← Back
CWE-922

373 CVEs • Abstraction: Class

Insecure Storage of Sensitive Information

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

JSON object

Loading...

CVEs (373)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Furbo
2Furbo 360 Dog Camera Firmware
Furbo Mini Firmware
Jun 17, 2026
Oct 12, 2025
0.3 LOW· v4
4.2 MEDIUM· v3
1.2 LOW· v2
A weakness has been identified in Tomofun Furbo 360 and Furbo Mini. Affected by this issue is some unknown functionality of the component UART Interface. Executing manipulation can lead to insecure storage of sensitive i...Show more
A weakness has been identified in Tomofun Furbo 360 and Furbo Mini. Affected by this issue is some unknown functionality of the component UART Interface. Executing manipulation can lead to insecure storage of sensitive information. The physical device can be targeted for the attack. This attack is characterized by high complexity. The exploitation is known to be difficult. The firmware versions determined to be affected are Furbo 360 up to FB0035_FW_036 and Furbo Mini up to MC0020_FW_074. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Furbo
2Furbo 360 Dog Camera Firmware
Furbo Mini Firmware
Jun 17, 2026
Oct 12, 2025
4.8 MEDIUM· v4
5.5 MEDIUM· v3
1.7 LOW· v2
A vulnerability has been found in Tomofun Furbo 360 and Furbo Mini. The impacted element is an unknown function of the file collect_logs.sh of the component Debug Log S3 Bucket Handler. The manipulation leads to insecure...Show more
A vulnerability has been found in Tomofun Furbo 360 and Furbo Mini. The impacted element is an unknown function of the file collect_logs.sh of the component Debug Log S3 Bucket Handler. The manipulation leads to insecure storage of sensitive information. An attack has to be approached locally. The firmware versions determined to be affected are Furbo 360 up to FB0035_FW_036 and Furbo Mini up to MC0020_FW_074. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Samsung
1Wear Os
Jun 17, 2026
Oct 10, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Insecure storage of sensitive information in Galaxy Watch prior to SMR Oct-2025 Release 1 allows local attackers to access sensitive information.
1Newforma
1Project Center
Jun 17, 2026
Oct 9, 2025
4.8 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
Newforma Info Exchange (NIX) stores credentials used to configure NPCS in 'HKLM\Software\WOW6432Node\Newforma\<version>\Credentials'. The credentials are encrypted but the encryption key is stored in the same registry l...Show more
Newforma Info Exchange (NIX) stores credentials used to configure NPCS in 'HKLM\Software\WOW6432Node\Newforma\<version>\Credentials'. The credentials are encrypted but the encryption key is stored in the same registry location. Authenticated users can access both the credentials and the encryption key. If these are Active Directory credentials, an attacker may be able to gain access to additional systems and resources.Show less
1Vasion
2Virtual Appliance Application
Virtual Appliance Host
Jun 17, 2026
Sep 19, 2025
6.9 MEDIUM· v4
7.8 HIGH· v3
N/A· v2
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 1.0.735 and Application versions prior to 20.0.1330 (macOS/Linux client deployments) contain a vulnerability in the local inter-process commun...Show more
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 1.0.735 and Application versions prior to 20.0.1330 (macOS/Linux client deployments) contain a vulnerability in the local inter-process communication (IPC) mechanism. The software stores IPC request and response files inside /opt/PrinterInstallerClient/tmp with world-readable and world-writable permissions. Any local user can craft malicious request files that are processed by privileged daemons, leading to unauthorized actions being executed in other user sessions. This breaks user session isolation, potentially allowing local attackers to hijack sessions, perform unintended actions in the context of other users, and impact system integrity and availability. This vulnerability has been identified by the vendor as: V-2022-004 — Client Inter-process Security.Show less
1Apple
2Ipados
Iphone Os
Jun 17, 2026
Sep 15, 2025
N/A· v4
4.0 MEDIUM· v3
N/A· v2
The issue was addressed with improved handling of caches. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26. An attacker with physical access to an unlocked device may be able to view an image in the...Show more
The issue was addressed with improved handling of caches. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26. An attacker with physical access to an unlocked device may be able to view an image in the most recently viewed locked note.Show less
-
-
Jun 17, 2026
Sep 12, 2025
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Some "Stored Value" Unattended Payment Solutions of KioSoft use vulnerable NFC cards. Attackers could potentially use this vulnerability to change the balance on the cards and generate money. The account balance is store...Show more
Some "Stored Value" Unattended Payment Solutions of KioSoft use vulnerable NFC cards. Attackers could potentially use this vulnerability to change the balance on the cards and generate money. The account balance is stored on an insecure MiFare Classic NFC card and can be read and written back. By carefully observing changes in card dumps, one can identify fields that store the cash value of the card. Additionally, a checksum can be identified, which is created by XOR-ing the cash and an unknown field with a certain value. By updating the fields accordingly, arbitrary amounts of money can be loaded onto the card (up to $655,35) to pay for goods.Show less
-
-
Jun 17, 2026
Sep 9, 2025
5.1 MEDIUM· v4
N/A· v3
N/A· v2
Insecure Storage of Sensitive Information vulnerability in Calix GigaCenter ONT (Quantenna SoC modules) allows admin access to the web interface.This issue affects GigaCenter ONT: 844E, 844G, 844GE, 854GE.
1Samsung
1Android
Jun 17, 2026
Sep 3, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Insecure Storage of Sensitive Information in Secure Folder prior to Android 16 allows local attackers to access sensitive information.
-
-
Jun 17, 2026
Aug 29, 2025
7.1 HIGH· v4
6.5 MEDIUM· v3
N/A· v2
Multiple products provided by iND Co.,Ltd contain an insecure storage of sensitive information vulnerability. If exploited, configuration information, such as admin password, may be disclosed. As for the details of affec...Show more
Multiple products provided by iND Co.,Ltd contain an insecure storage of sensitive information vulnerability. If exploited, configuration information, such as admin password, may be disclosed. As for the details of affected product names and versions, refer to the information under [Product Status].Show less
1Kapsch
2Ris 9160 Firmware
Ris 9260 Firmware
Jun 17, 2026
Aug 26, 2025
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Incorrect access control in the EEPROM component of Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 allows attackers to replace password hashes stored in the...Show more
Incorrect access control in the EEPROM component of Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 allows attackers to replace password hashes stored in the EEPROM with hashes of their own, leading to the escalation of privileges to root.Show less
14cstrategies
1Exonaut
Jun 17, 2026
Aug 6, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An issue was discovered in 4C Strategies Exonaut 21.6. Passwords, stored in the database, are hashed without a salt.
-
-
Jun 17, 2026
Jul 31, 2025
N/A· v4
6.0 MEDIUM· v3
N/A· v2
A vulnerability was discovered in the storage policy for certain sets of sensitive credential information in the HPE Telco Network Function Virtual Orchestrator. Successful Exploitation could lead to unauthorized parties...Show more
A vulnerability was discovered in the storage policy for certain sets of sensitive credential information in the HPE Telco Network Function Virtual Orchestrator. Successful Exploitation could lead to unauthorized parties gaining access to sensitive system information.Show less
1Grandstream
1Ucm6510 Firmware
Jul 5, 2026
Jul 29, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue in Grandstream UCM6510 v.1.0.20.52 and before allows a remote attacker to obtain sensitive information via the Login function at /cgi and /webrtccgi.
1Alteryx
1Alteryx Server
Jun 17, 2026
Jul 10, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
Insecure Permissions vulnerability in the Local Storage in Alteryx Server 2023.1.1.460 allows remote attackers to obtain valid user session tokens from localStorage, leading to account takeover
1Samsung
1Android
Jun 17, 2026
Jul 8, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Insecure storage of sensitive information in Emergency SOS prior to SMR Jul-2025 Release 1 allows local attackers to access sensitive information.
-
-
Jun 17, 2026
Jul 8, 2025
N/A· v4
5.6 MEDIUM· v3
N/A· v2
The GuiXT application, which is integrated with SAP GUI for Windows, uses obfuscation algorithms instead of secure symmetric ciphers for storing the credentials of an RFC user on the client PC. This leads to a high impac...Show more
The GuiXT application, which is integrated with SAP GUI for Windows, uses obfuscation algorithms instead of secure symmetric ciphers for storing the credentials of an RFC user on the client PC. This leads to a high impact on confidentiality because any attacker who gains access to the user hive of this user�s windows registry could recreate the original password. There is no impact on integrity or availability of the applicationShow less
-
-
Jun 17, 2026
Jun 10, 2025
N/A· v4
7.7 HIGH· v3
N/A· v2
A vulnerability in the APIs of HPE Aruba Networking Private 5G Core could potentially expose sensitive information to unauthorized users. A successful exploitation could allow an attacker to iteratively navigate through...Show more
A vulnerability in the APIs of HPE Aruba Networking Private 5G Core could potentially expose sensitive information to unauthorized users. A successful exploitation could allow an attacker to iteratively navigate through the filesystem and ultimately download protected system files containing sensitive information.Show less
1Smarsh
1Telemessage
Jun 17, 2026
May 28, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token with a short expiration time) that can be reused at a later date if discovered by an adversary.
-
-
Jun 17, 2026
May 22, 2025
5.1 MEDIUM· v4
6.5 MEDIUM· v3
N/A· v2
Serialized configuration information may be disclosed during device commissioning while using ASPECT's configuration toolsetThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: thr...Show more
Serialized configuration information may be disclosed during device commissioning while using ASPECT's configuration toolsetThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.Show less