CWE-922
373 CVEs • Abstraction: Class
Insecure Storage of Sensitive Information
The product stores sensitive information without properly limiting read or write access by unauthorized actors.
CVEs (373)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A Insecure Storage of Sensitive Information vulnerability in openSUSE opensuse-welcome allows local attackers to execute code as the user that runs opensuse-welcome if a custom layout is chosen This issue affects opensus...Show more |
Sending some requests in the web application of the vulnerable device allows information to be obtained due to the lack of security in the authentication process. |
A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application stores sensitive application data in an external insecure storage. This could allow an atta...Show more |
Insecure storage of sensitive information in Wing FTP Server (User Web Client) allows information elicitation.This issue affects Wing FTP Server: <= 7.2.0.
|
1Ibm 1Sterling External Authentication Server Jun 17, 2026 Sep 5, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 IBM Sterling Secure Proxy 6.0.3 and 6.1.0 could allow a local user with specific information about the system to obtain privileged information due to inadequate memory clearing during operations. IBM X-Force ID: 252139...Show more |
1Arubanetworks 1Edgeconnect Sd Wan Orchestrator Jun 17, 2026 Aug 22, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator...Show more |
Information disclosure in password protected surveys in Data Illusion Survey Software Solutions NGSurvey v2.4.28 and below allows attackers to view the password to access and arbitrarily submit surveys. |
Progress Chef Infra Server before 15.7 allows a local attacker to exploit a /var/opt/opscode/local-mode-cache/backup world-readable temporary backup path to access sensitive information, resulting in the disclosure of al...Show more |
1Elecom 5Wrc 1167febk A Firmware Wrc 1167febk S FirmwareWrc 1167gebk S Firmware+2 moreJun 17, 2026 Jul 13, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 ELECOM wireless LAN routers are vulnerable to sensitive information exposure, which allows a network-adjacent unauthorized attacker to obtain sensitive information. Affected products and versions are as follows: WRC-1167...Show more |
HCL Launch could disclose sensitive information if a manual edit of a configuration file has been performed.
|
1Apple 4Ipados Iphone OsMacos+1 moreJun 17, 2026 Jun 23, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 16.5 and iPadOS 16.5, tvOS 16.5, macOS Ventura 13.4. An app may be able to read sensitive location information. |
1Open Xchange 1Open Xchange Appsuite Backend Jun 17, 2026 Jun 20, 2023 N/A· v4 3.3 LOW· v3 N/A· v2 Default permissions for a properties file were too permissive. Local system users could read potentially sensitive information. We updated the default permissions for noreply.properties set during package installation. N...Show more |
An issue found in Blue Light Filter v.1.5.5 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the SharedPreference files. |
An issue found in Twilight v.13.3 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the SharedPreference files. |
Anonymous user may get the list of existing users managed by the application, that could ease further attacks (see CVE-2023-3065 and 3066)This issue affects Mobatime mobile application AMXGT100 through 1.3.20.
|
The Call Blocker application 6.6.3 for Android allows unauthorized applications to use exposed components to delete data stored in its database that is related to user privacy settings and affects the implementation of t...Show more |
Storage of Sensitive Data in a Mechanism without Access Control in GitHub repository francoisjacquet/rosariosis prior to 11.0. |
1Selinc 10Sel 2241 Rtac Module Firmware Sel 3350 FirmwareSel 3505 3 Firmware+7 moreJun 17, 2026 May 10, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A Storing Passwords in a Recoverable Format vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) database system could allow an authenticated attacker to retrieve passwords...Show more |
Insecure storage of sensitive information in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of privilege via local access. |
Insecure storage of sensitive information in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of privilege via local access. |