CWE-922 · 292 kayıt
Insecure Storage of Sensitive Information
Bu sınıftaki CVE’ler
292 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
44Planlayın | CVE-2020-13937Kavram kanıtı | Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3apache · kylin · CWE-922 | Orta5,3 | — | %78,3 | 19 Eki 2020 |
44Planlayın | CVE-2021-27170İstismar yok | An issue was discovered on FiberHome HG6245D devices through RP2613.fiberhome · hg6245d firmware · CWE-922 | Kritik9,8 | — | %15,9 | 10 Şub 2021 |
40Planlayın | CVE-2025-12539Kavram kanıtı | TNC Toolbox: Web Performance <= 1.4.2 - Unauthenticated Sensitive Information Exposure to Privilege Escalation/cPanel Account Takeoverleopardhost · tnc toolbox: web performance · CWE-922 | Kritik10,0 | — | %1,1 | 11 Kas 2025 |
39İzleyin | CVE-2021-42371İstismar yok | lpar2rrd is a hardcoded system account in XoruX LPAR2RRD and STOR2RRD before 7.30.xorux · lpar2rrd · CWE-922 | Kritik9,8 | — | %1,6 | 8 Kas 2021 |
39İzleyin | CVE-2023-29727İstismar yok | The Call Blocker application 6.6.3 for Android allows unauthorized applications to use exposed components to delete data stored in its databapplika · call blocker · CWE-922 | Kritik9,8 | — | %1,2 | 30 May 2023 |
39İzleyin | CVE-2017-5249İstismar yok | In version 6.1.0.19 and prior of Wink Labs's Wink - Smart Home Android app, the OAuth token used by the app to authorize user access is not wink · wink · CWE-922 | Kritik9,8 | — | %0,7 | 22 Şub 2018 |
39İzleyin | CVE-2017-5250İstismar yok | In version 1.9.7 and prior of Insteon's Insteon for Hub Android app, the OAuth token used by the app to authorize user access is not stored insteon · insteon for hub · CWE-922 | Kritik9,8 | — | %0,7 | 22 Şub 2018 |
39İzleyin | CVE-2022-44581İstismar yok | WordPress Defender Security plugin <= 3.3.2 - Broken Authentication vulnerabilitywpmudev · defender · CWE-922 | Kritik9,8 | — | %0,7 | 17 May 2024 |
39İzleyin | CVE-2023-32191İstismar yok | rke's credentials are stored in the RKE1 Cluster state ConfigMapsuse · rke · CWE-922 | Kritik9,9 | — | %0,7 | 16 Eki 2024 |
39İzleyin | CVE-2023-0580İstismar yok | Information Disclosure vulnerability in My Control System (on-premise)abb · my control system · CWE-922 | Kritik9,8 | — | %0,5 | 6 Nis 2023 |
39İzleyin | CVE-2025-48929İstismar yok | The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token with a short expiratsmarsh · telemessage · CWE-922 | Kritik9,8 | — | %0,3 | 28 May 2025 |
38İzleyin | CVE-2024-30896Kavram kanıtı | InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows authorized users with rCWE-922 | Kritik9,1 | — | %5,4 | 21 Kas 2024 |
36İzleyin | CVE-2017-7253İstismar yok | Dahua IP Camera devices 3.200.0001.6 can be exploited via these steps: 1.dahuasecurity · ip camera firmware · CWE-922 | Yüksek8,8 | — | %2,6 | 30 Mar 2017 |
36İzleyin | CVE-2025-8699İstismar yok | Some "Stored Value" Unattended Payment Solutions of KioSoft use vulnerable NFC cards.kiosoft · stored value unattended payment solution · CWE-922 | Kritik9,1 | — | %0,7 | 12 Eyl 2025 |
36İzleyin | CVE-2024-10943İstismar yok | FactoryTalk® Updater Authentication Bypassrockwell automation · factorytalk updater · CWE-922 | Kritik9,1 | — | %0,5 | 12 Kas 2024 |
35İzleyin | CVE-2023-42913İstismar yok | This issue was addressed through improved state management.apple · macos · CWE-922 | Yüksek8,8 | — | %0,5 | 28 Mar 2024 |
35İzleyin | CVE-2025-28244İstismar yok | Insecure Permissions vulnerability in the Local Storage in Alteryx Server 2023.1.1.460 allows remote attackers to obtain valid user session alteryx · alteryx server · CWE-922 | Yüksek8,8 | — | %0,5 | 10 Tem 2025 |
35İzleyin | CVE-2025-10971İstismar yok | Insecure Storage of Sensitive Informationfermax electrónica s.a.u · meetme · CWE-922 | Yüksek8,8 | — | %0,1 | 2 Ara 2025 |
34İzleyin | CVE-2024-47043İstismar yok | Ruijie Reyee OS Insecure Storage of Sensitive Informationruijienetworks · reyee os · CWE-922 | Yüksek8,7 | — | %0,4 | 6 Ara 2024 |
34İzleyin | CVE-2025-14376İstismar yok | Verve Asset Manager – Plaintext Storage Vulnerabilitiesrockwell automation · verve asset manager · CWE-922 | Yüksek8,6 | — | %0,1 | 20 Oca 2026 |
32İzleyin | CVE-2025-21299İstismar yok | Windows Kerberos Security Feature Bypass Vulnerabilitymicrosoft · windows 10 1507 · CWE-922 | Yüksek7,8 | — | %2,2 | 14 Oca 2025 |
32İzleyin | CVE-2024-22773İstismar yok | Intelbras Action RF 1200 routers 1.2.2 and earlier and Action RG 1200 routers 2.1.7 and earlier expose the Password in Cookie resulting in Lintelbras · action rf 1200 firmware · CWE-922 | Yüksek8,1 | — | %1,0 | 5 Şub 2024 |
32İzleyin | CVE-2024-52519İstismar yok | Nextcloud Server's OAuth2 client secrets were stored in a recoverable waynextcloud · nextcloud server · CWE-922 | Yüksek8,2 | — | %0,5 | 15 Kas 2024 |
32İzleyin | CVE-2025-2241İstismar yok | Hive: exposure of vcenter credentials via clusterprovision in hive / mce / acmred hat · multicluster engine for kubernetes · CWE-922 | Yüksek8,2 | — | %0,5 | 17 Mar 2025 |
32İzleyin | CVE-2024-48770İstismar yok | An issue in Plug n Play Camera com.wisdomcity.zwave 1.1.0 allows a remote attacker to obtain sensitive information via the firmware update pCWE-922 | Yüksek8,2 | — | %0,4 | 11 Eki 2024 |
- CVE-2020-1393744Planlayın
Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3
OrtaCVSS 5,3Kavram kanıtıEPSS %78apache · kylin19 Eki 2020
- CVE-2021-2717044Planlayın
An issue was discovered on FiberHome HG6245D devices through RP2613.
KritikCVSS 9,8İstismar yokEPSS %16fiberhome · hg6245d firmware10 Şub 2021
- CVE-2025-1253940Planlayın
TNC Toolbox: Web Performance <= 1.4.2 - Unauthenticated Sensitive Information Exposure to Privilege Escalation/cPanel Account Takeover
KritikCVSS 10,0Kavram kanıtıEPSS %1leopardhost · tnc toolbox: web performance11 Kas 2025
- CVE-2021-4237139İzleyin
lpar2rrd is a hardcoded system account in XoruX LPAR2RRD and STOR2RRD before 7.30.
