Threats Tagged 'cwe-922'
View all threats tagged with 'cwe-922'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-922'
Click on any threat for detailed analysis and mitigation recommendations
0 A vulnerability in Brocade SANnav before versions 2.4.0b and 3.0.0 causes encoded passwords and authentication tokens to be printed in log files. An authenticated attacker with access to these log files, including the SANnav supportsave, could potentially retrieve sensitive credentials. This issue affects on-premises deployments and does not have confirmed exploits in the wild. No patch or remediation information is provided in the available data. Join the discussion | GCVE Database | 10/08/2026, 05:18:55 UTC Added: 10/08/2026, 07:35:15 UTC |
0 A vulnerability in Brocade SANnav before 2.4.0b and 3.0.0 prints encoded passwords and authentication tokens in log files. The vulnerability could allow an authenticated attacker with access to the log file including the SANnav supportsave to access the passwords. Join the discussion | CVE Database V5 | 10/08/2026, 05:18:55 UTC Added: 10/08/2026, 05:48:57 UTC |
0 Secure Folder version 1.2 by FluteCode stores files intended for its password-protected vault as unencrypted files in the Android shared-storage directory. This insecure storage allows local applications or file managers with access to the shared-storage path to enumerate, copy, and open these files without needing to authenticate to Secure Folder. Join the discussion | CVE Database V5 | 09/24/2026, 23:41:34 UTC Added: 09/24/2026, 23:48:31 UTC |
0 CVE-2026-77875 is a medium severity vulnerability in QUANTUMTECH LTD's Hide Photos - Secure vault app version 4.1.0. The app uses a calculator-style vault passcode to protect access, but the sensitive data stored in the app is not bound to this authentication. A local attacker with access to shared external storage can copy the app's SQLite database and media files without needing to enter the vault passcode. Join the discussion | CVE Database V5 | 09/18/2026, 23:29:28 UTC Added: 09/19/2026, 00:02:47 UTC |
0 CVE-2026-44629 is a high-severity vulnerability in Genetec Inc.'s Synergis Softwire and Streamvault all-in-one appliances (SV-100E and SV-300E series). It involves improper access control to the installation folder, leading to insecure storage of sensitive information. This vulnerability can result in high confidentiality impact, with limited integrity and availability impacts. No patch or remediation information is currently available. Join the discussion | GCVE Database | 08/27/2026, 22:08:52 UTC Added: 08/28/2026, 15:23:17 UTC |
0 CVE-2026-44629 is a high-severity vulnerability in Genetec Inc.'s Synergis Softwire affecting Streamvault all-in-one appliances (SV-100E and SV-300E series) and Synergis Softwire installations on Windows servers. It involves improper access control to the installation folder, leading to insecure storage of sensitive information. The vulnerability has a CVSS 3.1 score of 7.9, indicating significant confidentiality impact and some integrity and availability impact. No specific affected versions or patch information is provided. Join the discussion | CVE Database V5 | 08/27/2026, 22:08:52 UTC Added: 08/28/2026, 11:04:25 UTC |
0 In versions of the Datadog Android application prior to v554-5.9.4, two Room-backed SQLite databases store sensitive content in plaintext: LocalNotificationDatabase (notification title, message, recipient, service, tags, and on-call/incident deep links) and SearchRecentDatabase (the user's full in-app search history). Impact: Any actor able to bypass the app sandbox can read these databases in plaintext. Join the discussion | CVE Database V5 | 08/07/2026, 18:02:34 UTC Added: 08/07/2026, 18:26:48 UTC |
0 HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an attack chain utilizing Stored XSS alongside dynamic token exposure in the `/system/api/connectionSettings` endpoint allows an authenticated attacker to perform a complete cross-tenant account takeover. The API dynamically leaks the active session's authentication tokens (including the `jwt`, `user_token`, `site_token`, and `appstore_token`) into a global JavaScript variable (`window.appSettings`). An attacker can exploit the XSS vulnerability to force a victim's browser to silently fetch their specific connection settings, extract the tokens, and exfiltrate them to an attacker-controlled webhook. Version 26.0.0 patches the issue. Join the discussion | CVE Database V5 | 06/05/2026, 18:32:55 UTC Added: 06/05/2026, 19:03:42 UTC |
0 Version 3.0.7 of the Securly Chrome Extension exposes multiple publicly accessible endpoints that allow unauthenticated access to sensitive data. The exposed information consists of SHA-1 hashes that are inadequately obfuscated using a simple Caesar cipher, which can be easily reversed to recover the original hash values and access the protected data. Join the discussion | CVE Database V5 | 06/03/2026, 18:09:04 UTC Added: 06/03/2026, 19:03:39 UTC |
0 Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access to sensitive information. Join the discussion | CVE Database V5 | 05/22/2026, 13:52:12 UTC Added: 05/22/2026, 14:29:48 UTC |
Showing 1 to 10 of 37 results