Перейти к содержимому
Noroxi

CWE-922 · 292 записей

Insecure Storage of Sensitive Information

CVE этого класса

292 записей

  • CVE-2020-13937
    44В плане

    Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3

    СредняяCVSS 5,3Proof of conceptEPSS 78 %

    apache · kylin19 окт. 2020 г.

  • CVE-2021-27170
    44В плане

    An issue was discovered on FiberHome HG6245D devices through RP2613.

    КритическаяCVSS 9,8Эксплойта нетEPSS 16 %

    fiberhome · hg6245d firmware10 февр. 2021 г.

  • CVE-2025-12539
    40В плане

    TNC Toolbox: Web Performance <= 1.4.2 - Unauthenticated Sensitive Information Exposure to Privilege Escalation/cPanel Account Takeover

    КритическаяCVSS 10,0Proof of conceptEPSS 1 %

    leopardhost · tnc toolbox: web performance11 нояб. 2025 г.

  • CVE-2021-42371
    39Наблюдать

    lpar2rrd is a hardcoded system account in XoruX LPAR2RRD and STOR2RRD before 7.30.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    xorux · lpar2rrd8 нояб. 2021 г.

  • CVE-2023-29727
    39Наблюдать

    The Call Blocker application 6.6.3 for Android allows unauthorized applications to use exposed components to delete data stored in its datab

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    applika · call blocker30 мая 2023 г.

  • CVE-2017-5249
    39Наблюдать

    In version 6.1.0.19 and prior of Wink Labs's Wink - Smart Home Android app, the OAuth token used by the app to authorize user access is not

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    wink · wink22 февр. 2018 г.

  • CVE-2017-5250
    39Наблюдать

    In version 1.9.7 and prior of Insteon's Insteon for Hub Android app, the OAuth token used by the app to authorize user access is not stored

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    insteon · insteon for hub22 февр. 2018 г.

  • CVE-2022-44581
    39Наблюдать

    WordPress Defender Security plugin <= 3.3.2 - Broken Authentication vulnerability

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    wpmudev · defender17 мая 2024 г.

  • CVE-2023-32191
    39Наблюдать

    rke's credentials are stored in the RKE1 Cluster state ConfigMap

    КритическаяCVSS 9,9Эксплойта нетEPSS 1 %

    suse · rke16 окт. 2024 г.

  • CVE-2023-0580
    39Наблюдать

    Information Disclosure vulnerability in My Control System (on-premise)

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    abb · my control system6 апр. 2023 г.

  • CVE-2025-48929
    39Наблюдать

    The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token with a short expirat

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    smarsh · telemessage28 мая 2025 г.

  • CVE-2024-30896
    38Наблюдать

    InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows authorized users with r

    КритическаяCVSS 9,1Proof of conceptEPSS 5 %

    21 нояб. 2024 г.

  • CVE-2017-7253
    36Наблюдать

    Dahua IP Camera devices 3.200.0001.6 can be exploited via these steps: 1.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %

    dahuasecurity · ip camera firmware30 мар. 2017 г.

  • CVE-2025-8699
    36Наблюдать

    Some "Stored Value" Unattended Payment Solutions of KioSoft use vulnerable NFC cards.

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    kiosoft · stored value unattended payment solution12 сент. 2025 г.

  • CVE-2024-10943
    36Наблюдать

    FactoryTalk® Updater Authentication Bypass

    КритическаяCVSS 9,1Эксплойта нетEPSS 0 %

    rockwell automation · factorytalk updater12 нояб. 2024 г.

  • CVE-2023-42913
    35Наблюдать

    This issue was addressed through improved state management.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    apple · macos28 мар. 2024 г.

  • CVE-2025-28244
    35Наблюдать

    Insecure Permissions vulnerability in the Local Storage in Alteryx Server 2023.1.1.460 allows remote attackers to obtain valid user session

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    alteryx · alteryx server10 июл. 2025 г.

  • CVE-2025-10971
    35Наблюдать

    Insecure Storage of Sensitive Information

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    fermax electrónica s.a.u · meetme2 дек. 2025 г.

  • CVE-2024-47043
    34Наблюдать

    Ruijie Reyee OS Insecure Storage of Sensitive Information

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    ruijienetworks · reyee os6 дек. 2024 г.

  • CVE-2025-14376
    34Наблюдать

    Verve Asset Manager – Plaintext Storage Vulnerabilities

    ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %

    rockwell automation · verve asset manager20 янв. 2026 г.

  • CVE-2025-21299
    32Наблюдать

    Windows Kerberos Security Feature Bypass Vulnerability

    ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %

    microsoft · windows 10 150714 янв. 2025 г.

  • CVE-2024-22773
    32Наблюдать

    Intelbras Action RF 1200 routers 1.2.2 and earlier and Action RG 1200 routers 2.1.7 and earlier expose the Password in Cookie resulting in L

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    intelbras · action rf 1200 firmware5 февр. 2024 г.

  • CVE-2024-52519
    32Наблюдать

    Nextcloud Server's OAuth2 client secrets were stored in a recoverable way

    ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %

    nextcloud · nextcloud server15 нояб. 2024 г.

  • CVE-2025-2241
    32Наблюдать

    Hive: exposure of vcenter credentials via clusterprovision in hive / mce / acm

    ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %

    red hat · multicluster engine for kubernetes17 мар. 2025 г.

  • CVE-2024-48770
    32Наблюдать

    An issue in Plug n Play Camera com.wisdomcity.zwave 1.1.0 allows a remote attacker to obtain sensitive information via the firmware update p

    ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %

    11 окт. 2024 г.

Все классы уязвимостей