KritikCVSS 9,8İstismar yokEPSS %2xorux · lpar2rrd8 Kas 2021
- CVE-2023-2972739İzleyin
The Call Blocker application 6.6.3 for Android allows unauthorized applications to use exposed components to delete data stored in its datab
KritikCVSS 9,8İstismar yokEPSS %1applika · call blocker30 May 2023
- CVE-2017-524939İzleyin
In version 6.1.0.19 and prior of Wink Labs's Wink - Smart Home Android app, the OAuth token used by the app to authorize user access is not
KritikCVSS 9,8İstismar yokEPSS %1wink · wink22 Şub 2018
- CVE-2017-525039İzleyin
In version 1.9.7 and prior of Insteon's Insteon for Hub Android app, the OAuth token used by the app to authorize user access is not stored
KritikCVSS 9,8İstismar yokEPSS %1insteon · insteon for hub22 Şub 2018
- CVE-2022-4458139İzleyin
WordPress Defender Security plugin <= 3.3.2 - Broken Authentication vulnerability
KritikCVSS 9,8İstismar yokEPSS %1wpmudev · defender17 May 2024
- CVE-2023-3219139İzleyin
rke's credentials are stored in the RKE1 Cluster state ConfigMap
KritikCVSS 9,9İstismar yokEPSS %1suse · rke16 Eki 2024
- CVE-2023-058039İzleyin
Information Disclosure vulnerability in My Control System (on-premise)
KritikCVSS 9,8İstismar yokEPSS %0abb · my control system6 Nis 2023
- CVE-2025-4892939İzleyin
The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token with a short expirat
KritikCVSS 9,8İstismar yokEPSS %0smarsh · telemessage28 May 2025
- CVE-2024-3089638İzleyin
InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows authorized users with r
KritikCVSS 9,1Kavram kanıtıEPSS %521 Kas 2024
- CVE-2017-725336İzleyin
Dahua IP Camera devices 3.200.0001.6 can be exploited via these steps: 1.
YüksekCVSS 8,8İstismar yokEPSS %3dahuasecurity · ip camera firmware30 Mar 2017
- CVE-2025-869936İzleyin
Some "Stored Value" Unattended Payment Solutions of KioSoft use vulnerable NFC cards.
KritikCVSS 9,1İstismar yokEPSS %1kiosoft · stored value unattended payment solution12 Eyl 2025
- CVE-2024-1094336İzleyin
FactoryTalk® Updater Authentication Bypass
KritikCVSS 9,1İstismar yokEPSS %0rockwell automation · factorytalk updater12 Kas 2024
- CVE-2023-4291335İzleyin
This issue was addressed through improved state management.
YüksekCVSS 8,8İstismar yokEPSS %1apple · macos28 Mar 2024
- CVE-2025-2824435İzleyin
Insecure Permissions vulnerability in the Local Storage in Alteryx Server 2023.1.1.460 allows remote attackers to obtain valid user session
YüksekCVSS 8,8İstismar yokEPSS %0alteryx · alteryx server10 Tem 2025
- CVE-2025-1097135İzleyin
Insecure Storage of Sensitive Information
YüksekCVSS 8,8İstismar yokEPSS %0fermax electrónica s.a.u · meetme2 Ara 2025
- CVE-2024-4704334İzleyin
Ruijie Reyee OS Insecure Storage of Sensitive Information
YüksekCVSS 8,7İstismar yokEPSS %0ruijienetworks · reyee os6 Ara 2024
- CVE-2025-1437634İzleyin
Verve Asset Manager – Plaintext Storage Vulnerabilities
YüksekCVSS 8,6İstismar yokEPSS %0rockwell automation · verve asset manager20 Oca 2026
- CVE-2025-2129932İzleyin
Windows Kerberos Security Feature Bypass Vulnerability
YüksekCVSS 7,8İstismar yokEPSS %2microsoft · windows 10 150714 Oca 2025
- CVE-2024-2277332İzleyin
Intelbras Action RF 1200 routers 1.2.2 and earlier and Action RG 1200 routers 2.1.7 and earlier expose the Password in Cookie resulting in L
YüksekCVSS 8,1İstismar yokEPSS %1intelbras · action rf 1200 firmware5 Şub 2024
- CVE-2024-5251932İzleyin
Nextcloud Server's OAuth2 client secrets were stored in a recoverable way
YüksekCVSS 8,2İstismar yokEPSS %0nextcloud · nextcloud server15 Kas 2024
- CVE-2025-224132İzleyin
Hive: exposure of vcenter credentials via clusterprovision in hive / mce / acm
YüksekCVSS 8,2İstismar yokEPSS %0red hat · multicluster engine for kubernetes17 Mar 2025
- CVE-2024-4877032İzleyin
An issue in Plug n Play Camera com.wisdomcity.zwave 1.1.0 allows a remote attacker to obtain sensitive information via the firmware update p
YüksekCVSS 8,2İstismar yokEPSS %011 Eki 2024