CWE-212: CWE-212

20
Total CVEs
1
Critical
10
High
6.5
Avg CVSS

Yearly Trend

2026
1
2025
9
2024
4
2022
4
2021
2

Top Affected Vendors

1 Debian 2
2 Ruby Lang 1
3 Artifex 1
4 Agentejo 1
5 Apache 1
6 Simple Get Project 1
7 Weblate 1
8 Eventsource 1
9 Huawei 1
10 Internet Routing Registry Daemon Project 1

All CWE-212 CVEs (20)

CVE-2022-2818
9.8

CVE-2022-2818 is an improper removal of sensitive information vulnerability in the cockpit repository that could expose sensitive data like credential...

Aug 15, 2022
CVE-2022-0355
8.8

CVE-2022-0355 is an information disclosure vulnerability in the NPM simple-get package where sensitive data like authorization headers and cookies are...

Jan 26, 2022
CVE-2022-1650
8.1

CVE-2022-1650 is an information exposure vulnerability in the eventsource JavaScript library where sensitive information (like authentication tokens) ...

May 12, 2022
CVE-2026-27640
7.5

tfplan2md versions before 1.26.1 fail to properly mask sensitive values in Terraform plan reports, exposing secrets like API keys, passwords, and conf...

Feb 25, 2026
CVE-2025-68131
7.5

This vulnerability in the cbor2 library allows attackers to read sensitive data from previously decoded CBOR messages when a CBORDecoder instance is r...

Dec 31, 2025
CVE-2025-61594
7.5

This vulnerability in Ruby's URI module allows credential exposure when using the '+' operator to combine URIs. Sensitive information like passwords f...

Dec 30, 2025
CVE-2024-8474
7.5

OpenVPN Connect versions before 3.5.0 log the configuration profile's private key in clear text within application logs. This allows unauthorized acto...

Jan 6, 2025
CVE-2023-52376
7.5

This CVE describes an information management vulnerability in Huawei's Gallery module that could allow unauthorized access to sensitive information. S...

Feb 18, 2024
CVE-2022-24798
7.5

IRRd version 4.2.x improperly exposed password hashes in query responses for mntner objects and database exports, allowing attackers to retrieve hashe...

Mar 31, 2022
CVE-2020-36476
7.5

This vulnerability in Mbed TLS allows sensitive application data to remain in memory after SSL/TLS sessions, potentially exposing it to attackers who ...

Aug 23, 2021
CVE-2021-31780
7.5

This vulnerability in MISP allows information disclosure when editing events with sharing groups. An incorrect sharing group association causes the sy...

Apr 23, 2021
CVE-2024-29120
5.9

This vulnerability in Streampark versions before 2.1.4 allows authenticated users to access other users' sensitive information, including administrato...

Jul 17, 2024
CVE-2024-56353
5.5

JetBrains TeamCity backup files exposed user credentials and session cookies in versions before 2024.12. This vulnerability allows attackers with acce...

Dec 20, 2024
CVE-2025-65000
5.3

This vulnerability exposes SSH private keys in the HTML source of Checkmk's remote alert handler rule pages. Attackers who can access these pages coul...

Dec 18, 2025
CVE-2025-62483
5.3

This vulnerability in Zoom Clients allows unauthenticated attackers to access sensitive information through network access due to improper data remova...

Nov 13, 2025
CVE-2025-14267
4.9

This vulnerability in M-Files Server allows sensitive information to be exposed due to incomplete data removal before transfer. It affects organizatio...

Dec 19, 2025
CVE-2024-6055
4.7

This vulnerability in Devolutions Remote Desktop Manager allows attackers who obtain exported configuration files to recover PowerShell credentials st...

Jun 17, 2024
CVE-2025-20118
4.4

This vulnerability in Cisco APIC allows authenticated local administrators to access sensitive information through insufficiently masked CLI command o...

Feb 26, 2025
CVE-2025-48708
4.0

This vulnerability in Artifex Ghostscript allows PDF passwords to be exposed in cleartext when processing certain PDF documents. It affects systems us...

May 23, 2025
CVE-2025-64326
2.6

Weblate versions 5.14 and below expose the IP address of project administrators in audit logs when inviting users to projects. This information leakag...

Nov 6, 2025

About CWE-212 (CWE-212)

Our database tracks 20 CVEs classified as CWE-212, with 1 rated critical and 10 rated high severity. The average CVSS score for CWE-212 vulnerabilities is 6.5.

External reference: View CWE-212 on MITRE CWE →

Monitor CWE-212 Vulnerabilities

Get alerted when new CWE-212 CVEs affect your infrastructure.

Start Monitoring Free