CWE-922
Insecure Storage of Sensitive Information
Description
The product stores sensitive information without properly limiting read or write access by unauthorized actors.
Hierarchy (View 1000)
CVEs mapped to this weakness (381)
page 4 of 20| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-22808 | Hig | 0.49 | 7.5 | 0.01 | Apr 22, 2024 | An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to cause a Denial of Service (DoS) by disrupting the communication between the PathPilot controller and the CNC router via overwriting the card's name in the device memory. | ||
| CVE-2024-28069 | Hig | 0.49 | 7.5 | 0.01 | Mar 16, 2024 | A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct an information disclosure attack due to improper configuration. A successful exploit could allow an attacker to access sensitive… | ||
| CVE-2024-1936 | Hig | 0.49 | 7.5 | 0.01 | Mar 4, 2024 | The encrypted subject of an email message could be incorrectly and permanently assigned to an arbitrary other email message in Thunderbird's local cache. Consequently, when replying to the contaminated email message, the user might accidentally leak the confidential subject to a… | ||
| CVE-2024-25728 | Hig | 0.49 | 7.5 | 0.01 | Feb 11, 2024 | ExpressVPN before 12.73.0 on Windows, when split tunneling is used, sends DNS requests according to the Windows configuration (e.g., sends them to DNS servers operated by the user's ISP instead of to the ExpressVPN DNS servers), which may allow remote attackers to obtain… | ||
| CVE-2023-41965 | Hig | 0.49 | 7.5 | 0.01 | Sep 18, 2023 | Sending some requests in the web application of the vulnerable device allows information to be obtained due to the lack of security in the authentication process. | ||
| CVE-2022-46484 | Hig | 0.49 | 7.5 | 0.01 | Aug 2, 2023 | Information disclosure in password protected surveys in Data Illusion Survey Software Solutions NGSurvey v2.4.28 and below allows attackers to view the password to access and arbitrarily submit surveys. | ||
| CVE-2023-3064 | Hig | 0.49 | 7.5 | 0.01 | Jun 5, 2023 | Anonymous user may get the list of existing users managed by the application, that could ease further attacks (see CVE-2023-3065 and 3066)This issue affects Mobatime mobile application AMXGT100 through 1.3.20. | ||
| CVE-2021-36546 | Hig | 0.49 | 7.5 | 0.01 | Feb 3, 2023 | Incorrect Access Control issue discovered in KiteCMS 1.1 allows remote attackers to view sensitive information via path in application URL. | ||
| CVE-2022-41876 | Hig | 0.49 | 7.5 | 0.01 | Nov 10, 2022 | ezplatform-graphql is a GraphQL server implementation for Ibexa DXP and Ibexa Open Source. Versions prior to 2.3.12 and 1.0.13 are subject to Insecure Storage of Sensitive Information. Unauthenticated GraphQL queries for user accounts can expose password hashes of users that… | ||
| CVE-2022-37835 | Hig | 0.49 | 7.5 | 0.01 | Sep 12, 2022 | Torguard VPN 4.8, has a vulnerability that allows an attacker to dump sensitive information, such as credentials and information about the server, without admin privileges. | ||
| CVE-2022-28168 | Hig | 0.49 | 7.5 | 0.01 | Jun 27, 2022 | In Brocade SANnav before Brocade SANnav v2.2.0.2 and Brocade SANnav2.1.1.8, encoded scp-server passwords are stored using Base64 encoding, which could allow an attacker able to access log files to easily decode the passwords. | ||
| CVE-2022-25264 | Hig | 0.49 | 7.5 | 0.01 | Feb 25, 2022 | In JetBrains TeamCity before 2021.2.3, environment variables of the "password" type could be logged in some cases. | ||
| CVE-2021-36786 | Hig | 0.49 | 7.5 | 0.01 | Aug 13, 2021 | The miniorange_saml (aka Miniorange Saml) extension before 1.4.3 for TYPO3 allows Sensitive Data Exposure of API credentials and private keys. | ||
| CVE-2021-22914 | Hig | 0.49 | 7.5 | 0.01 | Jun 16, 2021 | Citrix Cloud Connector before 6.31.0.62192 suffers from insecure storage of sensitive information due to sensitive information being stored in the Citrix Cloud Connector installation log files. Such information could be used by an malicious actor to access a Citrix Cloud… | ||
| CVE-2021-25776 | Hig | 0.49 | 7.5 | 0.01 | Feb 3, 2021 | In JetBrains TeamCity before 2020.2, an ECR token could be exposed in a build's parameters. | ||
| CVE-2020-26104 | Hig | 0.49 | 7.5 | 0.01 | Sep 25, 2020 | In cPanel before 88.0.3, an insecure SRS secret is used on a templated VM (SEC-552). | ||
| CVE-2020-15775 | Hig | 0.49 | 7.5 | 0.01 | Sep 18, 2020 | An issue was discovered in Gradle Enterprise 2017.1 - 2020.2.4. The /usage page of Gradle Enterprise conveys high level build information such as project names and build counts over time. This page is incorrectly viewable anonymously. | ||
| CVE-2020-7000 | Hig | 0.49 | 7.5 | 0.01 | Apr 3, 2020 | VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow an unauthenticated attacker to discover the cryptographic key from the web server and gain information about the login and the encryption/decryption mechanism, which may be exploited to bypass… | ||
| CVE-2019-20060 | Hig | 0.49 | 7.5 | 0.01 | Feb 10, 2020 | MFScripts YetiShare v3.5.2 through v4.5.4 places sensitive information in the Referer header. If this leaks, then third parties may discover password-reset hashes, file-delete links, or other sensitive information. | ||
| CVE-2019-12914 | Hig | 0.49 | 7.5 | 0.01 | Jul 17, 2019 | Redbrick Shift through 3.4.3 allows an attacker to extract authentication tokens of services (such as Gmail, Outlook, etc.) used in the application. |
- risk 0.49cvss 7.5epss 0.01
An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to cause a Denial of Service (DoS) by disrupting the communication between the PathPilot controller and the CNC router via overwriting the card's name in the device memory.
