CWE-922
385 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-922page 8 of 8
- CVE-2025-24101MEDIUMCVSS 5.5EG 5.52025-01-27
This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.3. An app may be able to access user-sensitive data.
- CVE-2025-24108MEDIUMCVSS 5.5EG 5.52025-01-27
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.3. An app may be able to access protected user data.
- CVE-2025-24117MEDIUMCVSS 5.5EG 5.52025-01-27
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, visionOS 2.3, watchOS 11.3. An app may be able to fingerprint the user.
- CVE-2025-24134MEDIUMCVSS 5.5EG 5.52025-01-27
An information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.3. An app may be able to access user-sensitive data.
- CVE-2025-2440MEDIUMCVSS 4.2EG 4.22025-04-09
CWE-922: Insecure Storage of Sensitive Information vulnerability exists that could potentially lead to unauthorized access of confidential data when a malicious user, having physical access and advanced information on the file system, sets…
- CVE-2025-2489MEDIUMCVSS 6.8EG 0.02025-03-18
Insecure information storage vulnerability in NTFS Tools version 3.5.1. Exploitation of this vulnerability could allow an attacker to know the application password, stored in /Users/user/Library/Application Support/ntfs-tool/config.json.
- CVE-2025-25732MEDIUMCVSS 6.8EG 6.52025-08-26
Incorrect access control in the EEPROM component of Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 allows attackers to replace password hashes stored in the EEPROM with hashes …
- CVE-2025-28171MEDIUMCVSS 6.5EG 6.52025-07-29
An issue in Grandstream UCM6510 v.1.0.20.52 and before allows a remote attacker to obtain sensitive information via the Login function at /cgi and /webrtccgi.
- CVE-2025-28244HIGHCVSS 8.8EG 8.82025-07-10
Insecure Permissions vulnerability in the Local Storage in Alteryx Server 2023.1.1.460 allows remote attackers to obtain valid user session tokens from localStorage, leading to account takeover
- CVE-2025-29809HIGHCVSS 7.1EG 7.12025-04-08
Insecure storage of sensitive information in Windows Kerberos allows an authorized attacker to bypass a security feature locally.
- CVE-2025-32746MEDIUMCVSS 4.0EG 5.52026-05-22
Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to unauthorized access t…
- CVE-2025-32751MEDIUMCVSS 5.5EG 5.52026-05-26
Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive... Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information vulnerability. A low privileged attacker with l…
- CVE-2025-34189HIGHCVSS 7.8EG 7.82025-09-19
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 1.0.735 and Application versions prior to 20.0.1330 (macOS/Linux client deployments) contain a vulnerability in the local inter-process communication (IPC) mecha…
- CVE-2025-35054MEDIUMCVSS 5.3EG 5.32025-10-09
Newforma Info Exchange (NIX) stores credentials used to configure NPCS in 'HKLM\Software\WOW6432Node\Newforma\<version>\Credentials'. The credentials are encrypted but the encryption key is stored in the same registry location. Authentica…
- CVE-2025-37100HIGHCVSS 7.7EG 7.72025-06-10
A vulnerability in the APIs of HPE Aruba Networking Private 5G Core could potentially expose sensitive information to unauthorized users. A successful exploitation could allow an attacker to iteratively navigate through the filesystem an…
- CVE-2025-37110MEDIUMCVSS 6.0EG 6.02025-07-31
A vulnerability was discovered in the storage policy for certain sets of sensitive credential information in the HPE Telco Network Function Virtual Orchestrator. Successful Exploitation could lead to unauthorized parties gaining access to …
- CVE-2025-42979MEDIUMCVSS 5.6EG 5.62025-07-08
The GuiXT application, which is integrated with SAP GUI for Windows, uses obfuscation algorithms instead of secure symmetric ciphers for storing the credentials of an RFC user on the client PC. This leads to a high impact on confidentialit…
- CVE-2025-43203MEDIUMCVSS 4.0EG 4.02025-09-15
The issue was addressed with improved handling of caches. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26. An attacker with physical access to an unlocked device may be able to view an image in the most recently viewe…
- CVE-2025-45242HIGHCVSS 7.7EG 7.72025-05-05
Rhymix v2.1.22 was discovered to contain an arbitrary file deletion vulnerability via the procFileAdminEditImage method in /file/file.admin.controller.php.
