← Back
CWE-922

373 CVEs • Abstraction: Class

Insecure Storage of Sensitive Information

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

JSON object

Loading...

CVEs (373)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 17, 2026
Sep 30, 2024
N/A· v4
5.9 MEDIUM· v3
N/A· v2
An issue in the API endpoint /AccountMaster/GetCurrentUserInfo of INROAD before v202402060 allows attackers to access sensitive information via a crafted payload to the UserNameOrPhoneNumber parameter.
1Gotenna
1Gotenna Pro
Jun 17, 2026
Sep 26, 2024
5.1 MEDIUM· v4
6.5 MEDIUM· v3
N/A· v2
In the goTenna Pro App, the encryption keys are stored along with a static IV on the End User Device (EUD). This allows for complete decryption of keys stored on the EUD if physically compromised. This allows an attac...Show more
In the goTenna Pro App, the encryption keys are stored along with a static IV on the End User Device (EUD). This allows for complete decryption of keys stored on the EUD if physically compromised. This allows an attacker to decrypt all encrypted broadcast communications based on encryption keys stored on the EUD. This requires access to and control of the EUD, so it is recommended to use strong access control measures and layered encryption on the EUD for more secure operation.Show less
1Gotenna
1Gotenna
Jun 17, 2026
Sep 26, 2024
6.0 MEDIUM· v4
6.5 MEDIUM· v3
N/A· v2
The goTenna Pro ATAK plugin uses a weak password for sharing encryption keys via the key broadcast method. If the broadcasted encryption key is captured over RF, and password is cracked via brute force attack, it is p...Show more
The goTenna Pro ATAK plugin uses a weak password for sharing encryption keys via the key broadcast method. If the broadcasted encryption key is captured over RF, and password is cracked via brute force attack, it is possible to decrypt it and use it to decrypt all future and past messages sent via encrypted broadcast with that particular key. This only applies when the key is broadcasted over RF. This is an optional feature, so it is advised to use local QR encryption key sharing for additional security on this and previous versions.Show less
1Gotenna
1Atak Plugin
Jun 17, 2026
Sep 26, 2024
5.1 MEDIUM· v4
6.5 MEDIUM· v3
N/A· v2
In the goTenna Pro ATAK Plugin application, the encryption keys are stored along with a static IV on the device. This allows for complete decryption of keys stored on the device. This allows an attacker to decrypt all...Show more
In the goTenna Pro ATAK Plugin application, the encryption keys are stored along with a static IV on the device. This allows for complete decryption of keys stored on the device. This allows an attacker to decrypt all encrypted broadcast communications based on broadcast keys stored on the device.Show less
1Apache
1Maven Archetype
Jun 17, 2026
Sep 26, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Exposure of Sensitive Information to an Unauthorized Actor, Insecure Storage of Sensitive Information vulnerability in Maven Archetype Plugin. This issue affects Maven Archetype Plugin: from 3.2.1 before 3.3.0. Users a...Show more
Exposure of Sensitive Information to an Unauthorized Actor, Insecure Storage of Sensitive Information vulnerability in Maven Archetype Plugin. This issue affects Maven Archetype Plugin: from 3.2.1 before 3.3.0. Users are recommended to upgrade to version 3.3.0, which fixes the issue. Archetype integration testing creates a file called ./target/classes/archetype-it/archetype-settings.xml This file contains all the content from the users ~/.m2/settings.xml file, which often contains information they do not want to publish. We expect that on many developer machines, this also contains credentials. When the user runs mvn verify again (without a mvn clean), this file becomes part of the final artifact. If a developer were to publish this into Maven Central or any other remote repository (whether as a release or a snapshot) their credentials would be published without them knowing.Show less
-
-
Jun 17, 2026
Sep 18, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
A vulnerability has been discovered in all versions of Smartplay headunits, which are widely used in Suzuki and Toyota cars. This misconfiguration can lead to information disclosure, leaking sensitive details such as dia...Show more
A vulnerability has been discovered in all versions of Smartplay headunits, which are widely used in Suzuki and Toyota cars. This misconfiguration can lead to information disclosure, leaking sensitive details such as diagnostic log traces, system logs, headunit passwords, and personally identifiable information (PII). The exposure of such information may have serious implications for user privacy and system integrity.Show less
