← Back
CWE-922

377 CVEs • Abstraction: Class

Insecure Storage of Sensitive Information

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

JSON object

Loading...

CVEs (377)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 17, 2026
Jul 8, 2025
N/A· v4
5.6 MEDIUM· v3
N/A· v2
The GuiXT application, which is integrated with SAP GUI for Windows, uses obfuscation algorithms instead of secure symmetric ciphers for storing the credentials of an RFC user on the client PC. This leads to a high impac...Show more
The GuiXT application, which is integrated with SAP GUI for Windows, uses obfuscation algorithms instead of secure symmetric ciphers for storing the credentials of an RFC user on the client PC. This leads to a high impact on confidentiality because any attacker who gains access to the user hive of this user�s windows registry could recreate the original password. There is no impact on integrity or availability of the applicationShow less
-
-
Jun 17, 2026
Jun 10, 2025
N/A· v4
7.7 HIGH· v3
N/A· v2
A vulnerability in the APIs of HPE Aruba Networking Private 5G Core could potentially expose sensitive information to unauthorized users. A successful exploitation could allow an attacker to iteratively navigate through...Show more
A vulnerability in the APIs of HPE Aruba Networking Private 5G Core could potentially expose sensitive information to unauthorized users. A successful exploitation could allow an attacker to iteratively navigate through the filesystem and ultimately download protected system files containing sensitive information.Show less
1Smarsh
1Telemessage
Jun 17, 2026
May 28, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token with a short expiration time) that can be reused at a later date if discovered by an adversary.
-
-
Jun 17, 2026
May 22, 2025
5.1 MEDIUM· v4
6.5 MEDIUM· v3
N/A· v2
Serialized configuration information may be disclosed during device commissioning while using ASPECT's configuration toolsetThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: thr...Show more
Serialized configuration information may be disclosed during device commissioning while using ASPECT's configuration toolsetThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.Show less
1Rhymix
1Rhymix
Jul 5, 2026
May 5, 2025
N/A· v4
7.7 HIGH· v3
N/A· v2
Rhymix v2.1.22 was discovered to contain an arbitrary file deletion vulnerability via the procFileAdminEditImage method in /file/file.admin.controller.php.
1Tenda
1Rx2 Pro Firmware
Jun 17, 2026
May 1, 2025
N/A· v4
8.2 HIGH· v3
N/A· v2
Use of weak credentials in the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated attacker to authenticate to the telnet service by calculating the root password based on easily-obtained device information. The password...Show more
Use of weak credentials in the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated attacker to authenticate to the telnet service by calculating the root password based on easily-obtained device information. The password is based on the last two digits/octets of the MAC address.Show less
-
-
Jun 17, 2026
Apr 9, 2025
4.1 MEDIUM· v4
4.2 MEDIUM· v3
N/A· v2
CWE-922: Insecure Storage of Sensitive Information vulnerability exists that could potentially lead to unauthorized access of confidential data when a malicious user, having physical access and advanced information on th...Show more
CWE-922: Insecure Storage of Sensitive Information vulnerability exists that could potentially lead to unauthorized access of confidential data when a malicious user, having physical access and advanced information on the file system, sets the radio in factory default mode.Show less
1Microsoft
13Windows 10 1507
Windows 10 1607Windows 10 1809+10 more
Jun 17, 2026
Apr 8, 2025
N/A· v4
7.1 HIGH· v3
N/A· v2
Insecure storage of sensitive information in Windows Kerberos allows an authorized attacker to bypass a security feature locally.
1Samsung
1Wear Os
Jun 17, 2026
Apr 8, 2025
N/A· v4
6.2 MEDIUM· v3
N/A· v2
Improper access control in Galaxy Watch prior to SMR Apr-2025 Release 1 allows local attackers to access sensitive information of Galaxy watch.
-
-
Jun 17, 2026
Mar 18, 2025
6.8 MEDIUM· v4
N/A· v3
N/A· v2
Insecure information storage vulnerability in NTFS Tools version 3.5.1. Exploitation of this vulnerability could allow an attacker to know the application password, stored in /Users/user/Library/Application Support/ntfs-...Show more
Insecure information storage vulnerability in NTFS Tools version 3.5.1. Exploitation of this vulnerability could allow an attacker to know the application password, stored in /Users/user/Library/Application Support/ntfs-tool/config.json.Show less
-
-
Aug 21, 2026
Mar 17, 2025
N/A· v4
8.2 HIGH· v3
N/A· v2
A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VS...Show more
A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read access to ClusterProvision objects can extract sensitive credentials even if they do not have direct access to Kubernetes Secrets. This issue can lead to unauthorized VCenter access, cluster management, and privilege escalation.Show less
-
-
Jun 17, 2026
Mar 15, 2025
N/A· v4
3.3 LOW· v3
N/A· v2
A flaw was found in Foreman/Red Hat Satellite. Improper file permissions allow low-privileged OS users to monitor and access temporary files under /var/tmp, exposing sensitive command outputs, such as /etc/shadow. This i...Show more
A flaw was found in Foreman/Red Hat Satellite. Improper file permissions allow low-privileged OS users to monitor and access temporary files under /var/tmp, exposing sensitive command outputs, such as /etc/shadow. This issue can lead to information disclosure and privilege escalation if exploited effectively.Show less
1Samsung
1Wear Os
Jun 17, 2026
Mar 6, 2025
N/A· v4
6.2 MEDIUM· v3
N/A· v2
Incorrect default permission in DiagMonAgent prior to SMR Mar-2025 Release 1 allows local attackers to access data within Galaxy Watch.
1Openatom
1Openharmony
Jun 17, 2026
Mar 4, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
in OpenHarmony v5.0.2 and prior versions allow a local attacker cause information leak through out-of-bounds read bypass permission check.
-
-
Jun 17, 2026
Feb 28, 2025
N/A· v4
6.3 MEDIUM· v3
N/A· v2
The connection string visible to users with access to FRSCore database on Foreseer Reporting Software (FRS) VM, this string can be used for gaining administrative access to the 4crXref database. This vulnerability has be...Show more
The connection string visible to users with access to FRSCore database on Foreseer Reporting Software (FRS) VM, this string can be used for gaining administrative access to the 4crXref database. This vulnerability has been resolved in the latest version 1.5.100 of FRS.Show less
1Smackcoders
1Export All Posts, Products, Orders, Refunds & Users
Jun 17, 2026
Feb 12, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.3 via the exports directory. This makes it possible f...Show more
The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.3 via the exports directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads/smack_uci_uploads/exports/ directory which can contain information like exported user data.Show less
1Samsung
1Android
Jun 17, 2026
Feb 4, 2025
N/A· v4
4.4 MEDIUM· v3
N/A· v2
Inclusion of sensitive information in test code in softsim trustlet prior to SMR Jan-2025 Release 1 allows local privileged attackers to get test key.
1Ruoyi
1Ruoyi
Jun 17, 2026
Jan 29, 2025
N/A· v4
7.2 HIGH· v3
N/A· v2
RuoYi v4.8.0 was discovered to allow unauthorized attackers to view the session ID of the admin in the system monitoring. This issue can allow attackers to impersonate Admin users via using a crafted cookie.
1Cmsimple
1Cmsimple
Jun 17, 2026
Jan 27, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to the validate link function.
-
-
Jun 17, 2026
Jan 27, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Incorrect access control in BYD QIN PLUS DM-i Dilink OS 3.0_13.1.7.2204050.1 allows unauthorized attackers to access system logcat logs.