- CVE-2025-46627HIGHCVSS 8.2EG 8.22025-05-01
Use of weak credentials in the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated attacker to authenticate to the telnet service by calculating the root password based on easily-obtained device information. The password is based on the la…
- CVE-2025-46660MEDIUMCVSS 5.3EG 5.32025-08-06
An issue was discovered in 4C Strategies Exonaut 21.6. Passwords, stored in the database, are hashed without a salt.
- CVE-2025-48929MEDIUMCVSS 4.0EG 4.02025-05-28
The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token with a short expiration time) that can be reused at a later date if discovered by an adversary.
- CVE-2025-53507MEDIUMCVSS 6.5EG 6.52025-08-29
Multiple products provided by iND Co.,Ltd contain an insecure storage of sensitive information vulnerability. If exploited, configuration information, such as admin password, may be disclosed. As for the details of affected product names a…
- CVE-2025-54083MEDIUMCVSS 5.1EG 0.02025-09-09
Insecure Storage of Sensitive Information vulnerability in Calix GigaCenter ONT (Quantenna SoC modules) allows admin access to the web interface.This issue affects GigaCenter ONT: 844E, 844G, 844GE, 854GE.
- CVE-2025-60856MEDIUMCVSS 6.8EG 6.82025-10-20
Reolink Video Doorbell WiFi DB_566128M5MP_W allows root shell access through an unsecured UART/serial console. An attacker with physical access can connect to the exposed interface and execute arbitrary commands with root privileges. NOTE:…
- CVE-2025-61482HIGHCVSS 7.2EG 7.22025-10-27
Improper handling of OTP/TOTP/HOTP values in NetKnights GmbH privacyIDEA Authenticator v.4.3.0 on Android allows local attackers with root access to bypass two factor authentication. By hooking into app crypto routines and intercepting dec…
- CVE-2025-70963HIGHCVSS 7.6EG 7.62026-02-06
Gophish <=0.12.1 is vulnerable to Incorrect Access Control. The administrative dashboard exposes each user’s long-lived API key directly inside the rendered HTML/JavaScript of the page on every login. This makes permanent API credentials…
- CVE-2025-8699CRITICALCVSS 9.1EG 9.12025-09-12
Some "Stored Value" Unattended Payment Solutions of KioSoft use vulnerable NFC cards. Attackers could potentially use this vulnerability to change the balance on the cards and generate money. The account balance is stored on an insecure Mi…
- CVE-2026-20629MEDIUMCVSS 5.5EG 5.52026-02-11
A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Tahoe 26.3. An app may be able to access user-sensitive data.
- CVE-2026-26152HIGHCVSS 7.0EG 7.02026-04-14
Insecure storage of sensitive information in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally.
- CVE-2026-40868HIGHCVSS 8.1EG 8.12026-04-21
Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to 1.16.4, kyverno’s apiCall servicecall helper implicitly injects Authorization: Bearer ... using the kyverno controller serviceaccount token when a …
- CVE-2026-5515MEDIUMCVSS 5.5EG 5.52026-05-27
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.0 stores potentially sensitive information in log files that could be read by a local user.
- CVE-2026-5650MEDIUMCVSS 5.3EG 5.32026-04-06
A vulnerability was found in code-projects Online Application System for Admission 1.0. Impacted is an unknown function of the file /enrollment/database/oas.sql. Performing a manipulation results in insecure storage of sensitive informatio…
- CVE-2026-5666MEDIUMCVSS 5.3EG 5.32026-04-06
A vulnerability was detected in code-projects Online FIR System 1.0. Affected by this issue is some unknown functionality of the file /complaints.sql of the component SQL Database Backup File Handler. The manipulation results in insecure s…
- CVE-2026-7257MEDIUMCVSS 4.4EG 4.42026-05-12
** UNSUPPORTED WHEN ASSIGNED ** An insecure storage of sensitive information vulnerability in the configuration file of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow a local attacker with administrator privileges to downloa…
Map vulnerabilities like CWE-922 to your infrastructure
EchelonGraph correlates every CVE — across CWE-922 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →