Vulnerabilities > Insecure Storage of Sensitive Information

DATE CVE VULNERABILITY TITLE RISK
2022-05-12 CVE-2022-1044 Insecure Storage of Sensitive Information vulnerability in Trudesk Project Trudesk
Sensitive Data Exposure Due To Insecure Storage Of Profile Image in GitHub repository polonel/trudesk prior to v1.2.1.
4.3
2022-04-27 CVE-2021-25266 Insecure Storage of Sensitive Information vulnerability in Sophos Authenticator and Intercept X
An insecure data storage vulnerability allows a physical attacker with root privileges to retrieve TOTP secret keys from unlocked phones in Sophos Authenticator for Android version 3.4 and older, and Intercept X for Mobile (Android) before version 9.7.3495.
local
low complexity
sophos CWE-922
2.1
2022-04-14 CVE-2022-1257 Insecure Storage of Sensitive Information vulnerability in Mcafee Agent
Insecure storage of sensitive information vulnerability in MA for Linux, macOS, and Windows prior to 5.7.6 allows a local user to gain access to sensitive information through storage in ma.db.
local
low complexity
mcafee CWE-922
5.5
2022-03-23 CVE-2021-27456 Insecure Storage of Sensitive Information vulnerability in Phillips products
Philips Gemini PET/CT family software stores sensitive information in a removable media device that does not have built-in access control.
local
low complexity
phillips CWE-922
2.1
2022-03-09 CVE-2022-0881 Insecure Storage of Sensitive Information vulnerability in Framasoft Peertube
Insecure Storage of Sensitive Information in GitHub repository chocobozzz/peertube prior to 4.1.1.
network
low complexity
framasoft CWE-922
4.0
2022-02-25 CVE-2022-25264 Insecure Storage of Sensitive Information vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2021.2.3, environment variables of the "password" type could be logged in some cases.
network
low complexity
jetbrains CWE-922
5.0
2022-02-23 CVE-2022-0724 Insecure Storage of Sensitive Information vulnerability in Microweber
Insecure Storage of Sensitive Information in GitHub repository microweber/microweber prior to 1.3.
network
low complexity
microweber CWE-922
4.0
2022-01-10 CVE-2022-21823 Insecure Storage of Sensitive Information vulnerability in Ivanti Workspace Control
A insecure storage of sensitive information vulnerability exists in Ivanti Workspace Control <2021.2 (10.7.30.0) that could allow an attacker with locally authenticated low privileges to obtain key information due to an unspecified attack vector.
local
low complexity
ivanti CWE-922
2.1
2021-12-23 CVE-2017-13909 Insecure Storage of Sensitive Information vulnerability in Apple mac OS X
An issue existed in the storage of sensitive tokens.
local
low complexity
apple CWE-922
2.1
2021-12-08 CVE-2021-25522 Insecure Storage of Sensitive Information vulnerability in Samsung Smart Capture
Insecure storage of sensitive information vulnerability in Smart Capture prior to version 4.8.02.10 allows attacker to access victim's captured images without permission.
local
low complexity
samsung CWE-922
2.1