The product stores sensitive information in a file system or device that does not have built-in access control.
Volume of CVEs assigned to CWE-921 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-30016CRITICAL SAP Financial Consolidation allows an unauthenticated attacker to gain unauthorized access to the Admin account. The vulnerability arises due to improper authentication mechanisms, | Apr 8, 2025 | 9.8 | 29 | NO | NO |
CVE-2023-2665HIGH Storage of Sensitive Data in a Mechanism without Access Control in GitHub repository francoisjacquet/rosariosis prior to 11.0. | May 12, 2023 | 7.5 | 25 | NO | NO |
CVE-2024-9334HIGH Use of Hard-coded Credentials, Storage of Sensitive Data in a Mechanism without Access Control vulnerability in E-Kent Pallium Vehicle Tracking allows Authentication Bypass.
This | Feb 27, 2025 | 8.2 | 22 | NO | NO |
CVE-2023-41965HIGH Sending some requests in the web application of the vulnerable device allows information to be obtained due to the lack of security in the authentication process. | Sep 18, 2023 | 7.5 | 19 | NO | NO |
CVE-2025-24870MEDIUM SAP GUI for Windows & RFC service credentials are incorrectly stored in the memory of the program allowing an unauthenticated attacker to access information within systems, resulti | Feb 11, 2025 | 6.0 | 18 | NO | NO |
CVE-2025-24843MEDIUM Insecure file retrieval process that facilitates potential for file manipulation to affect product stability and confidentiality, integrity, authenticity, and attestation of stored | Feb 28, 2025 | 5.1 | 16 | NO | NO |
CVE-2024-5206MEDIUM A sensitive data leakage vulnerability was identified in scikit-learn's TfidfVectorizer, specifically in versions up to and including 1.4.1.post1, which was fixed in version 1.5.0. | Jun 6, 2024 | 4.7 | 16 | NO | NO |
CVE-2023-41818MEDIUM
An improper use of the SD card for sensitive data vulnerability was reported in the Motorola Device Help application that could allow a local attacker to read system logs.
| May 3, 2024 | 5.0 | 16 | NO | NO |
Philips Gemini PET/CT family software stores sensitive information in a removable media device that does not have built-in access control. | Mar 23, 2022 | 2.4 | 14 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.