CWE-212— Improper Removal of Sensitive Information Before Storage or Transfer
107 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-212page 2 of 3
- CVE-2022-30617HIGHCVSS 8.8EG 8.82022-05-19
An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, for other admin panel users that have a relationship (e.g., created by, updated by) with content acce…
- CVE-2022-30618HIGHCVSS 7.5EG 7.52022-05-19
An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, for API users if content types accessible to the authenticated user contain relationships to API user…
- CVE-2022-31042HIGHCVSS 7.5EG 7.52022-06-10
Guzzle is an open source PHP HTTP client. In affected versions the `Cookie` headers on requests are sensitive information. On making a request using the `https` scheme to a server which responds with a redirect to a URI with the `http` sch…
- CVE-2022-31043HIGHCVSS 7.5EG 7.52022-06-10
Guzzle is an open source PHP HTTP client. In affected versions `Authorization` headers on requests are sensitive information. On making a request using the `https` scheme to a server which responds with a redirect to a URI with the `http` …
- CVE-2022-31090HIGHCVSS 7.7EG 7.72022-06-27
Guzzle, an extensible PHP HTTP client. `Authorization` headers on requests are sensitive information. In affected versions when using our Curl handler, it is possible to use the `CURLOPT_HTTPAUTH` option to specify an `Authorization` heade…
- CVE-2022-31112HIGHCVSS 8.2EG 8.22022-06-30
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In affected versions parse Server LiveQuery does not remove protected fields in classes, passing them to the client. The LiveQueryContr…
- CVE-2022-31162HIGHCVSS 7.5EG 7.52022-07-22
Slack Morphism is an async client library for Rust. Prior to 0.41.0, it was possible for Slack OAuth client information to leak in application debug logs. Stricter and more secure debug formatting was introduced in v0.41.0 for OAuth secret…
- CVE-2022-33740HIGHCVSS 7.1EG 7.12022-07-05
Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions befo…
- CVE-2022-3460HIGHCVSS 7.5EG 7.52023-01-03
In affected versions of Octopus Deploy it is possible for certain types of sensitive variables to inadvertently become unmasked when viewed in variable preview.
- CVE-2022-39393HIGHCVSS 8.6EG 8.62022-11-10
Wasmtime is a standalone runtime for WebAssembly. Prior to versions 2.0.2 and 1.0.2, there is a bug in Wasmtime's implementation of its pooling instance allocator where when a linear memory is reused for another instance the initial heap s…
- CVE-2022-4734HIGHCVSS 8.1EG 8.12022-12-27
Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository usememos/memos prior to 0.9.1.
- CVE-2023-1637MEDIUMCVSS 5.5EG 5.52023-03-27
A flaw that boot CPU could be vulnerable for the speculative execution behavior kind of attacks in the Linux kernel X86 CPU Power management options functionality was found in the way user resuming CPU from suspend-to-RAM. A local user cou…
- CVE-2023-28834LOWCVSS 3.5EG 3.52023-04-03
Nextcloud Server is an open source personal cloud server. Nextcloud Server 24.0.0 until 24.0.6 and 25.0.0 until 25.0.4, as well as Nextcloud Enterprise Server 23.0.0 until 23.0.11, 24.0.0 until 24.0.6, and 25.0.0 until 25.0.4, have an info…
- CVE-2023-3006MEDIUMCVSS 5.5EG 5.52023-05-31
A known cache speculation vulnerability, known as Branch History Injection (BHI) or Spectre-BHB, becomes actual again for the new hw AmpereOne. Spectre-BHB is similar to Spectre v2, except that malicious code uses the shared branch history…
- CVE-2023-41967LOWCVSS 2.4EG 2.42023-12-18
Sensitive information uncleared after debug/power state transition in the Controller 6000 could be abused by an attacker with knowledge of the Controller's default diagnostic password and physical access to the Controller to view its conf…
- CVE-2023-48308LOWCVSS 3.5EG 3.52023-12-22
