CWE-922 · 292 записей
Insecure Storage of Sensitive Information
CVE этого класса
292 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
44В плане | CVE-2020-13937Proof of concept | Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3apache · kylin · CWE-922 | Средняя5,3 | — | 78,3 % | 19 окт. 2020 г. |
44В плане | CVE-2021-27170Эксплойта нет | An issue was discovered on FiberHome HG6245D devices through RP2613.fiberhome · hg6245d firmware · CWE-922 | Критическая9,8 | — | 15,9 % | 10 февр. 2021 г. |
40В плане | CVE-2025-12539Proof of concept | TNC Toolbox: Web Performance <= 1.4.2 - Unauthenticated Sensitive Information Exposure to Privilege Escalation/cPanel Account Takeoverleopardhost · tnc toolbox: web performance · CWE-922 | Критическая10,0 | — | 1,1 % | 11 нояб. 2025 г. |
39Наблюдать | CVE-2021-42371Эксплойта нет | lpar2rrd is a hardcoded system account in XoruX LPAR2RRD and STOR2RRD before 7.30.xorux · lpar2rrd · CWE-922 | Критическая9,8 | — | 1,6 % | 8 нояб. 2021 г. |
39Наблюдать | CVE-2023-29727Эксплойта нет | The Call Blocker application 6.6.3 for Android allows unauthorized applications to use exposed components to delete data stored in its databapplika · call blocker · CWE-922 | Критическая9,8 | — | 1,2 % | 30 мая 2023 г. |
39Наблюдать | CVE-2017-5249Эксплойта нет | In version 6.1.0.19 and prior of Wink Labs's Wink - Smart Home Android app, the OAuth token used by the app to authorize user access is not wink · wink · CWE-922 | Критическая9,8 | — | 0,7 % | 22 февр. 2018 г. |
39Наблюдать | CVE-2017-5250Эксплойта нет | In version 1.9.7 and prior of Insteon's Insteon for Hub Android app, the OAuth token used by the app to authorize user access is not stored insteon · insteon for hub · CWE-922 | Критическая9,8 | — | 0,7 % | 22 февр. 2018 г. |
39Наблюдать | CVE-2022-44581Эксплойта нет | WordPress Defender Security plugin <= 3.3.2 - Broken Authentication vulnerabilitywpmudev · defender · CWE-922 | Критическая9,8 | — | 0,7 % | 17 мая 2024 г. |
39Наблюдать | CVE-2023-32191Эксплойта нет | rke's credentials are stored in the RKE1 Cluster state ConfigMapsuse · rke · CWE-922 | Критическая9,9 | — | 0,7 % | 16 окт. 2024 г. |
39Наблюдать | CVE-2023-0580Эксплойта нет | Information Disclosure vulnerability in My Control System (on-premise)abb · my control system · CWE-922 | Критическая9,8 | — | 0,5 % | 6 апр. 2023 г. |
39Наблюдать | CVE-2025-48929Эксплойта нет | The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token with a short expiratsmarsh · telemessage · CWE-922 | Критическая9,8 | — | 0,3 % | 28 мая 2025 г. |
38Наблюдать | CVE-2024-30896Proof of concept | InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows authorized users with rCWE-922 | Критическая9,1 | — | 5,4 % | 21 нояб. 2024 г. |
36Наблюдать | CVE-2017-7253Эксплойта нет | Dahua IP Camera devices 3.200.0001.6 can be exploited via these steps: 1.dahuasecurity · ip camera firmware · CWE-922 | Высокая8,8 | — | 2,6 % | 30 мар. 2017 г. |
36Наблюдать | CVE-2025-8699Эксплойта нет | Some "Stored Value" Unattended Payment Solutions of KioSoft use vulnerable NFC cards.kiosoft · stored value unattended payment solution · CWE-922 | Критическая9,1 | — | 0,7 % | 12 сент. 2025 г. |
