İçeriğe atla
Noroxi

CWE-212 · 101 kayıt

Improper Removal of Sensitive Information Before Storage or Transfer

Bu sınıftaki CVE’ler

101 kayıt

  • m00nl1ght-dev/steam-workshop-deploy: Exposure of Version-Control Repository to an Unauthorized Control Sphere and Insufficiently Protected C

    KritikCVSS 10,0İstismar yok

    GitHub Actions · m00nl1ght-dev/steam-workshop-deploy13 Ağu 2025

  • CVE-2022-1650
    38İzleyin

    Improper Removal of Sensitive Information Before Storage or Transfer in eventsource/eventsource

    KritikCVSS 9,3İstismar yokEPSS %2

    eventsource · eventsource12 May 2022

  • CVE-2020-15094
    36İzleyin

    In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient class from the HttpClient Symfony component relies on the HttpCache class

    YüksekCVSS 8,8İstismar yokEPSS %3

    sensiolabs · httpclient2 Eyl 2020

  • CVE-2021-0340
    36İzleyin

    In parseNextBox of IsoInterface.java, there is a possible leak of unredacted location information due to improper input validation.

    YüksekCVSS 8,8Kavram kanıtıEPSS %2

    google · android10 Şub 2021

  • CVE-2020-11684
    36İzleyin

    AT91bootstrap before 3.9.2 does not properly wipe encryption and authentication keys from memory before passing control to a less privileged

    KritikCVSS 9,1İstismar yokEPSS %1

    linux4sam · at91bootstrap14 Eyl 2020

  • CVE-2022-2818
    35İzleyin

    Improper Removal of Sensitive Information Before Storage or Transfer in cockpit-hq/cockpit

    YüksekCVSS 8,8İstismar yokEPSS %2

    agentejo · cockpit15 Ağu 2022

  • CVE-2019-13402
    35İzleyin

    /usr/sbin/default.sh and /usr/apache/htdocs/cgi-bin/admin/hardfactorydefault.cgi on Dynacolor FCM-MB40 v1.2.0.0 devices implement an incompl

    YüksekCVSS 8,8İstismar yokEPSS %2

    fortinet · fcm-mb40 firmware7 Tem 2019

  • CVE-2022-30617
    35İzleyin

    An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, fo

    YüksekCVSS 8,8İstismar yokEPSS %1

    strapi · strapi19 May 2022

  • CVE-2026-39937
    35İzleyin

    Global vanishing does not completely remove user email

    YüksekCVSS 8,8İstismar yokEPSS %0

    the wikimedia foundation · mediawiki - centralauth extension7 Nis 2026

  • CVE-2026-85094
    35İzleyin

    The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privileged WebView.

    YüksekCVSS 8,8İstismar yokEPSS %0

    canva · canva4 Eyl 2026

  • CVE-2026-27640
    34İzleyin

    tfplan2md has Sensitive Value Exposure in Generated Reports

    YüksekCVSS 8,5İstismar yokEPSS %0

    oocx · tfplan2md25 Şub 2026

  • CVE-2024-43384
    32İzleyin

    Phoenix Contact: Improper removal of sensitive information in MGUARD products

    YüksekCVSS 8,0İstismar yokEPSS %0

    phoenixcontact · fl mguard 2102 firmware7 May 2026

  • CVE-2025-65965
    32İzleyin

    Grype has a credential disclosure vulnerability in Grype JSON output

    YüksekCVSS 8,2İstismar yokEPSS %0

    anchore · grype25 Kas 2025

  • CVE-2020-1940
    31İzleyin

    The optional initial password change and password expiration features present in Apache Jackrabbit Oak 1.2.0 to 1.22.0 are prone to a sensit

    YüksekCVSS 7,5İstismar yokEPSS %5

    apache · jackrabbit oak28 Oca 2020

  • CVE-2002-0704
    31İzleyin

    The Network Address Translation (NAT) capability for Netfilter ("iptables") 1.2.6a and earlier leaks translated IP addresses in ICMP error m

    YüksekCVSS 7,5İstismar yokEPSS %3

    linux · linux kernel26 Tem 2002

  • CVE-2022-0355
    31İzleyin

    Improper Removal of Sensitive Information Before Storage or Transfer in feross/simple-get

    YüksekCVSS 7,5İstismar yokEPSS %2

    simple-get project · simple-get26 Oca 2022

  • CVE-2019-20637
    31İzleyin

    An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1.

    YüksekCVSS 7,5İstismar yokEPSS %2

    varnish-cache · varnish cache8 Nis 2020

  • CVE-2018-6337
    31İzleyin

    folly::secureRandom will re-use a buffer between parent and child processes when fork() is called.

    YüksekCVSS 7,5İstismar yokEPSS %2

    facebook · folly31 Ara 2018

  • CVE-2020-36476
    30İzleyin

    An issue was discovered in Mbed TLS before 2.24.0 (and before 2.16.8 LTS and before 2.7.17 LTS).

    YüksekCVSS 7,5İstismar yokEPSS %2

    arm · mbed tls22 Ağu 2021

  • CVE-2022-24798
    30İzleyin

    Insufficient password hash filtering in some IRRd queries and exports

    YüksekCVSS 7,5İstismar yokEPSS %1

    internet routing registry daemon project · internet routing registry daemon31 Mar 2022

  • CVE-2024-49997
    30İzleyin

    net: ethernet: lantiq_etop: fix memory disclosure

    YüksekCVSS 7,5İstismar yokEPSS %1

    linux · linux kernel21 Eki 2024

  • CVE-2021-31780
    30İzleyin

    In app/Model/MispObject.php in MISP 2.4.141, an incorrect sharing group association could lead to information disclosure on an event edit.

    YüksekCVSS 7,5İstismar yokEPSS %1

    misp-project · misp23 Nis 2021

  • CVE-2022-30618
    30İzleyin

    An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, fo

    YüksekCVSS 7,5İstismar yokEPSS %1

    strapi · strapi19 May 2022

  • CVE-2021-46813
    30İzleyin

    Vulnerability of residual files not being deleted after an update in the ChinaDRM module.

    YüksekCVSS 7,5İstismar yokEPSS %1

    huawei · emui13 Haz 2022

  • CVE-2022-3460
    30İzleyin

    In affected versions of Octopus Deploy it is possible for certain types of sensitive variables to inadvertently become unmasked when viewed

    YüksekCVSS 7,5İstismar yokEPSS %1

    octopus · octopus server2 Oca 2023

Tüm zafiyet sınıfları