CWE-922
373 CVEs • Abstraction: Class
Insecure Storage of Sensitive Information
The product stores sensitive information without properly limiting read or write access by unauthorized actors.
CVEs (373)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Veritas System Recovery (VSR) versions 18 and 21 store a network destination password in the Windows registry during configuration of the backup configuration. This vulnerability could provide a Windows user (who has suf...Show more |
Torguard VPN 4.8, has a vulnerability that allows an attacker to dump sensitive information, such as credentials and information about the server, without admin privileges. |
The Blink1Control2 application <= 2.2.7 uses weak password encryption and an insecure method of storage. |
Insecure Storage of Sensitive Information in GitHub repository chatwoot/chatwoot prior to 2.6.0. |
In Brocade SANnav before Brocade SANnav v2.2.0.2 and Brocade SANnav2.1.1.8, encoded scp-server passwords are stored using Base64 encoding, which could allow an attacker able to access log files to easily decode the passw...Show more |
Improper auto-fill algorithm in Samsung Internet prior to version 17.0.1.69 allows physical attackers to guess stored credit card numbers. |
1Flightradar24 1Flightradar24 Flight Tracker Jun 17, 2026 Jun 2, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in FlightRadar24 v8.9.0, v8.10.0, v8.10.2, v8.10.3, v8.10.4 for Android, allows attackers to cause unspecified consequences due to being able to decompile a local application and extract their API...Show more |
Sensitive Data Exposure Due To Insecure Storage Of Profile Image in GitHub repository polonel/trudesk prior to v1.2.1. |
An insecure data storage vulnerability allows a physical attacker with root privileges to retrieve TOTP secret keys from unlocked phones in Sophos Authenticator for Android version 3.4 and older, and Intercept X for Mobi...Show more |
Insecure storage of sensitive information vulnerability in MA for Linux, macOS, and Windows prior to 5.7.6 allows a local user to gain access to sensitive information through storage in ma.db. The sensitive information h...Show more |
1Phillips 11Gemini 882160 Firmware Gemini 882300 FirmwareGemini 882390 Firmware+8 moreJun 17, 2026 Mar 23, 2022 N/A· v4 2.4 LOW· v3 2.1 LOW· v2 Philips Gemini PET/CT family software stores sensitive information in a removable media device that does not have built-in access control. |
Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could exploit this vulnerability to display remote OpenAPI definitions. No...Show more |
Insecure Storage of Sensitive Information in GitHub repository chocobozzz/peertube prior to 4.1.1. |
In JetBrains TeamCity before 2021.2.3, environment variables of the "password" type could be logged in some cases. |
Insecure Storage of Sensitive Information in GitHub repository microweber/microweber prior to 1.3. |
A insecure storage of sensitive information vulnerability exists in Ivanti Workspace Control <2021.2 (10.7.30.0) that could allow an attacker with locally authenticated low privileges to obtain key information due to an...Show more |
An issue existed in the storage of sensitive tokens. This issue was addressed by placing the tokens in Keychain. This issue is fixed in macOS High Sierra 10.13. A local attacker may gain access to iCloud authentication t...Show more |
Insecure storage of device information in Contacts prior to version 12.7.05.24 allows attacker to get Samsung Account ID. |
Insecure storage of device information in Samsung Dialer prior to version 12.7.05.24 allows attacker to get Samsung Account ID. |
Insecure storage of sensitive information vulnerability in Smart Capture prior to version 4.8.02.10 allows attacker to access victim's captured images without permission. |