← Back
CWE-922

373 CVEs • Abstraction: Class

Insecure Storage of Sensitive Information

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

JSON object

Loading...

CVEs (373)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
5.3 MEDIUM· v3
4.6 MEDIUM· v2
cPanel before 74.0.0 insecurely stores phpMyAdmin session files (SEC-418).
1Rdbrck
1Shift
Jun 17, 2026
Jul 17, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Redbrick Shift through 3.4.3 allows an attacker to extract authentication tokens of services (such as Gmail, Outlook, etc.) used in the application.
1Rdbrck
1Shift
Jun 17, 2026
Jul 17, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Redbrick Shift through 3.4.3 allows an attacker to extract authentication tokens of services (such as Gmail, Outlook, etc.) used in the application.
1Bluecats
1Bc Reveal
Jun 17, 2026
May 22, 2019
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
The iOS mobile application BlueCats Reveal before 5.14 stores the username and password in the app cache as base64 encoded strings, i.e. clear text. These persist in the cache even if the user logs out. This can allow an...Show more
The iOS mobile application BlueCats Reveal before 5.14 stores the username and password in the app cache as base64 encoded strings, i.e. clear text. These persist in the cache even if the user logs out. This can allow an attacker to compromise the affected BlueCats network implementation. The attacker would first need to gain physical control of the iOS device or compromise it with a malicious app.Show less
1Bluecats
1Bluecats Reveal
Jun 17, 2026
May 22, 2019
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
The Android mobile application BlueCats Reveal before 3.0.19 stores the username and password in a clear text file. This file persists until the user logs out or the session times out from non-usage (30 days of no user a...Show more
The Android mobile application BlueCats Reveal before 3.0.19 stores the username and password in a clear text file. This file persists until the user logs out or the session times out from non-usage (30 days of no user activity). This can allow an attacker to compromise the affected BlueCats network implementation. The attacker would first need to gain physical control of the Android device or compromise it with a malicious app.Show less
1Eaton
1Halo Home
Jun 17, 2026
May 22, 2019
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
The Android mobile application Halo Home before 1.11.0 stores OAuth authentication and refresh access tokens in a clear text file. This file persists until the user logs out of the application and reboots the device. Thi...Show more
The Android mobile application Halo Home before 1.11.0 stores OAuth authentication and refresh access tokens in a clear text file. This file persists until the user logs out of the application and reboots the device. This vulnerability can allow an attacker to impersonate the legitimate user by reusing the stored OAuth token, thus allowing them to view and change the user's personal information stored in the backend cloud service. The attacker would first need to gain physical control of the Android device or compromise it with a malicious app.Show less
1Suse
1Manager
Jun 17, 2026
May 13, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
SUSE Manager until version 4.0.7 and Uyuni until commit 1b426ad5ed0a7191a6fb46bb83e98ae4b99a5ade created world-readable swap files on systems that don't have a swap already configured and don't have btrfs as filesystem
1Insteon
1Insteon For Hub
Nov 21, 2024
Feb 22, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In version 1.9.7 and prior of Insteon's Insteon for Hub Android app, the OAuth token used by the app to authorize user access is not stored in an encrypted and secure manner.
1Wink
1Wink
Nov 21, 2024
Feb 22, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In version 6.1.0.19 and prior of Wink Labs's Wink - Smart Home Android app, the OAuth token used by the app to authorize user access is not stored in an encrypted and secure manner.
1Sandisk
1Secureaccess
May 13, 2026
Nov 16, 2017
N/A· v4
4.3 MEDIUM· v3
2.1 LOW· v2
SanDisk Secure Access 3.01 vault decrypts and copies encrypted files to a temporary folder, where they can remain indefinitely in certain situations, such as if the file is being edited when the user exits the applicatio...Show more
SanDisk Secure Access 3.01 vault decrypts and copies encrypted files to a temporary folder, where they can remain indefinitely in certain situations, such as if the file is being edited when the user exits the application or if the application crashes.Show less
1Google
1Android
May 13, 2026
May 12, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An information disclosure vulnerability in File-Based Encryption could enable a local malicious attacker to bypass operating system protections for the lock screen. This issue is rated as Moderate due to the possibility...Show more
An information disclosure vulnerability in File-Based Encryption could enable a local malicious attacker to bypass operating system protections for the lock screen. This issue is rated as Moderate due to the possibility of bypassing the lock screen. Product: Android. Versions: 7.0, 7.1.1. Android ID: A-32793550.Show less
1Dahuasecurity
1Ip Camera Firmware
May 13, 2026
Mar 30, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Dahua IP Camera devices 3.200.0001.6 can be exploited via these steps: 1. Use the default low-privilege credentials to list all users via a request to a certain URI. 2. Login to the IP camera with admin credentials so as...Show more
Dahua IP Camera devices 3.200.0001.6 can be exploited via these steps: 1. Use the default low-privilege credentials to list all users via a request to a certain URI. 2. Login to the IP camera with admin credentials so as to obtain full control of the target IP camera. During exploitation, the first JSON object encountered has a "Component error: login challenge!" message. The second JSON object encountered has a result indicating a successful admin login.Show less
1Usb Pratirodh Project
1Usb Pratirodh
May 13, 2026
Mar 23, 2017
N/A· v4
6.6 MEDIUM· v3
2.1 LOW· v2
USB Pratirodh is prone to sensitive information disclosure. It stores sensitive information such as username and password in simple usb.xml. An attacker with physical access to the system can modify the file according hi...Show more
USB Pratirodh is prone to sensitive information disclosure. It stores sensitive information such as username and password in simple usb.xml. An attacker with physical access to the system can modify the file according his own requirements that may aid in further attack.Show less