CWE-212 · 101 kayıt
Improper Removal of Sensitive Information Before Storage or Transfer
Bu sınıftaki CVE’ler
101 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | GHSA-x6gv-2rvh-qmp6İstismar yok | m00nl1ght-dev/steam-workshop-deploy: Exposure of Version-Control Repository to an Unauthorized Control Sphere and Insufficiently Protected CGitHub Actions · m00nl1ght-dev/steam-workshop-deploy · CWE-212 | Kritik10,0 | — | — | 13 Ağu 2025 |
38İzleyin | CVE-2022-1650İstismar yok | Improper Removal of Sensitive Information Before Storage or Transfer in eventsource/eventsourceeventsource · eventsource · CWE-212 | Kritik9,3 | — | %1,9 | 12 May 2022 |
36İzleyin | CVE-2020-15094İstismar yok | In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient class from the HttpClient Symfony component relies on the HttpCache classsensiolabs · httpclient · CWE-212 | Yüksek8,8 | — | %3,0 | 2 Eyl 2020 |
36İzleyin | CVE-2021-0340Kavram kanıtı | In parseNextBox of IsoInterface.java, there is a possible leak of unredacted location information due to improper input validation.google · android · CWE-212 | Yüksek8,8 | — | %2,1 | 10 Şub 2021 |
36İzleyin | CVE-2020-11684İstismar yok | AT91bootstrap before 3.9.2 does not properly wipe encryption and authentication keys from memory before passing control to a less privilegedlinux4sam · at91bootstrap · CWE-212 | Kritik9,1 | — | %1,1 | 14 Eyl 2020 |
35İzleyin | CVE-2022-2818İstismar yok | Improper Removal of Sensitive Information Before Storage or Transfer in cockpit-hq/cockpitagentejo · cockpit · CWE-212 | Yüksek8,8 | — | %1,7 | 15 Ağu 2022 |
35İzleyin | CVE-2019-13402İstismar yok | /usr/sbin/default.sh and /usr/apache/htdocs/cgi-bin/admin/hardfactorydefault.cgi on Dynacolor FCM-MB40 v1.2.0.0 devices implement an incomplfortinet · fcm-mb40 firmware · CWE-212 | Yüksek8,8 | — | %1,5 | 7 Tem 2019 |
35İzleyin | CVE-2022-30617İstismar yok | An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, fostrapi · strapi · CWE-212 | Yüksek8,8 | — | %1,5 | 19 May 2022 |
35İzleyin | CVE-2026-39937İstismar yok | Global vanishing does not completely remove user emailthe wikimedia foundation · mediawiki - centralauth extension · CWE-212 | Yüksek8,8 | — | %0,4 | 7 Nis 2026 |
35İzleyin | CVE-2026-85094İstismar yok | The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privileged WebView.canva · canva · CWE-212 | Yüksek8,8 | — | %0,4 | 4 Eyl 2026 |
34İzleyin | CVE-2026-27640İstismar yok | tfplan2md has Sensitive Value Exposure in Generated Reportsoocx · tfplan2md · CWE-212 | Yüksek8,5 | — | %0,4 | 25 Şub 2026 |
32İzleyin | CVE-2024-43384İstismar yok | Phoenix Contact: Improper removal of sensitive information in MGUARD productsphoenixcontact · fl mguard 2102 firmware · CWE-212 | Yüksek8,0 | — | %0,3 | 7 May 2026 |
32İzleyin | CVE-2025-65965İstismar yok | Grype has a credential disclosure vulnerability in Grype JSON outputanchore · grype · CWE-212 | Yüksek8,2 | — | %0,1 | 25 Kas 2025 |
31İzleyin | CVE-2020-1940İstismar yok | The optional initial password change and password expiration features present in Apache Jackrabbit Oak 1.2.0 to 1.22.0 are prone to a sensitapache · jackrabbit oak · CWE-212 | Yüksek7,5 | — | %4,5 | 28 Oca 2020 |
31İzleyin | CVE-2002-0704İstismar yok | The Network Address Translation (NAT) capability for Netfilter ("iptables") 1.2.6a and earlier leaks translated IP addresses in ICMP error mlinux · linux kernel · CWE-212 | Yüksek7,5 | — | %3,2 | 26 Tem 2002 |
31İzleyin | CVE-2022-0355İstismar yok | Improper Removal of Sensitive Information Before Storage or Transfer in feross/simple-getsimple-get project · simple-get · CWE-212 | Yüksek7,5 | — | %2,0 | 26 Oca 2022 |
31İzleyin | CVE-2019-20637İstismar yok | An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1.varnish-cache · varnish cache · CWE-212 | Yüksek7,5 | — | %1,8 | 8 Nis 2020 |
31İzleyin | CVE-2018-6337İstismar yok | folly::secureRandom will re-use a buffer between parent and child processes when fork() is called.facebook · folly · CWE-212 | Yüksek7,5 | — | %1,8 | 31 Ara 2018 |
30İzleyin | CVE-2020-36476İstismar yok | An issue was discovered in Mbed TLS before 2.24.0 (and before 2.16.8 LTS and before 2.7.17 LTS).arm · mbed tls · CWE-212 | Yüksek7,5 | — | %1,6 | 22 Ağu 2021 |
30İzleyin | CVE-2022-24798İstismar yok | Insufficient password hash filtering in some IRRd queries and exportsinternet routing registry daemon project · internet routing registry daemon · CWE-212 | Yüksek7,5 | — | %1,4 | 31 Mar 2022 |
30İzleyin | CVE-2024-49997İstismar yok | net: ethernet: lantiq_etop: fix memory disclosurelinux · linux kernel · CWE-212 | Yüksek7,5 | — | %1,1 | 21 Eki 2024 |
30İzleyin | CVE-2021-31780İstismar yok | In app/Model/MispObject.php in MISP 2.4.141, an incorrect sharing group association could lead to information disclosure on an event edit.misp-project · misp · CWE-212 | Yüksek7,5 | — | %1,0 | 23 Nis 2021 |
30İzleyin | CVE-2022-30618İstismar yok | An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, fostrapi · strapi · CWE-212 | Yüksek7,5 | — | %0,9 | 19 May 2022 |
30İzleyin | CVE-2021-46813İstismar yok | Vulnerability of residual files not being deleted after an update in the ChinaDRM module.huawei · emui · CWE-212 | Yüksek7,5 | — | %0,6 | 13 Haz 2022 |
30İzleyin | CVE-2022-3460İstismar yok | In affected versions of Octopus Deploy it is possible for certain types of sensitive variables to inadvertently become unmasked when viewed octopus · octopus server · CWE-212 | Yüksek7,5 | — | %0,6 | 2 Oca 2023 |
- GHSA-x6gv-2rvh-qmp640Planlayın
m00nl1ght-dev/steam-workshop-deploy: Exposure of Version-Control Repository to an Unauthorized Control Sphere and Insufficiently Protected C
KritikCVSS 10,0İstismar yokGitHub Actions · m00nl1ght-dev/steam-workshop-deploy13 Ağu 2025
- CVE-2022-165038İzleyin
Improper Removal of Sensitive Information Before Storage or Transfer in eventsource/eventsource
KritikCVSS 9,3İstismar yokEPSS %2eventsource · eventsource12 May 2022
- CVE-2020-1509436İzleyin
In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient class from the HttpClient Symfony component relies on the HttpCache class
YüksekCVSS 8,8İstismar yokEPSS %3sensiolabs · httpclient2 Eyl 2020
- CVE-2021-034036İzleyin
In parseNextBox of IsoInterface.java, there is a possible leak of unredacted location information due to improper input validation.
YüksekCVSS 8,8Kavram kanıtıEPSS %2google · android10 Şub 2021
- CVE-2020-1168436İzleyin
AT91bootstrap before 3.9.2 does not properly wipe encryption and authentication keys from memory before passing control to a less privileged
KritikCVSS 9,1İstismar yokEPSS %1linux4sam · at91bootstrap14 Eyl 2020
- CVE-2022-281835İzleyin
Improper Removal of Sensitive Information Before Storage or Transfer in cockpit-hq/cockpit
YüksekCVSS 8,8İstismar yokEPSS %2agentejo · cockpit15 Ağu 2022
- CVE-2019-1340235İzleyin
/usr/sbin/default.sh and /usr/apache/htdocs/cgi-bin/admin/hardfactorydefault.cgi on Dynacolor FCM-MB40 v1.2.0.0 devices implement an incompl
YüksekCVSS 8,8İstismar yokEPSS %2fortinet · fcm-mb40 firmware7 Tem 2019
- CVE-2022-3061735İzleyin
An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, fo
YüksekCVSS 8,8İstismar yokEPSS %1strapi · strapi19 May 2022
- CVE-2026-3993735İzleyin
Global vanishing does not completely remove user email
YüksekCVSS 8,8İstismar yokEPSS %0the wikimedia foundation · mediawiki - centralauth extension7 Nis 2026
- CVE-2026-8509435İzleyin
The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privileged WebView.
YüksekCVSS 8,8İstismar yokEPSS %0canva · canva4 Eyl 2026
- CVE-2026-2764034İzleyin
tfplan2md has Sensitive Value Exposure in Generated Reports
YüksekCVSS 8,5İstismar yokEPSS %0oocx · tfplan2md25 Şub 2026
- CVE-2024-4338432İzleyin
Phoenix Contact: Improper removal of sensitive information in MGUARD products
YüksekCVSS 8,0İstismar yokEPSS %0phoenixcontact · fl mguard 2102 firmware7 May 2026
- CVE-2025-6596532İzleyin
Grype has a credential disclosure vulnerability in Grype JSON output
YüksekCVSS 8,2İstismar yokEPSS %0anchore · grype25 Kas 2025
- CVE-2020-194031İzleyin
The optional initial password change and password expiration features present in Apache Jackrabbit Oak 1.2.0 to 1.22.0 are prone to a sensit
YüksekCVSS 7,5İstismar yokEPSS %5apache · jackrabbit oak28 Oca 2020
- CVE-2002-070431İzleyin
The Network Address Translation (NAT) capability for Netfilter ("iptables") 1.2.6a and earlier leaks translated IP addresses in ICMP error m
YüksekCVSS 7,5İstismar yokEPSS %3linux · linux kernel26 Tem 2002
- CVE-2022-035531İzleyin
Improper Removal of Sensitive Information Before Storage or Transfer in feross/simple-get
YüksekCVSS 7,5İstismar yokEPSS %2simple-get project · simple-get26 Oca 2022
- CVE-2019-2063731İzleyin
An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1.
YüksekCVSS 7,5İstismar yokEPSS %2varnish-cache · varnish cache8 Nis 2020
- CVE-2018-633731İzleyin
folly::secureRandom will re-use a buffer between parent and child processes when fork() is called.
YüksekCVSS 7,5İstismar yokEPSS %2facebook · folly31 Ara 2018
- CVE-2020-3647630İzleyin
An issue was discovered in Mbed TLS before 2.24.0 (and before 2.16.8 LTS and before 2.7.17 LTS).
YüksekCVSS 7,5İstismar yokEPSS %2arm · mbed tls22 Ağu 2021
- CVE-2022-2479830İzleyin
Insufficient password hash filtering in some IRRd queries and exports
YüksekCVSS 7,5İstismar yokEPSS %1internet routing registry daemon project · internet routing registry daemon31 Mar 2022
- CVE-2024-4999730İzleyin
net: ethernet: lantiq_etop: fix memory disclosure
YüksekCVSS 7,5İstismar yokEPSS %1linux · linux kernel21 Eki 2024
- CVE-2021-3178030İzleyin
In app/Model/MispObject.php in MISP 2.4.141, an incorrect sharing group association could lead to information disclosure on an event edit.
YüksekCVSS 7,5İstismar yokEPSS %1misp-project · misp23 Nis 2021
- CVE-2022-3061830İzleyin
An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, fo
YüksekCVSS 7,5İstismar yokEPSS %1strapi · strapi19 May 2022
- CVE-2021-4681330İzleyin
Vulnerability of residual files not being deleted after an update in the ChinaDRM module.
YüksekCVSS 7,5İstismar yokEPSS %1huawei · emui13 Haz 2022
- CVE-2022-346030İzleyin
In affected versions of Octopus Deploy it is possible for certain types of sensitive variables to inadvertently become unmasked when viewed
YüksekCVSS 7,5İstismar yokEPSS %1octopus · octopus server2 Oca 2023