CWE-922: Insecure Storage of Sensitive Information
The product stores sensitive information without properly limiting read or write access by unauthorized actors.
116 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-10943 — FactoryTalk® Updater Authentication Bypass
- CVE-2025-10971 — Insecure Storage of Sensitive Information
- CVE-2024-47043 — Ruijie Reyee OS Insecure Storage of Sensitive Information
- CVE-2025-14376 — Verve Asset Manager – Plaintext Storage Vulnerabilities
- CVE-2026-33407 — Wallos: SSRF via HTTP Proxy Environment Variable
- CVE-2024-37144 — Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8.
- CVE-2024-29968 — SQL Table names, column names, and SQL queries are collected in DR standby Supportsave
- CVE-2026-46511 — HAXcms: Mass Token Exfiltration and Cross-Tenant Hijack
- CVE-2025-53507 — Multiple products provided by iND Co.,Ltd contain an insecure storage of sensitive information vulnerability. If exploit
- CVE-2025-2241 — Hive: exposure of vcenter credentials via clusterprovision in hive / mce / acm
- CVE-2025-2489 — Insecure storage of sensitive information in NTFS Tool
- CVE-2024-29965 — Insecure backup
- CVE-2026-40868 — kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token
- CVE-2026-44629 — Improper access control to the Synergis Softwire installation folder. This vulnerability affects Streamvault all-in-one
- CVE-2024-39775 — Net Manager has an out-of-bounds read permission bypass vulnerability
- CVE-2024-13954 — Serialization / Deserialization of configuration data
- CVE-2024-5598 — Advanced File Manager <= 5.2.4 - Sensitive Information Exposure via Directory Listing
- CVE-2025-22492 — Insecure storage of connection strings in FRS
- CVE-2025-37110 — Sensitive Credential Information stored insecurely in System Database
- CVE-2026-5666 — code-projects Online FIR System SQL Database Backup File complaints.sql sensitive information
Recently published
- CVE-2026-44629 — Improper access control to the Synergis Softwire installation folder. This vulnerability affects Streamvault all-in-one
- CVE-2026-20705 — Insecure storage of sensitive information in the Intel(R) TDX module for some Intel(R) platform within Ring 0: Trust Dom
- CVE-2026-47362 — The Datadog Android application stores operationally sensitive content in plaintext SQLite databases via Room. Two datab
- CVE-2026-46511 — HAXcms: Mass Token Exfiltration and Cross-Tenant Hijack
- CVE-2025-32751 — Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information vulnerability. A low
- CVE-2025-32746 — Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information vulnerability. An un
- CVE-2026-7257 — ** UNSUPPORTED WHEN ASSIGNED ** An insecure storage of sensitive information vulnerability in the configuration file of
- CVE-2026-40868 — kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token
- CVE-2026-5666 — code-projects Online FIR System SQL Database Backup File complaints.sql sensitive information
- CVE-2026-5650 — code-projects Online Application System for Admission oas.sql sensitive information
- CVE-2026-33407 — Wallos: SSRF via HTTP Proxy Environment Variable
- CVE-2025-10734 — ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.12 - Unauthenticated Sensitive Information Exposure
- CVE-2025-10464 — Cleartext password storage in Birtech Information Technologies' Sensaway
- CVE-2025-14376 — Verve Asset Manager – Plaintext Storage Vulnerabilities
- CVE-2025-10971 — Insecure Storage of Sensitive Information
- CVE-2025-11645 — Tomofun Furbo Mobile App Authentication Token sensitive information
- CVE-2025-11644 — Tomofun Furbo 360/Furbo Mini UART sensitive information
- CVE-2025-11639 — Tomofun Furbo 360/Furbo Mini Debug Log S3 Bucket collect_logs.sh sensitive information
- CVE-2025-35054 — Newforma Info Exchange (NIX) insufficiently protected credentials
- CVE-2025-34189 — Vasion Print (formerly PrinterLogic) Insecure Inter-Process Communication Allows Local Session Hijacking
More specific weaknesses
- CWE-921 — Storage of Sensitive Data in a Mechanism without Access Control