Skip to main content

CWE archive

CWE-922 CVEs

Programmatic archive

376 CVEs tagged with CWE-92216 Critical, 84 High, 223 Medium, 53 Low, 0 Unrated.

CVE-2022-32833

Published Dec 15, 2022

An issue existed with the file paths used to store website data. The issue was resolved by improving how website data is stored. This issue is fixed in iOS 16. An unauthorized use…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-34312

Published Nov 14, 2022

IBM CICS TX 11.1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 229447.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-41876

Published Nov 10, 2022

ezplatform-graphql is a GraphQL server implementation for Ibexa DXP and Ibexa Open Source. Versions prior to 2.3.12 and 1.0.13 are subject to Insecure Storage of Sensitive Informa…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32867

Published Nov 1, 2022

This issue was addressed with improved data protection. This issue is fixed in iOS 16, macOS Ventura 13. A user with physical access to an iOS device may be able to read past diag…

CVSS 2.4 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-28170

Published Oct 25, 2022

Brocade Fabric OS Web Application services before Brocade Fabric v9.1.0, v9.0.1e, v8.2.3c, v7.4.2j store server and user passwords in the debug statements. This could allow a loca…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-41320

Published Sep 23, 2022

Veritas System Recovery (VSR) versions 18 and 21 store a network destination password in the Windows registry during configuration of the backup configuration. This vulnerability…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-37835

Published Sep 12, 2022

Torguard VPN 4.8, has a vulnerability that allows an attacker to dump sensitive information, such as credentials and information about the server, without admin privileges.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-28168

Published Jun 27, 2022

In Brocade SANnav before Brocade SANnav v2.2.0.2 and Brocade SANnav2.1.1.8, encoded scp-server passwords are stored using Base64 encoding, which could allow an attacker able to ac…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-30740

Published Jun 7, 2022

Improper auto-fill algorithm in Samsung Internet prior to version 17.0.1.69 allows physical attackers to guess stored credit card numbers.

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1044

Published May 12, 2022

Sensitive Data Exposure Due To Insecure Storage Of Profile Image in GitHub repository polonel/trudesk prior to v1.2.1.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-25266

Published Apr 27, 2022

An insecure data storage vulnerability allows a physical attacker with root privileges to retrieve TOTP secret keys from unlocked phones in Sophos Authenticator for Android versio…

CVSS 3.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-1257

Published Apr 14, 2022

Insecure storage of sensitive information vulnerability in MA for Linux, macOS, and Windows prior to 5.7.6 allows a local user to gain access to sensitive information through stor…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-25031

Published Mar 11, 2022

Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could exploit this vulnerability…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-0881

Published Mar 9, 2022

Insecure Storage of Sensitive Information in GitHub repository chocobozzz/peertube prior to 4.1.1.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-25264

Published Feb 25, 2022

In JetBrains TeamCity before 2021.2.3, environment variables of the "password" type could be logged in some cases.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-0724

Published Feb 23, 2022

Insecure Storage of Sensitive Information in GitHub repository microweber/microweber prior to 1.3.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-21823

Published Jan 10, 2022

A insecure storage of sensitive information vulnerability exists in Ivanti Workspace Control <2021.2 (10.7.30.0) that could allow an attacker with locally authenticated low privil…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-13909

Published Dec 23, 2021

An issue existed in the storage of sensitive tokens. This issue was addressed by placing the tokens in Keychain. This issue is fixed in macOS High Sierra 10.13. A local attacker m…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 276-300 of 376 CVEsPage 12 of 16