Vulnerabilities > Insecure Storage of Sensitive Information

DATE CVE VULNERABILITY TITLE RISK
2023-05-12 CVE-2023-2665 Insecure Storage of Sensitive Information vulnerability in Rosariosis
Storage of Sensitive Data in a Mechanism without Access Control in GitHub repository francoisjacquet/rosariosis prior to 11.0.
network
low complexity
rosariosis CWE-922
7.5
2023-05-10 CVE-2023-31150 Insecure Storage of Sensitive Information vulnerability in Selinc products
A Storing Passwords in a Recoverable Format vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) database system could allow an authenticated attacker to retrieve passwords. See SEL Service Bulletin dated 2022-11-15 for more details.
network
low complexity
selinc CWE-922
6.5
2023-05-10 CVE-2022-43475 Insecure Storage of Sensitive Information vulnerability in Intel Data Center Manager
Insecure storage of sensitive information in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-922
7.8
2023-05-10 CVE-2022-44619 Insecure Storage of Sensitive Information vulnerability in Intel Data Center Manager
Insecure storage of sensitive information in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-922
7.8
2023-05-06 CVE-2022-43877 Insecure Storage of Sensitive Information vulnerability in IBM Urbancode Deploy
IBM UrbanCode Deploy (UCD) versions up to 7.3.0.1 could disclose sensitive password information during a manual edit of the agentrelay.properties file.
local
low complexity
ibm CWE-922
5.5
2023-04-16 CVE-2023-22687 Insecure Storage of Sensitive Information vulnerability in Freesoul Deactivate Plugins - Plugin Manager and Cleanup Project Freesoul Deactivate Plugins - Plugin Manager and Cleanup
Insecure Storage of Sensitive Information vulnerability in Jose Mortellaro Freesoul Deactivate Plugins – Plugin manager and cleanup plugin <= 1.9.4.0 versions.
7.5
2023-04-06 CVE-2023-0580 Insecure Storage of Sensitive Information vulnerability in ABB MY Control System 5.0/5.13
Insecure Storage of Sensitive Information vulnerability in ABB My Control System (on-premise) allows an attacker who successfully exploited this vulnerability to gain access to the secure application data or take control of the application. Of the services that make up the My Control System (on-premise) application, the following ones are affected by this vulnerability: User Interface System Monitoring1 Asset Inventory This issue affects My Control System (on-premise): from 5.0;0 through 5.13.
network
low complexity
abb CWE-922
critical
9.8
2023-03-27 CVE-2022-39043 Insecure Storage of Sensitive Information vulnerability in Juiker 4.6.0607.1
Juiker app stores debug logs which contains sensitive information to mobile external storage.
low complexity
juiker CWE-922
2.4
2023-02-03 CVE-2021-36546 Insecure Storage of Sensitive Information vulnerability in Kitesky Kitecms 1.1
Incorrect Access Control issue discovered in KiteCMS 1.1 allows remote attackers to view sensitive information via path in application URL.
network
low complexity
kitesky CWE-922
7.5
2023-01-14 CVE-2022-2815 Insecure Storage of Sensitive Information vulnerability in Publify Project Publify
Insecure Storage of Sensitive Information in GitHub repository publify/publify prior to 9.2.10.
network
low complexity
publify-project CWE-922
6.5