Vulnerabilities > Improper Cross-boundary Removal of Sensitive Data

DATE CVE VULNERABILITY TITLE RISK
2022-02-09 CVE-2022-0536 Improper Cross-boundary Removal of Sensitive Data vulnerability in Follow-Redirects Project Follow-Redirects
Improper Removal of Sensitive Information Before Storage or Transfer in NPM follow-redirects prior to 1.14.8.
network
high complexity
follow-redirects-project CWE-212
5.9
2022-02-04 CVE-2022-23605 Improper Cross-boundary Removal of Sensitive Data vulnerability in Wire Wire-Webapp
Wire webapp is a web client for the wire messaging protocol.
local
low complexity
wire CWE-212
2.1
2022-01-26 CVE-2022-0355 Improper Cross-boundary Removal of Sensitive Data vulnerability in Simple-Get Project Simple-Get
Improper Removal of Sensitive Information Before Storage or Transfer in NPM simple-get prior to 4.0.1.
network
low complexity
simple-get-project CWE-212
7.5
2021-10-05 CVE-2021-39891 Improper Cross-boundary Removal of Sensitive Data vulnerability in Gitlab
In all versions of GitLab CE/EE since version 8.0, access tokens created as part of admin's impersonation of a user are not cleared at the end of impersonation which may lead to unnecessary sensitive info disclosure.
network
low complexity
gitlab CWE-212
4.0
2021-08-23 CVE-2020-36476 Improper Cross-boundary Removal of Sensitive Data vulnerability in multiple products
An issue was discovered in Mbed TLS before 2.24.0 (and before 2.16.8 LTS and before 2.7.17 LTS).
network
low complexity
arm debian CWE-212
7.5
2021-08-13 CVE-2021-38554 Improper Cross-boundary Removal of Sensitive Data vulnerability in Hashicorp Vault
HashiCorp Vault and Vault Enterprise’s UI erroneously cached and exposed user-viewed secrets between sessions in a single shared browser.
network
hashicorp CWE-212
3.5
2021-06-11 CVE-2021-28689 Improper Cross-boundary Removal of Sensitive Data vulnerability in XEN
x86: Speculative vulnerabilities with bare (non-shim) 32-bit PV guests 32-bit x86 PV guest kernels run in ring 1.
local
low complexity
xen CWE-212
5.5
2021-06-08 CVE-2021-32658 Improper Cross-boundary Removal of Sensitive Data vulnerability in Nextcloud
Nextcloud Android is the Android client for the Nextcloud open source home cloud system.
low complexity
nextcloud CWE-212
4.6
2021-05-27 CVE-2020-14301 Improper Cross-boundary Removal of Sensitive Data vulnerability in multiple products
An information disclosure vulnerability was found in libvirt in versions before 6.3.0.
network
low complexity
redhat netapp CWE-212
4.0
2021-04-23 CVE-2021-31780 Improper Cross-boundary Removal of Sensitive Data vulnerability in Misp 2.4.141
In app/Model/MispObject.php in MISP 2.4.141, an incorrect sharing group association could lead to information disclosure on an event edit.
network
low complexity
misp CWE-212
5.0