- risk 0.49cvss 7.5epss 0.01
A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct an information disclosure attack due to improper configuration. A successful exploit could allow an attacker to access sensitive…
- risk 0.49cvss 7.5epss 0.01
The encrypted subject of an email message could be incorrectly and permanently assigned to an arbitrary other email message in Thunderbird's local cache. Consequently, when replying to the contaminated email message, the user might accidentally leak the confidential subject to a…
- risk 0.49cvss 7.5epss 0.01
ExpressVPN before 12.73.0 on Windows, when split tunneling is used, sends DNS requests according to the Windows configuration (e.g., sends them to DNS servers operated by the user's ISP instead of to the ExpressVPN DNS servers), which may allow remote attackers to obtain…
- risk 0.49cvss 7.5epss 0.01
Sending some requests in the web application of the vulnerable device allows information to be obtained due to the lack of security in the authentication process.
- risk 0.49cvss 7.5epss 0.01
Information disclosure in password protected surveys in Data Illusion Survey Software Solutions NGSurvey v2.4.28 and below allows attackers to view the password to access and arbitrarily submit surveys.
- risk 0.49cvss 7.5epss 0.01
Anonymous user may get the list of existing users managed by the application, that could ease further attacks (see CVE-2023-3065 and 3066)This issue affects Mobatime mobile application AMXGT100 through 1.3.20.
- risk 0.49cvss 7.5epss 0.01
Incorrect Access Control issue discovered in KiteCMS 1.1 allows remote attackers to view sensitive information via path in application URL.
- risk 0.49cvss 7.5epss 0.01
ezplatform-graphql is a GraphQL server implementation for Ibexa DXP and Ibexa Open Source. Versions prior to 2.3.12 and 1.0.13 are subject to Insecure Storage of Sensitive Information. Unauthenticated GraphQL queries for user accounts can expose password hashes of users that…
- risk 0.49cvss 7.5epss 0.01
Torguard VPN 4.8, has a vulnerability that allows an attacker to dump sensitive information, such as credentials and information about the server, without admin privileges.
- risk 0.49cvss 7.5epss 0.01
In Brocade SANnav before Brocade SANnav v2.2.0.2 and Brocade SANnav2.1.1.8, encoded scp-server passwords are stored using Base64 encoding, which could allow an attacker able to access log files to easily decode the passwords.
- risk 0.49cvss 7.5epss 0.01
In JetBrains TeamCity before 2021.2.3, environment variables of the "password" type could be logged in some cases.
- risk 0.49cvss 7.5epss 0.01
The miniorange_saml (aka Miniorange Saml) extension before 1.4.3 for TYPO3 allows Sensitive Data Exposure of API credentials and private keys.
- risk 0.49cvss 7.5epss 0.01
Citrix Cloud Connector before 6.31.0.62192 suffers from insecure storage of sensitive information due to sensitive information being stored in the Citrix Cloud Connector installation log files. Such information could be used by an malicious actor to access a Citrix Cloud…
- risk 0.49cvss 7.5epss 0.01
In JetBrains TeamCity before 2020.2, an ECR token could be exposed in a build's parameters.
- risk 0.49cvss 7.5epss 0.01
In cPanel before 88.0.3, an insecure SRS secret is used on a templated VM (SEC-552).
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Gradle Enterprise 2017.1 - 2020.2.4. The /usage page of Gradle Enterprise conveys high level build information such as project names and build counts over time. This page is incorrectly viewable anonymously.
- risk 0.49cvss 7.5epss 0.01
VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow an unauthenticated attacker to discover the cryptographic key from the web server and gain information about the login and the encryption/decryption mechanism, which may be exploited to bypass…
- risk 0.49cvss 7.5epss 0.01
MFScripts YetiShare v3.5.2 through v4.5.4 places sensitive information in the Referer header. If this leaks, then third parties may discover password-reset hashes, file-delete links, or other sensitive information.
- risk 0.49cvss 7.5epss 0.01
Redbrick Shift through 3.4.3 allows an attacker to extract authentication tokens of services (such as Gmail, Outlook, etc.) used in the application.