The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.
Volume of CVEs assigned to CWE-212 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
119 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-42880CRITICAL Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a missing authorization and data- | May 7, 2026 | 9.6 | 42 | NO | NO |
CVE-2026-43824CRITICAL In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data. | May 2, 2026 | 9.6 | 42 | NO | NO |
CVE-2026-54421MEDIUM In OpenStack Ironic before 37.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such | Jun 14, 2026 | 6.8 | 31 | NO | NO |
CVE-2026-39937HIGH Improper removal of sensitive information before storage or transfer vulnerability in The Wikimedia Foundation Mediawiki - CentralAuth Extension allows Resource Leak Exposure. The | Apr 7, 2026 | 8.8 | 31 | NO | NO |
CVE-2022-1650CRITICAL Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository eventsource/eventsource prior to v2.0.2. | May 12, 2022 | 9.3 | 31 | NO | NO |
CVE-2024-43384HIGH A low privileged remote attacker can gain the root password due to improper removal of sensitive information before storage or transfer. | May 7, 2026 | 8.0 | 30 | NO | NO |
CVE-2026-32891CRITICAL Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media server. Versions 1.4.1 and below contain a stored XSS vulner | Mar 20, 2026 | 9.0 | 30 | NO | NO |
CVE-2026-15811MEDIUM A vulnerability was found in kronosnet's (version <=1.34) cryptographic configuration management. The framework does not correctly zero-out or wipe sensitive memory segments after | Jul 21, 2026 | 5.8 | 29 | NO | NO |
CVE-2026-46657HIGH Bludit is a content management system. Versions prior to 3.22.0 have a vulnerability in the user management logic that allows deactivated accounts to maintain access via persistent | Jun 8, 2026 | 7.1 | 29 | NO | NO |
CVE-2026-40895HIGH follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. Prior to 1.16.0, when an HTTP request follows a | Apr 21, 2026 | 7.5 | 29 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.