-
-
Jun 17, 2026
Sep 10, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Arbitrary File Read vulnerability in Xi'an Daxi Information Technology Co., Ltd OfficeWeb365 v.7.18.23.0 and v8.6.1.0 allows a remote attacker to obtain sensitive information via the "Pic/Indexes" interface
1Openatom
1Openharmony
Jun 17, 2026
Sep 2, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
in OpenHarmony v4.1.0 and prior versions allow a remote attacker cause information leak through out-of-bounds Read.
1Openatom
1Openharmony
Jun 17, 2026
Sep 2, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.
1Openatom
1Openharmony
Jun 17, 2026
Sep 2, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.
1Wolfssl
1Wolfssl
Jun 17, 2026
Aug 27, 2024
N/A· v4
5.9 MEDIUM· v3
N/A· v2
An issue was discovered in wolfSSL before 5.7.0. A safe-error attack via Rowhammer, namely FAULT+PROBE, leads to ECDSA key disclosure. When WOLFSSL_CHECK_SIG_FAULTS is used in signing operations with private ECC keys, s...Show more
An issue was discovered in wolfSSL before 5.7.0. A safe-error attack via Rowhammer, namely FAULT+PROBE, leads to ECDSA key disclosure. When WOLFSSL_CHECK_SIG_FAULTS is used in signing operations with private ECC keys, such as in server-side TLS connections, the connection is halted if any fault occurs. The success rate in a certain amount of connection requests can be processed via an advanced technique for ECDSA key recovery.Show less
1Isellerpal
1Enterprise Resource Management System
Jun 17, 2026
Aug 15, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An issue in Huizhi enterprise resource management system v.1.0 and before allows a local attacker to obtain sensitive information via the /nssys/common/filehandle. Aspx component
1Ivanti
1Neurons For Itsm
Jun 17, 2026
Aug 13, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An information disclosure vulnerability in Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier allows an unauthenticated attacker to obtain the OIDC client secret via debug information.
1Apple
1Macos
Jun 17, 2026
Jul 29, 2024
N/A· v4
3.3 LOW· v3
N/A· v2
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6. An app may be able to view a contact's phone number in system logs.
1Apple
3Ipados
Iphone OsWatchos
Jun 17, 2026
Jul 29, 2024
N/A· v4
4.6 MEDIUM· v3
N/A· v2
A lock screen issue was addressed with improved state management. This issue is fixed in iOS 17.6 and iPadOS 17.6, watchOS 10.6. An attacker with physical access may be able to use Siri to access sensitive user data.
1Zowe
1Zowe Cli
Jun 17, 2026
Jul 19, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A vulnerability in Zowe CLI allows local, privileged actors to display securely stored properties in cleartext within a terminal using the '--show-inputs-only' flag.
1Apache
1Streampark
Jun 17, 2026
Jul 17, 2024
N/A· v4
5.9 MEDIUM· v3
N/A· v2
In Streampark (version < 2.1.4), when a user logged in successfully, the Backend service would return "Authorization" as the front-end authentication credential. User can use this credential to request other users' info...Show more
In Streampark (version < 2.1.4), when a user logged in successfully, the Backend service would return "Authorization" as the front-end authentication credential. User can use this credential to request other users' information, including the administrator's username, password, salt value, etc.  Mitigation: all users should upgrade to 2.1.4Show less
-
-
Jun 17, 2026
Jul 15, 2024
5.1 MEDIUM· v4
N/A· v3
N/A· v2
The vulnerability allows a malicious low-privileged PAM user to access information about other PAM users and their group memberships.
1Google
1Android
Jun 17, 2026
Jul 9, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In ensureFileColumns of MediaProvider.java, there is a possible disclosure of files owned by another user due to improper input validation. This could lead to local information disclosure with no additional execution pri...Show more
In ensureFileColumns of MediaProvider.java, there is a possible disclosure of files owned by another user due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Show less
-
-
Jun 17, 2026
Jul 3, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
The Avalara for Salesforce CPQ app before 7.0 for Salesforce allows attackers to read an API key. NOTE: the current version is 11 as of mid-2024.