, some configuration parameters are retrieved from management nodes. These parameters embed credentials whose integrity and confidentiality may be important to the security of the HPC…

  • CVE-2024-29968HigApr 19, 2024
    risk 0.50cvss 7.7epss 0.00

    An information disclosure vulnerability exists in Brocade SANnav before v2.3.1 and v2.3.0a when Brocade SANnav instances are configured in disaster recovery mode. SQL Table names, column names, and SQL queries are collected in DR standby Supportsave. This could allow…

  • CVE-2023-43633HigSep 21, 2023
    risk 0.50cvss 8.8epss 0.00

    On boot, the Pillar eve container checks for the existence and content of “/config/GlobalConfig/global.json”. If the file exists, it overrides the existing configuration on the device on boot. This allows an attacker to change the system’s configuration, which also…

  • CVE-2023-43631HigSep 21, 2023
    risk 0.50cvss 8.8epss 0.00

    On boot, the Pillar eve container checks for the existence and content of “/config/authorized_keys”. If the file is present, and contains a supported public key, the container will go on to open port 22 and enable sshd with the given keys as the authorized keys for root…

  • CVE-2023-43630HigSep 20, 2023
    risk 0.50cvss 8.8epss 0.00

    PCR14 is not in the list of PCRs that seal/unseal the “vault” key, but due to the change that was implemented in commit “7638364bc0acf8b5c481b5ce5fea11ad44ad7fd4”, fixing this issue alone would not solve the problem of the config partition not being measured correctly. …

  • CVE-2025-70963HigFeb 6, 2026
    risk 0.49cvss 7.6epss 0.00

    Gophish <=0.12.1 is vulnerable to Incorrect Access Control. The administrative dashboard exposes each user’s long-lived API key directly inside the rendered HTML/JavaScript of the page on every login. This makes permanent API credentials accessible to any script running in the…

  • CVE-2024-12315HigFeb 12, 2025
    risk 0.49cvss 7.5epss 0.00

    The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.3 via the exports directory. This makes it possible for unauthenticated attackers to extract sensitive data…

  • CVE-2024-57546HigJan 27, 2025
    risk 0.49cvss 7.5epss 0.01

    An issue in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to the validate link function.

  • CVE-2025-22984HigJan 14, 2025
    risk 0.49cvss 7.5epss 0.01

    An access control issue in the component /api/squareComment/DelectSquareById of iceCMS v2.2.0 allows unauthenticated attackers to access sensitive information.

  • CVE-2025-22983HigJan 14, 2025
    risk 0.49cvss 7.5epss 0.01

    An access control issue in the component /square/getAllSquare/circle of iceCMS v2.2.0 allows unauthenticated attackers to access sensitive information.

  • CVE-2024-56113HigJan 9, 2025
    risk 0.49cvss 7.5epss 0.01

    Smart Toilet Lab - Motius 1.3.11 is running with debug mode turned on (DEBUG = True) and exposing sensitive information defined in Django settings file through verbose error page.

  • CVE-2024-47043HigDec 6, 2024
    risk 0.49cvss 7.5epss 0.00

    Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could enable an attacker to correlate a device serial number and the user's phone number and part of the email address.

  • CVE-2024-48939HigNov 11, 2024
    risk 0.49cvss 7.5epss 0.01

    Insufficient validation performed on the REST API License file in Paxton Net2 before 6.07.14023.5015 (SR4) enables use of the REST API with an invalid License File. Attackers may be able to retrieve access-log data.

  • CVE-2024-10028HigNov 6, 2024
    risk 0.49cvss 7.5epss 0.00

    The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.13 via the exposed process stats file during the backup process. This makes it…

  • CVE-2024-48353HigNov 1, 2024
    risk 0.49cvss 7.5epss 0.00

    Yealink Meeting Server before V26.0.0.67 allows attackers to obtain static key information from a front-end JS file and decrypt the plaintext passwords based on the obtained key information.

  • CVE-2024-48352HigNov 1, 2024
    risk 0.49cvss 7.5epss 0.00

    Yealink Meeting Server before V26.0.0.67 is vulnerable to sensitive data exposure in the server response via sending HTTP request with enterprise ID.

  • CVE-2024-48783HigOct 15, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue in Ruijie NBR3000D-E Gateway allows a remote attacker to obtain sensitive information via the /tool/shell/postgresql.conf component.

  • CVE-2024-39339HigSep 18, 2024
    risk 0.49cvss 7.5epss 0.00

    A vulnerability has been discovered in all versions of Smartplay headunits, which are widely used in Suzuki and Toyota cars. This misconfiguration can lead to information disclosure, leaking sensitive details such as diagnostic log traces, system logs, headunit passwords, and…

  • CVE-2024-37728HigSep 10, 2024
    risk 0.49cvss 7.5epss 0.02

    Arbitrary File Read vulnerability in Xi'an Daxi Information Technology Co., Ltd OfficeWeb365 v.7.18.23.0 and v8.6.1.0 allows a remote attacker to obtain sensitive information via the "Pic/Indexes" interface

  • CVE-2024-38453HigJul 3, 2024
    risk 0.49cvss 7.5epss 0.00

    The Avalara for Salesforce CPQ app before 7.0 for Salesforce allows attackers to read an API key. NOTE: the current version is 11 as of mid-2024.