Nextcloud/Cloud is a calendar app for Nextcloud. An attacker can gain access to stacktrace and internal paths of the server when generating an exception while editing a calendar appointment. It is recommended that the Nextcloud Calendar ap…
- CVE-2023-52376HIGHCVSS 7.5EG 7.52024-02-18
Information management vulnerability in the Gallery module.Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2024-29120MEDIUMCVSS 5.9EG 5.92024-07-17
In Streampark (version < 2.1.4), when a user logged in successfully, the Backend service would return "Authorization" as the front-end authentication credential. User can use this credential to request other users' information, including …
- CVE-2024-31493MEDIUMCVSS 6.5EG 6.52024-06-03
An improper removal of sensitive information before storage or transfer vulnerability [CWE-212] in FortiSOAR version 7.3.0, version 7.2.2 and below, version 7.0.3 and below may allow an authenticated low privileged user to read Connector p…
- CVE-2024-32028MEDIUMCVSS 4.1EG 4.12024-04-12
OpenTelemetry dotnet is a dotnet telemetry framework. In affected versions of `OpenTelemetry.Instrumentation.Http` and `OpenTelemetry.Instrumentation.AspNetCore` the `url.full` writes attribute/tag on spans (`Activity`) when tracing is ena…
- CVE-2024-32036MEDIUMCVSS 5.3EG 5.32024-04-15
ImageSharp is a 2D graphics API. A data leakage flaw was found in ImageSharp's JPEG and TGA decoders. This vulnerability is triggered when an attacker passes a specially crafted JPEG or TGA image file to a software using ImageSharp, potent…
- CVE-2024-41156LOWCVSS 2.7EG 2.72024-10-29
Profile files from TRO600 series radios are extracted in plain-text and encrypted file formats. Profile files provide potential attackers valuable configuration information about the Tropos network. Profiles can only be exported by authent…
- CVE-2024-43384HIGHCVSS 8.0EG 8.02026-05-07
A low privileged remote attacker can gain the root password due to improper removal of sensitive information before storage or transfer.
- CVE-2024-43554MEDIUMCVSS 5.5EG 5.52024-10-08
Windows Kernel-Mode Driver Information Disclosure Vulnerability
- CVE-2024-49997HIGHCVSS 7.5EG 7.52024-10-21
In the Linux kernel, the following vulnerability has been resolved: net: ethernet: lantiq_etop: fix memory disclosure When applying padding, the buffer is not zeroed, which results in memory disclosure. The mentioned data is observed on …
- CVE-2024-56353MEDIUMCVSS 5.5EG 5.52024-12-20
In JetBrains TeamCity before 2024.12 backup file exposed user credentials and session cookies
- CVE-2024-6055MEDIUMCVSS 4.7EG 4.72024-06-17
Improper removal of sensitive information in data source export feature in Devolutions Remote Desktop Manager 2024.1.32.0 and earlier on Windows allows an attacker that obtains the exported settings to recover powershell credentials config…
- CVE-2024-7698MEDIUMCVSS 5.7EG 5.72024-09-10
A low privileged remote attacker can get access to CSRF tokens of higher privileged users which can be abused to mount CSRF attacks.
- CVE-2024-8474HIGHCVSS 7.5EG 7.52025-01-06
OpenVPN Connect before version 3.5.0 can contain the configuration profile's clear-text private key which is logged in the application log, which an unauthorized actor can use to decrypt the VPN traffic
- CVE-2025-0011LOWCVSS 3.3EG 3.32025-09-06
Improper removal of sensitive information before storage or transfer in AMD Crash Defender could allow an attacker to obtain kernel address information potentially resulting in loss of confidentiality.
- CVE-2025-14267MEDIUMCVSS 4.9EG 4.92025-12-19
Incomplete removal of sensitive information before transfer vulnerability in M-Files Corporation M-Files Server allows data leak exposure affecting versions before 25.12.15491.7
- CVE-2025-1759MEDIUMCVSS 5.9EG 5.92025-08-18
IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.
- CVE-2025-20118MEDIUMCVSS 4.4EG 4.42025-02-26
A vulnerability in the implementation of the internal system processes of Cisco APIC could allow an authenticated, local attacker to access sensitive information on an affected device. To exploit this vulnerability, the attacker must have …
- CVE-2025-24884MEDIUMCVSS 5.1EG 0.02025-01-29
kube-audit-rest is a simple logger of mutation/creation requests to the k8s api. If the "full-elastic-stack" example vector configuration was used for a real cluster, the previous values of kubernetes secrets would have been disclosed in t…
- CVE-2025-27221LOWCVSS 3.2EG 3.22025-03-04
In the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.join, URI#merge, URI#+) have an inadvertent leakage of authentication credentials because userinfo is retained even after changing the host.
- CVE-2025-33013MEDIUMCVSS 6.2EG 6.22025-07-24
IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, 3.6.0, and MQ Operator SC2 3.2.0 through 3.2.13 Container could disclose sensitive information to a local user d…
- CVE-2025-48066MEDIUMCVSS 6.0EG 6.02025-05-22
wire-webapp is the web application for the open-source messaging service Wire. A bug fix caused a regression causing an issue with function to delete local data. Instructing the client to delete its local database on user logout does not r…
- CVE-2025-48708MEDIUMCVSS 4.0EG 2.92025-05-23
gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before 10.05.1 lacks argument sanitization for the # case. A created PDF document includes its password in cleartext.
- CVE-2025-53886MEDIUMCVSS 4.5EG 4.52025-07-15
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, when using Directus Flows with the WebHook trigger all incoming request details are logged including se…
- CVE-2025-57757MEDIUMCVSS 5.3EG 5.32025-08-28
Contao is an Open Source CMS. In versions starting from 5.0.0 and prior to 5.3.38 and 5.6.1, if a news feed contains protected news archives, their news items are not filtered and become publicly available in the RSS feed. This issue has b…
- CVE-2025-58049MEDIUMCVSS 5.8EG 5.82025-08-28
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions from 14.4.2 to before 16.4.8, 16.5.0-rc-1 to before 16.10.7, and 17.0.0-rc-1 to before 17.4.0-rc-1, the PDF export jobs st…
- CVE-2025-59955MEDIUMCVSS 5.7EG 5.72026-01-05
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions prior to and including v4.0.0-beta.420.8 have an information disclosure vulnerability in the `/api/v1/teams/{team_id}/memb…
- CVE-2025-61594HIGHCVSS 7.5EG 7.52025-12-30
URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) 0.13.2 and earlier (bundled in Ruby 3.3 series), 1.0.3 and earlier (bundled in Ruby 3.4 series), when usi…
- CVE-2025-61643MEDIUMCVSS 6.1EG 6.12026-02-03
Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/recentchanges/RecentChangeRCFeedNotifier.Php. This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1.
- CVE-2025-62483MEDIUMCVSS 5.3EG 5.32025-11-13
Improper removal of sensitive information in certain Zoom Clients before version 6.5.10 may allow an unauthenticated user to conduct a disclosure of information via network access.
- CVE-2025-64326LOWCVSS 2.6EG 2.62025-11-06
Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, …
- CVE-2025-65000MEDIUMCVSS 5.3EG 5.32025-12-18
SSH private keys of the "Remote alert handlers (Linux)" rule were exposed in the rule page's HTML source in Checkmk <= 2.4.0p18 and all versions of Checkmk 2.3.0. This potentially allowed unauthorized triggering of predefined alert handler…
- CVE-2025-65965HIGHCVSS 8.2EG 0.02025-11-25
Grype is a vulnerability scanner for container images and filesystems. A credential disclosure vulnerability was found in Grype, affecting versions 0.68.0 through 0.104.0. If registry credentials are defined and the output of grype is writ…
- CVE-2025-68131HIGHCVSS 7.5EG 7.52025-12-31
cbor2 provides encoding and decoding for the Concise Binary Object Representation (CBOR) serialization format. Starting in version 3.0.0 and prior to version 5.8.0, whhen a CBORDecoder instance is reused across multiple decode operations, …
- CVE-2026-20928MEDIUMCVSS 4.6EG 4.62026-04-14
Improper removal of sensitive information before storage or transfer in Windows Recovery Environment Agent allows an unauthorized attacker to bypass a security feature with a physical attack.
Map vulnerabilities like CWE-212 to your infrastructure
EchelonGraph correlates every CVE — across CWE-212 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →