The product stores sensitive information without properly limiting read or write access by unauthorized actors.
Volume of CVEs assigned to CWE-922 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
373 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-13937MEDIUM Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3.0.0-alpha, 3.0.0-alpha2, 3.0.0-beta, 3. | Oct 19, 2020 | 5.3 | 72 | NO | YES |
CVE-2018-25031MEDIUM Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could exploit this vulnerability t | Mar 11, 2022 | 4.3 | 50 | NO | YES |
CVE-2024-30896CRITICAL InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows authorized users with read access to the authorization resource | Nov 21, 2024 | 9.1 | 42 | NO | YES |
CVE-2021-27170CRITICAL An issue was discovered on FiberHome HG6245D devices through RP2613. By default, there are no firewall rules for IPv6 connectivity, exposing the internal management interfaces to t | Feb 10, 2021 | 9.8 | 38 | NO | NO |
CVE-2022-35513HIGH The Blink1Control2 application <= 2.2.7 uses weak password encryption and an insecure method of storage. | Sep 7, 2022 | 7.5 | 37 | NO | YES |
CVE-2025-12539CRITICAL The TNC Toolbox: Web Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.2. This is due to the plugin storing | Nov 11, 2025 | 10.0 | 33 | NO | NO |
CVE-2024-37728HIGH Arbitrary File Read vulnerability in Xi'an Daxi Information Technology Co., Ltd OfficeWeb365 v.7.18.23.0 and v8.6.1.0 allows a remote attacker to obtain sensitive information via t | Sep 10, 2024 | 7.5 | 32 | NO | YES |
CVE-2026-46511HIGH HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an attack chain utilizing Stored XSS alongside dynamic token exposure in the `/system/ | Jun 5, 2026 | 8.7 | 31 | NO | NO |
CVE-2024-7569CRITICAL An information disclosure vulnerability in Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier allows an unauthenticated attacker to obtain the OIDC client secret | Aug 13, 2024 | 9.8 | 31 | NO | NO |
CVE-2021-42371CRITICAL lpar2rrd is a hardcoded system account in XoruX LPAR2RRD and STOR2RRD before 7.30. | Nov 8, 2021 | 9.8 | 31 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.