36Наблюдать | CVE-2024-10943Эксплойта нет | FactoryTalk® Updater Authentication Bypassrockwell automation · factorytalk updater · CWE-922 | Критическая9,1 | — | 0,5 % | 12 нояб. 2024 г. |
35Наблюдать | CVE-2023-42913Эксплойта нет | This issue was addressed through improved state management.apple · macos · CWE-922 | Высокая8,8 | — | 0,5 % | 28 мар. 2024 г. |
35Наблюдать | CVE-2025-28244Эксплойта нет | Insecure Permissions vulnerability in the Local Storage in Alteryx Server 2023.1.1.460 allows remote attackers to obtain valid user session alteryx · alteryx server · CWE-922 | Высокая8,8 | — | 0,5 % | 10 июл. 2025 г. |
35Наблюдать | CVE-2025-10971Эксплойта нет | Insecure Storage of Sensitive Informationfermax electrónica s.a.u · meetme · CWE-922 | Высокая8,8 | — | 0,1 % | 2 дек. 2025 г. |
34Наблюдать | CVE-2024-47043Эксплойта нет | Ruijie Reyee OS Insecure Storage of Sensitive Informationruijienetworks · reyee os · CWE-922 | Высокая8,7 | — | 0,4 % | 6 дек. 2024 г. |
34Наблюдать | CVE-2025-14376Эксплойта нет | Verve Asset Manager – Plaintext Storage Vulnerabilitiesrockwell automation · verve asset manager · CWE-922 | Высокая8,6 | — | 0,1 % | 20 янв. 2026 г. |
32Наблюдать | CVE-2025-21299Эксплойта нет | Windows Kerberos Security Feature Bypass Vulnerabilitymicrosoft · windows 10 1507 · CWE-922 | Высокая7,8 | — | 2,2 % | 14 янв. 2025 г. |
32Наблюдать | CVE-2024-22773Эксплойта нет | Intelbras Action RF 1200 routers 1.2.2 and earlier and Action RG 1200 routers 2.1.7 and earlier expose the Password in Cookie resulting in Lintelbras · action rf 1200 firmware · CWE-922 | Высокая8,1 | — | 1,0 % | 5 февр. 2024 г. |
32Наблюдать | CVE-2024-52519Эксплойта нет | Nextcloud Server's OAuth2 client secrets were stored in a recoverable waynextcloud · nextcloud server · CWE-922 | Высокая8,2 | — | 0,5 % | 15 нояб. 2024 г. |
32Наблюдать | CVE-2025-2241Эксплойта нет | Hive: exposure of vcenter credentials via clusterprovision in hive / mce / acmred hat · multicluster engine for kubernetes · CWE-922 | Высокая8,2 | — | 0,5 % | 17 мар. 2025 г. |
32Наблюдать | CVE-2024-48770Эксплойта нет | An issue in Plug n Play Camera com.wisdomcity.zwave 1.1.0 allows a remote attacker to obtain sensitive information via the firmware update pCWE-922 | Высокая8,2 | — | 0,4 % | 11 окт. 2024 г. |
- CVE-2020-1393744В плане
Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3
СредняяCVSS 5,3Proof of conceptEPSS 78 %apache · kylin19 окт. 2020 г.
- CVE-2021-2717044В плане
An issue was discovered on FiberHome HG6245D devices through RP2613.
КритическаяCVSS 9,8Эксплойта нетEPSS 16 %fiberhome · hg6245d firmware10 февр. 2021 г.
- CVE-2025-1253940В плане
TNC Toolbox: Web Performance <= 1.4.2 - Unauthenticated Sensitive Information Exposure to Privilege Escalation/cPanel Account Takeover
КритическаяCVSS 10,0Proof of conceptEPSS 1 %leopardhost · tnc toolbox: web performance11 нояб. 2025 г.
- CVE-2021-4237139Наблюдать
lpar2rrd is a hardcoded system account in XoruX LPAR2RRD and STOR2RRD before 7.30.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %xorux · lpar2rrd8 нояб. 2021 г.
- CVE-2023-2972739Наблюдать
The Call Blocker application 6.6.3 for Android allows unauthorized applications to use exposed components to delete data stored in its datab
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %applika · call blocker30 мая 2023 г.
- CVE-2017-524939Наблюдать
In version 6.1.0.19 and prior of Wink Labs's Wink - Smart Home Android app, the OAuth token used by the app to authorize user access is not
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %wink · wink22 февр. 2018 г.
- CVE-2017-525039Наблюдать
In version 1.9.7 and prior of Insteon's Insteon for Hub Android app, the OAuth token used by the app to authorize user access is not stored
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %insteon · insteon for hub22 февр. 2018 г.
- CVE-2022-4458139Наблюдать
WordPress Defender Security plugin <= 3.3.2 - Broken Authentication vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %wpmudev · defender17 мая 2024 г.
- CVE-2023-3219139Наблюдать
rke's credentials are stored in the RKE1 Cluster state ConfigMap
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %suse · rke16 окт. 2024 г.
- CVE-2023-058039Наблюдать
Information Disclosure vulnerability in My Control System (on-premise)
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %abb · my control system6 апр. 2023 г.
- CVE-2025-4892939Наблюдать
The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token with a short expirat
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %smarsh · telemessage28 мая 2025 г.
- CVE-2024-3089638Наблюдать
InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows authorized users with r
КритическаяCVSS 9,1Proof of conceptEPSS 5 %21 нояб. 2024 г.
- CVE-2017-725336Наблюдать
Dahua IP Camera devices 3.200.0001.6 can be exploited via these steps: 1.
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %dahuasecurity · ip camera firmware30 мар. 2017 г.
- CVE-2025-869936Наблюдать
Some "Stored Value" Unattended Payment Solutions of KioSoft use vulnerable NFC cards.
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %kiosoft · stored value unattended payment solution12 сент. 2025 г.
- CVE-2024-1094336Наблюдать
FactoryTalk® Updater Authentication Bypass
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %rockwell automation · factorytalk updater12 нояб. 2024 г.
- CVE-2023-4291335Наблюдать
This issue was addressed through improved state management.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %apple · macos28 мар. 2024 г.
- CVE-2025-2824435Наблюдать
Insecure Permissions vulnerability in the Local Storage in Alteryx Server 2023.1.1.460 allows remote attackers to obtain valid user session
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %alteryx · alteryx server10 июл. 2025 г.
- CVE-2025-1097135Наблюдать
Insecure Storage of Sensitive Information
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %fermax electrónica s.a.u · meetme2 дек. 2025 г.
- CVE-2024-4704334Наблюдать
Ruijie Reyee OS Insecure Storage of Sensitive Information
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %ruijienetworks · reyee os6 дек. 2024 г.
- CVE-2025-1437634Наблюдать
Verve Asset Manager – Plaintext Storage Vulnerabilities
ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %rockwell automation · verve asset manager20 янв. 2026 г.
- CVE-2025-2129932Наблюдать
Windows Kerberos Security Feature Bypass Vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %microsoft · windows 10 150714 янв. 2025 г.
- CVE-2024-2277332Наблюдать
Intelbras Action RF 1200 routers 1.2.2 and earlier and Action RG 1200 routers 2.1.7 and earlier expose the Password in Cookie resulting in L
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %intelbras · action rf 1200 firmware5 февр. 2024 г.
- CVE-2024-5251932Наблюдать
Nextcloud Server's OAuth2 client secrets were stored in a recoverable way
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %nextcloud · nextcloud server15 нояб. 2024 г.
- CVE-2025-224132Наблюдать
Hive: exposure of vcenter credentials via clusterprovision in hive / mce / acm
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %red hat · multicluster engine for kubernetes17 мар. 2025 г.
- CVE-2024-4877032Наблюдать
An issue in Plug n Play Camera com.wisdomcity.zwave 1.1.0 allows a remote attacker to obtain sensitive information via the firmware update p
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %11 окт. 2024 г.