İçeriğe atla
Noroxi

CWE-922 · 292 kayıt

Insecure Storage of Sensitive Information

Bu sınıftaki CVE’ler

292 kayıt

  • CVE-2020-13937
    44Planlayın

    Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3

    OrtaCVSS 5,3Kavram kanıtıEPSS %78

    apache · kylin19 Eki 2020

  • CVE-2021-27170
    44Planlayın

    An issue was discovered on FiberHome HG6245D devices through RP2613.

    KritikCVSS 9,8İstismar yokEPSS %16

    fiberhome · hg6245d firmware10 Şub 2021

  • CVE-2025-12539
    40Planlayın

    TNC Toolbox: Web Performance <= 1.4.2 - Unauthenticated Sensitive Information Exposure to Privilege Escalation/cPanel Account Takeover

    KritikCVSS 10,0Kavram kanıtıEPSS %1

    leopardhost · tnc toolbox: web performance11 Kas 2025

  • CVE-2021-42371
    39İzleyin

    lpar2rrd is a hardcoded system account in XoruX LPAR2RRD and STOR2RRD before 7.30.

    KritikCVSS 9,8İstismar yokEPSS %2

    xorux · lpar2rrd8 Kas 2021

  • CVE-2023-29727
    39İzleyin

    The Call Blocker application 6.6.3 for Android allows unauthorized applications to use exposed components to delete data stored in its datab

    KritikCVSS 9,8İstismar yokEPSS %1

    applika · call blocker30 May 2023

  • CVE-2017-5249
    39İzleyin

    In version 6.1.0.19 and prior of Wink Labs's Wink - Smart Home Android app, the OAuth token used by the app to authorize user access is not

    KritikCVSS 9,8İstismar yokEPSS %1

    wink · wink22 Şub 2018

  • CVE-2017-5250
    39İzleyin

    In version 1.9.7 and prior of Insteon's Insteon for Hub Android app, the OAuth token used by the app to authorize user access is not stored

    KritikCVSS 9,8İstismar yokEPSS %1

    insteon · insteon for hub22 Şub 2018

  • CVE-2022-44581
    39İzleyin

    WordPress Defender Security plugin <= 3.3.2 - Broken Authentication vulnerability

    KritikCVSS 9,8İstismar yokEPSS %1

    wpmudev · defender17 May 2024

  • CVE-2023-32191
    39İzleyin

    rke's credentials are stored in the RKE1 Cluster state ConfigMap

    KritikCVSS 9,9İstismar yokEPSS %1

    suse · rke16 Eki 2024

  • CVE-2023-0580
    39İzleyin

    Information Disclosure vulnerability in My Control System (on-premise)

    KritikCVSS 9,8İstismar yokEPSS %0

    abb · my control system6 Nis 2023

  • CVE-2025-48929
    39İzleyin

    The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token with a short expirat

    KritikCVSS 9,8İstismar yokEPSS %0

    smarsh · telemessage28 May 2025

  • CVE-2024-30896
    38İzleyin

    InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows authorized users with r

    KritikCVSS 9,1Kavram kanıtıEPSS %5

    21 Kas 2024

  • CVE-2017-7253
    36İzleyin

    Dahua IP Camera devices 3.200.0001.6 can be exploited via these steps: 1.

    YüksekCVSS 8,8İstismar yokEPSS %3

    dahuasecurity · ip camera firmware30 Mar 2017

  • CVE-2025-8699
    36İzleyin

    Some "Stored Value" Unattended Payment Solutions of KioSoft use vulnerable NFC cards.

    KritikCVSS 9,1İstismar yokEPSS %1

    kiosoft · stored value unattended payment solution12 Eyl 2025

  • CVE-2024-10943
    36İzleyin

    FactoryTalk® Updater Authentication Bypass

    KritikCVSS 9,1İstismar yokEPSS %0

    rockwell automation · factorytalk updater12 Kas 2024

  • CVE-2023-42913
    35İzleyin

    This issue was addressed through improved state management.

    YüksekCVSS 8,8İstismar yokEPSS %1

    apple · macos28 Mar 2024

  • CVE-2025-28244
    35İzleyin

    Insecure Permissions vulnerability in the Local Storage in Alteryx Server 2023.1.1.460 allows remote attackers to obtain valid user session

    YüksekCVSS 8,8İstismar yokEPSS %0

    alteryx · alteryx server10 Tem 2025

  • CVE-2025-10971
    35İzleyin

    Insecure Storage of Sensitive Information

    YüksekCVSS 8,8İstismar yokEPSS %0

    fermax electrónica s.a.u · meetme2 Ara 2025

  • CVE-2024-47043
    34İzleyin

    Ruijie Reyee OS Insecure Storage of Sensitive Information

    YüksekCVSS 8,7İstismar yokEPSS %0

    ruijienetworks · reyee os6 Ara 2024

  • CVE-2025-14376
    34İzleyin

    Verve Asset Manager – Plaintext Storage Vulnerabilities

    YüksekCVSS 8,6İstismar yokEPSS %0

    rockwell automation · verve asset manager20 Oca 2026

  • CVE-2025-21299
    32İzleyin

    Windows Kerberos Security Feature Bypass Vulnerability

    YüksekCVSS 7,8İstismar yokEPSS %2

    microsoft · windows 10 150714 Oca 2025

  • CVE-2024-22773
    32İzleyin

    Intelbras Action RF 1200 routers 1.2.2 and earlier and Action RG 1200 routers 2.1.7 and earlier expose the Password in Cookie resulting in L

    YüksekCVSS 8,1İstismar yokEPSS %1

    intelbras · action rf 1200 firmware5 Şub 2024

  • CVE-2024-52519
    32İzleyin

    Nextcloud Server's OAuth2 client secrets were stored in a recoverable way

    YüksekCVSS 8,2İstismar yokEPSS %0

    nextcloud · nextcloud server15 Kas 2024

  • CVE-2025-2241
    32İzleyin

    Hive: exposure of vcenter credentials via clusterprovision in hive / mce / acm

    YüksekCVSS 8,2İstismar yokEPSS %0

    red hat · multicluster engine for kubernetes17 Mar 2025

  • CVE-2024-48770
    32İzleyin

    An issue in Plug n Play Camera com.wisdomcity.zwave 1.1.0 allows a remote attacker to obtain sensitive information via the firmware update p

    YüksekCVSS 8,2İstismar yokEPSS %0

    11 Eki 2024

Tüm zafiyet sınıfları