CWE-212: CWE-212
Yearly Trend
Top Affected Vendors
All CWE-212 CVEs (20)
CVE-2022-2818 is an improper removal of sensitive information vulnerability in the cockpit repository that could expose sensitive data like credential...
Aug 15, 2022CVE-2022-0355 is an information disclosure vulnerability in the NPM simple-get package where sensitive data like authorization headers and cookies are...
Jan 26, 2022CVE-2022-1650 is an information exposure vulnerability in the eventsource JavaScript library where sensitive information (like authentication tokens) ...
May 12, 2022tfplan2md versions before 1.26.1 fail to properly mask sensitive values in Terraform plan reports, exposing secrets like API keys, passwords, and conf...
Feb 25, 2026This vulnerability in the cbor2 library allows attackers to read sensitive data from previously decoded CBOR messages when a CBORDecoder instance is r...
Dec 31, 2025This vulnerability in Ruby's URI module allows credential exposure when using the '+' operator to combine URIs. Sensitive information like passwords f...
Dec 30, 2025OpenVPN Connect versions before 3.5.0 log the configuration profile's private key in clear text within application logs. This allows unauthorized acto...
Jan 6, 2025This CVE describes an information management vulnerability in Huawei's Gallery module that could allow unauthorized access to sensitive information. S...
Feb 18, 2024IRRd version 4.2.x improperly exposed password hashes in query responses for mntner objects and database exports, allowing attackers to retrieve hashe...
Mar 31, 2022This vulnerability in Mbed TLS allows sensitive application data to remain in memory after SSL/TLS sessions, potentially exposing it to attackers who ...
Aug 23, 2021This vulnerability in MISP allows information disclosure when editing events with sharing groups. An incorrect sharing group association causes the sy...
Apr 23, 2021This vulnerability in Streampark versions before 2.1.4 allows authenticated users to access other users' sensitive information, including administrato...
Jul 17, 2024JetBrains TeamCity backup files exposed user credentials and session cookies in versions before 2024.12. This vulnerability allows attackers with acce...
Dec 20, 2024This vulnerability exposes SSH private keys in the HTML source of Checkmk's remote alert handler rule pages. Attackers who can access these pages coul...
Dec 18, 2025This vulnerability in Zoom Clients allows unauthenticated attackers to access sensitive information through network access due to improper data remova...
Nov 13, 2025This vulnerability in M-Files Server allows sensitive information to be exposed due to incomplete data removal before transfer. It affects organizatio...
Dec 19, 2025This vulnerability in Devolutions Remote Desktop Manager allows attackers who obtain exported configuration files to recover PowerShell credentials st...
Jun 17, 2024This vulnerability in Cisco APIC allows authenticated local administrators to access sensitive information through insufficiently masked CLI command o...
Feb 26, 2025This vulnerability in Artifex Ghostscript allows PDF passwords to be exposed in cleartext when processing certain PDF documents. It affects systems us...
May 23, 2025Weblate versions 5.14 and below expose the IP address of project administrators in audit logs when inviting users to projects. This information leakag...
Nov 6, 2025About CWE-212 (CWE-212)
Our database tracks 20 CVEs classified as CWE-212, with 1 rated critical and 10 rated high severity. The average CVSS score for CWE-212 vulnerabilities is 6.5.
External reference: View CWE-212 on MITRE CWE →
Monitor CWE-212 Vulnerabilities
Get alerted when new CWE-212 CVEs affect your infrastructure.
Start Monitoring Free