VYPR

CWE-922

Insecure Storage of Sensitive Information

ClassIncomplete

Description

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

If read access is not properly restricted, then attackers can steal the sensitive information. If write access is not properly restricted, then attackers can modify and possibly delete the data, causing incorrect results and possibly a denial of service.

Hierarchy (View 1000)

Parents

CVEs mapped to this weakness (381)

page 6 of 20
  • CVE-2022-1257MedApr 14, 2022
    risk 0.43cvss 6.1epss 0.01

    Insecure storage of sensitive information vulnerability in MA for Linux, macOS, and Windows prior to 5.7.6 allows a local user to gain access to sensitive information through storage in ma.db. The sensitive information has been moved to encrypted database files.

  • CVE-2020-5262HigMar 19, 2020
    risk 0.43cvss 7.7epss 0.01

    In EasyBuild before version 4.1.2, the GitHub Personal Access Token (PAT) used by EasyBuild for the GitHub integration features (like `--new-pr`, `--fro,-pr`, etc.) is shown in plain text in EasyBuild debug log files. This issue is fixed in EasyBuild v4.1.2, and in the `master`+…

  • CVE-2017-6911MedMar 23, 2017
    risk 0.43cvss 6.6epss 0.01

    USB Pratirodh is prone to sensitive information disclosure. It stores sensitive information such as username and password in simple usb.xml. An attacker with physical access to the system can modify the file according his own requirements that may aid in further attack.

  • CVE-2025-10464MedFeb 9, 2026
    risk 0.42cvss 6.5epss 0.00

    Insecure Storage of Sensitive Information vulnerability in Birtech Information Technologies Industry and Trade Ltd. Co. Senseway allows Retrieve Embedded Sensitive Data. This issue affects Senseway: through 09022026. NOTE: Because the product was developed using outdated…

  • CVE-2025-53507MedAug 29, 2025
    risk 0.42cvss 6.5epss 0.00

    Multiple products provided by iND Co.,Ltd contain an insecure storage of sensitive information vulnerability. If exploited, configuration information, such as admin password, may be disclosed. As for the details of affected product names and versions, refer to the information…

  • CVE-2025-28171MedJul 29, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in Grandstream UCM6510 v.1.0.20.52 and before allows a remote attacker to obtain sensitive information via the Login function at /cgi and /webrtccgi.

  • CVE-2024-13954MedMay 22, 2025
    risk 0.42cvss 6.5epss 0.00

    Serialized configuration information may be disclosed during device commissioning while using ASPECT's configuration toolsetThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

  • CVE-2024-54728MedJan 27, 2025
    risk 0.42cvss 6.5epss 0.00

    Incorrect access control in BYD QIN PLUS DM-i Dilink OS 3.0_13.1.7.2204050.1 allows unauthorized attackers to access system logcat logs.

  • CVE-2024-56972MedJan 27, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in Midea Group Co., Ltd Midea Home iOS 9.3.12 allows attackers to access sensitive user information via supplying a crafted link.

  • CVE-2024-56971MedJan 27, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in Zhiyuan Yuedu (Guangzhou) Literature Information Technology Co., Ltd Shuqi Novel iOS 5.3.8 allows attackers to access sensitive user information via supplying a crafted link.

  • CVE-2024-56969MedJan 27, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in Pixocial Technology (Singapore) Pte. Ltd BeautyPlus iOS 7.8.010 allows attackers to access sensitive user information via supplying a crafted link.

  • CVE-2024-56968MedJan 27, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in Shenzhen Intellirocks Tech Co. Ltd Govee Home iOS 6.5.01 allows attackers to access sensitive user information via supplying a crafted payload.

  • CVE-2024-56967MedJan 27, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in Cloud Whale Interactive Technology LLC. PolyBuzz iOS 2.0.20 allows attackers to access sensitive user information via supplying a crafted link.

  • CVE-2024-56966MedJan 27, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in Shanghai Xuan Ting Entertainment Information & Technology Co., Ltd Qidian Reader iOS 5.9.384 allows attackers to access sensitive user information via supplying a crafted link.

  • CVE-2024-56965MedJan 27, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in Shanghai Shizhi Information Technology Co., Ltd Shihuo iOS 8.16.0 allows attackers to access sensitive user information via supplying a crafted link.

  • CVE-2024-56964MedJan 27, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in Che Hao Duo Used Automobile Agency (Beijing) Co., Ltd Guazi Used Car iOS 10.15.1 allows attackers to access sensitive user information via supplying a crafted link.

  • CVE-2024-56963MedJan 27, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in Beijing Sogou Technology Development Co., Ltd Sogou Input iOS 12.2.0 allows attackers to access sensitive user information via supplying a crafted link.

  • CVE-2024-56962MedJan 27, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in Tencent Technology (Shanghai) Co., Ltd WeSing iOS v9.3.39 allows attackers to access sensitive user information via supplying a crafted link.

  • CVE-2024-56960MedJan 27, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in Tianjin Xiaowu Information technology Co., Ltd BeiKe Holdings iOS 1.3.50 allows attackers to access sensitive user information via supplying a crafted link.

  • CVE-2024-56959MedJan 27, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in Mashang Consumer Finance Co., Ltd Anyihua iOS 3.6.2 allows attackers to access sensitive user information via supplying a crafted link.