Vulnerabilities (CVE)

Filtered by CWE-922
Total 161 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-22687 1 Freesoul Deactivate Plugins - Plugin Manager And Cleanup Project 1 Freesoul Deactivate Plugins - Plugin Manager And Cleanup 2023-04-21 N/A 7.5 HIGH
Insecure Storage of Sensitive Information vulnerability in Jose Mortellaro Freesoul Deactivate Plugins – Plugin manager and cleanup plugin <= 1.9.4.0 versions.
CVE-2022-2815 1 Publify Project 1 Publify 2023-01-20 N/A 6.5 MEDIUM
Insecure Storage of Sensitive Information in GitHub repository publify/publify prior to 9.2.10.
CVE-2019-4549 1 Ibm 1 Security Directory Server 2022-12-07 5.0 MEDIUM 5.3 MEDIUM
IBM Security Directory Server 6.4.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 165951.
CVE-2022-41876 1 Ibexa 1 Ezplatform-graphql 2022-11-15 N/A 5.3 MEDIUM
ezplatform-graphql is a GraphQL server implementation for Ibexa DXP and Ibexa Open Source. Versions prior to 2.3.12 and 1.0.13 are subject to Insecure Storage of Sensitive Information. Unauthenticated GraphQL queries for user accounts can expose password hashes of users that have created or modified content, typically administrators and editors. This issue has been patched in versions 2.3.12, and 1.0.13 on the 1.X branch. Users unable to upgrade can remove the "passwordHash" entry from "src/bundle/Resources/config/graphql/User.types.yaml" in the GraphQL package, and other properties like hash type, email, login if you prefer.
CVE-2020-15775 1 Gradle 1 Enterprise 2022-09-30 5.0 MEDIUM 7.5 HIGH
An issue was discovered in Gradle Enterprise 2017.1 - 2020.2.4. The /usage page of Gradle Enterprise conveys high level build information such as project names and build counts over time. This page is incorrectly viewable anonymously.
CVE-2022-37835 1 Torguard 1 Vpn 2022-09-15 N/A 7.5 HIGH
Torguard VPN 4.8, has a vulnerability that allows an attacker to dump sensitive information, such as credentials and information about the server, without admin privileges.
CVE-2021-42371 1 Xorux 2 Lpar2rrd, Stor2rrd 2022-09-03 7.5 HIGH 9.8 CRITICAL
lpar2rrd is a hardcoded system account in XoruX LPAR2RRD and STOR2RRD before 7.30.
CVE-2022-28168 1 Broadcom 1 Sannav 2022-07-07 5.0 MEDIUM 7.5 HIGH
In Brocade SANnav before Brocade SANnav v2.2.0.2 and Brocade SANnav2.1.1.8, encoded scp-server passwords are stored using Base64 encoding, which could allow an attacker able to access log files to easily decode the passwords.
CVE-2022-30740 1 Samsung 1 Internet 2022-06-13 2.1 LOW 4.3 MEDIUM
Improper auto-fill algorithm in Samsung Internet prior to version 17.0.1.69 allows physical attackers to guess stored credit card numbers.
CVE-2022-1044 1 Trudesk Project 1 Trudesk 2022-05-20 4.3 MEDIUM 6.5 MEDIUM
Sensitive Data Exposure Due To Insecure Storage Of Profile Image in GitHub repository polonel/trudesk prior to v1.2.1.
CVE-2021-25266 1 Sophos 2 Authenticator, Intercept X 2022-05-06 2.1 LOW 3.9 LOW
An insecure data storage vulnerability allows a physical attacker with root privileges to retrieve TOTP secret keys from unlocked phones in Sophos Authenticator for Android version 3.4 and older, and Intercept X for Mobile (Android) before version 9.7.3495.
CVE-2021-27456 1 Phillips 22 Gemini 882160, Gemini 882160 Firmware, Gemini 882300 and 19 more 2022-04-12 2.1 LOW 2.4 LOW
Philips Gemini PET/CT family software stores sensitive information in a removable media device that does not have built-in access control.
CVE-2022-0881 1 Framasoft 1 Peertube 2022-03-11 4.0 MEDIUM 6.5 MEDIUM
Insecure Storage of Sensitive Information in GitHub repository chocobozzz/peertube prior to 4.1.1.
CVE-2022-25264 1 Jetbrains 1 Teamcity 2022-03-08 5.0 MEDIUM 7.5 HIGH
In JetBrains TeamCity before 2021.2.3, environment variables of the "password" type could be logged in some cases.
CVE-2022-0724 1 Microweber 1 Microweber 2022-03-02 4.0 MEDIUM 6.5 MEDIUM
Insecure Storage of Sensitive Information in GitHub repository microweber/microweber prior to 1.3.
CVE-2022-21823 1 Ivanti 1 Workspace Control 2022-01-14 2.1 LOW 5.5 MEDIUM
A insecure storage of sensitive information vulnerability exists in Ivanti Workspace Control <2021.2 (10.7.30.0) that could allow an attacker with locally authenticated low privileges to obtain key information due to an unspecified attack vector.
CVE-2017-13909 1 Apple 1 Mac Os X 2022-01-05 2.1 LOW 5.5 MEDIUM
An issue existed in the storage of sensitive tokens. This issue was addressed by placing the tokens in Keychain. This issue is fixed in macOS High Sierra 10.13. A local attacker may gain access to iCloud authentication tokens.
CVE-2021-25524 1 Samsung 1 Contacts 2021-12-13 2.1 LOW 3.3 LOW
Insecure storage of device information in Contacts prior to version 12.7.05.24 allows attacker to get Samsung Account ID.
CVE-2021-25523 1 Samsung 1 Dialer 2021-12-13 2.1 LOW 3.3 LOW
Insecure storage of device information in Samsung Dialer prior to version 12.7.05.24 allows attacker to get Samsung Account ID.
CVE-2021-25522 1 Samsung 1 Smart Capture 2021-12-13 2.1 LOW 3.3 LOW
Insecure storage of sensitive information vulnerability in Smart Capture prior to version 4.8.02.10 allows attacker to access victim's captured images without permission.