CWE-212 · 101 записей
Improper Removal of Sensitive Information Before Storage or Transfer
CVE этого класса
101 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | GHSA-x6gv-2rvh-qmp6Эксплойта нет | m00nl1ght-dev/steam-workshop-deploy: Exposure of Version-Control Repository to an Unauthorized Control Sphere and Insufficiently Protected CGitHub Actions · m00nl1ght-dev/steam-workshop-deploy · CWE-212 | Критическая10,0 | — | — | 13 авг. 2025 г. |
38Наблюдать | CVE-2022-1650Эксплойта нет | Improper Removal of Sensitive Information Before Storage or Transfer in eventsource/eventsourceeventsource · eventsource · CWE-212 | Критическая9,3 | — | 1,9 % | 12 мая 2022 г. |
36Наблюдать | CVE-2020-15094Эксплойта нет | In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient class from the HttpClient Symfony component relies on the HttpCache classsensiolabs · httpclient · CWE-212 | Высокая8,8 | — | 3,0 % | 2 сент. 2020 г. |
36Наблюдать | CVE-2021-0340Proof of concept | In parseNextBox of IsoInterface.java, there is a possible leak of unredacted location information due to improper input validation.google · android · CWE-212 | Высокая8,8 | — | 2,1 % | 10 февр. 2021 г. |
36Наблюдать | CVE-2020-11684Эксплойта нет | AT91bootstrap before 3.9.2 does not properly wipe encryption and authentication keys from memory before passing control to a less privilegedlinux4sam · at91bootstrap · CWE-212 | Критическая9,1 | — | 1,1 % | 14 сент. 2020 г. |
35Наблюдать | CVE-2022-2818Эксплойта нет | Improper Removal of Sensitive Information Before Storage or Transfer in cockpit-hq/cockpitagentejo · cockpit · CWE-212 | Высокая8,8 | — | 1,7 % | 15 авг. 2022 г. |
35Наблюдать | CVE-2019-13402Эксплойта нет | /usr/sbin/default.sh and /usr/apache/htdocs/cgi-bin/admin/hardfactorydefault.cgi on Dynacolor FCM-MB40 v1.2.0.0 devices implement an incomplfortinet · fcm-mb40 firmware · CWE-212 | Высокая8,8 | — | 1,5 % | 7 июл. 2019 г. |
35Наблюдать | CVE-2022-30617Эксплойта нет | An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, fostrapi · strapi · CWE-212 | Высокая8,8 | — | 1,5 % | 19 мая 2022 г. |
35Наблюдать | CVE-2026-39937Эксплойта нет | Global vanishing does not completely remove user emailthe wikimedia foundation · mediawiki - centralauth extension · CWE-212 | Высокая8,8 | — | 0,4 % | 7 апр. 2026 г. |
35Наблюдать | CVE-2026-85094Эксплойта нет | The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privileged WebView.canva · canva · CWE-212 | Высокая8,8 | — | 0,4 % | 4 сент. 2026 г. |
34Наблюдать | CVE-2026-27640Эксплойта нет | tfplan2md has Sensitive Value Exposure in Generated Reportsoocx · tfplan2md · CWE-212 | Высокая8,5 | — | 0,4 % | 25 февр. 2026 г. |
32Наблюдать | CVE-2024-43384Эксплойта нет | Phoenix Contact: Improper removal of sensitive information in MGUARD productsphoenixcontact · fl mguard 2102 firmware · CWE-212 | Высокая8,0 | — | 0,3 % | 7 мая 2026 г. |
32Наблюдать | CVE-2025-65965Эксплойта нет | Grype has a credential disclosure vulnerability in Grype JSON outputanchore · grype · CWE-212 | Высокая8,2 | — | 0,1 % | 25 нояб. 2025 г. |
31Наблюдать | CVE-2020-1940Эксплойта нет | The optional initial password change and password expiration features present in Apache Jackrabbit Oak 1.2.0 to 1.22.0 are prone to a sensitapache · jackrabbit oak · CWE-212 | Высокая7,5 | — | 4,5 % | 28 янв. 2020 г. |
31Наблюдать | CVE-2002-0704Эксплойта нет | The Network Address Translation (NAT) capability for Netfilter ("iptables") 1.2.6a and earlier leaks translated IP addresses in ICMP error mlinux · linux kernel · CWE-212 | Высокая7,5 | — | 3,2 % | 26 июл. 2002 г. |
31Наблюдать | CVE-2022-0355Эксплойта нет | Improper Removal of Sensitive Information Before Storage or Transfer in feross/simple-getsimple-get project · simple-get · CWE-212 | Высокая7,5 | — | 2,0 % | 26 янв. 2022 г. |
31Наблюдать | CVE-2019-20637Эксплойта нет | An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1.varnish-cache · varnish cache · CWE-212 | Высокая7,5 | — | 1,8 % | 8 апр. 2020 г. |
31Наблюдать | CVE-2018-6337Эксплойта нет | folly::secureRandom will re-use a buffer between parent and child processes when fork() is called.facebook · folly · CWE-212 | Высокая7,5 | — | 1,8 % | 31 дек. 2018 г. |
30Наблюдать | CVE-2020-36476Эксплойта нет | An issue was discovered in Mbed TLS before 2.24.0 (and before 2.16.8 LTS and before 2.7.17 LTS).arm · mbed tls · CWE-212 | Высокая7,5 | — | 1,6 % | 22 авг. 2021 г. |
30Наблюдать | CVE-2022-24798Эксплойта нет | Insufficient password hash filtering in some IRRd queries and exportsinternet routing registry daemon project · internet routing registry daemon · CWE-212 | Высокая7,5 | — | 1,4 % | 31 мар. 2022 г. |
30Наблюдать | CVE-2024-49997Эксплойта нет | net: ethernet: lantiq_etop: fix memory disclosurelinux · linux kernel · CWE-212 | Высокая7,5 | — | 1,1 % | 21 окт. 2024 г. |
30Наблюдать | CVE-2021-31780Эксплойта нет | In app/Model/MispObject.php in MISP 2.4.141, an incorrect sharing group association could lead to information disclosure on an event edit.misp-project · misp · CWE-212 | Высокая7,5 | — | 1,0 % | 23 апр. 2021 г. |
30Наблюдать | CVE-2022-30618Эксплойта нет | An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, fostrapi · strapi · CWE-212 | Высокая7,5 | — | 0,9 % | 19 мая 2022 г. |
30Наблюдать | CVE-2021-46813Эксплойта нет | Vulnerability of residual files not being deleted after an update in the ChinaDRM module.huawei · emui · CWE-212 | Высокая7,5 | — | 0,6 % | 13 июн. 2022 г. |
30Наблюдать | CVE-2022-3460Эксплойта нет | In affected versions of Octopus Deploy it is possible for certain types of sensitive variables to inadvertently become unmasked when viewed octopus · octopus server · CWE-212 | Высокая7,5 | — | 0,6 % | 2 янв. 2023 г. |
- GHSA-x6gv-2rvh-qmp640В плане
m00nl1ght-dev/steam-workshop-deploy: Exposure of Version-Control Repository to an Unauthorized Control Sphere and Insufficiently Protected C
КритическаяCVSS 10,0Эксплойта нетGitHub Actions · m00nl1ght-dev/steam-workshop-deploy13 авг. 2025 г.
- CVE-2022-165038Наблюдать
Improper Removal of Sensitive Information Before Storage or Transfer in eventsource/eventsource
КритическаяCVSS 9,3Эксплойта нетEPSS 2 %eventsource · eventsource12 мая 2022 г.
- CVE-2020-1509436Наблюдать
In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient class from the HttpClient Symfony component relies on the HttpCache class
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %sensiolabs · httpclient2 сент. 2020 г.
- CVE-2021-034036Наблюдать
In parseNextBox of IsoInterface.java, there is a possible leak of unredacted location information due to improper input validation.
ВысокаяCVSS 8,8Proof of conceptEPSS 2 %google · android10 февр. 2021 г.
- CVE-2020-1168436Наблюдать
AT91bootstrap before 3.9.2 does not properly wipe encryption and authentication keys from memory before passing control to a less privileged
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %linux4sam · at91bootstrap14 сент. 2020 г.
- CVE-2022-281835Наблюдать
Improper Removal of Sensitive Information Before Storage or Transfer in cockpit-hq/cockpit
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %agentejo · cockpit15 авг. 2022 г.
- CVE-2019-1340235Наблюдать
/usr/sbin/default.sh and /usr/apache/htdocs/cgi-bin/admin/hardfactorydefault.cgi on Dynacolor FCM-MB40 v1.2.0.0 devices implement an incompl
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %fortinet · fcm-mb40 firmware7 июл. 2019 г.
- CVE-2022-3061735Наблюдать
An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, fo
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %strapi · strapi19 мая 2022 г.
- CVE-2026-3993735Наблюдать
Global vanishing does not completely remove user email
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %the wikimedia foundation · mediawiki - centralauth extension7 апр. 2026 г.
- CVE-2026-8509435Наблюдать
The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privileged WebView.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %canva · canva4 сент. 2026 г.
- CVE-2026-2764034Наблюдать
tfplan2md has Sensitive Value Exposure in Generated Reports
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %oocx · tfplan2md25 февр. 2026 г.
- CVE-2024-4338432Наблюдать
Phoenix Contact: Improper removal of sensitive information in MGUARD products
ВысокаяCVSS 8,0Эксплойта нетEPSS 0 %phoenixcontact · fl mguard 2102 firmware7 мая 2026 г.
- CVE-2025-6596532Наблюдать
Grype has a credential disclosure vulnerability in Grype JSON output
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %anchore · grype25 нояб. 2025 г.
- CVE-2020-194031Наблюдать
The optional initial password change and password expiration features present in Apache Jackrabbit Oak 1.2.0 to 1.22.0 are prone to a sensit
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %apache · jackrabbit oak28 янв. 2020 г.
- CVE-2002-070431Наблюдать
The Network Address Translation (NAT) capability for Netfilter ("iptables") 1.2.6a and earlier leaks translated IP addresses in ICMP error m
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %linux · linux kernel26 июл. 2002 г.
- CVE-2022-035531Наблюдать
Improper Removal of Sensitive Information Before Storage or Transfer in feross/simple-get
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %simple-get project · simple-get26 янв. 2022 г.
- CVE-2019-2063731Наблюдать
An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %varnish-cache · varnish cache8 апр. 2020 г.
- CVE-2018-633731Наблюдать
folly::secureRandom will re-use a buffer between parent and child processes when fork() is called.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %facebook · folly31 дек. 2018 г.
- CVE-2020-3647630Наблюдать
An issue was discovered in Mbed TLS before 2.24.0 (and before 2.16.8 LTS and before 2.7.17 LTS).
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %arm · mbed tls22 авг. 2021 г.
- CVE-2022-2479830Наблюдать
Insufficient password hash filtering in some IRRd queries and exports
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %internet routing registry daemon project · internet routing registry daemon31 мар. 2022 г.
- CVE-2024-4999730Наблюдать
net: ethernet: lantiq_etop: fix memory disclosure
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %linux · linux kernel21 окт. 2024 г.
- CVE-2021-3178030Наблюдать
In app/Model/MispObject.php in MISP 2.4.141, an incorrect sharing group association could lead to information disclosure on an event edit.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %misp-project · misp23 апр. 2021 г.
- CVE-2022-3061830Наблюдать
An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, fo
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %strapi · strapi19 мая 2022 г.
- CVE-2021-4681330Наблюдать
Vulnerability of residual files not being deleted after an update in the ChinaDRM module.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %huawei · emui13 июн. 2022 г.
- CVE-2022-346030Наблюдать
In affected versions of Octopus Deploy it is possible for certain types of sensitive variables to inadvertently become unmasked when viewed
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %octopus · octopus server2 янв. 2023 г.