CWE-922: CWE-922

72
Total CVEs
6
Critical
30
High
6.5
Avg CVSS

Yearly Trend

2026
1
2025
25
2024
33
2023
7
2022
2

Top Affected Vendors

1 Apple 7
2 Samsung 5
3 Broadcom 3
4 Google 2
5 Thecosy 2
6 Microsoft 2
7 Ovaledge 2
8 Ruoyi 1
9 Rhymix 1
10 Jenkins 1

All CWE-922 CVEs (72)

CVE-2025-12539
10.0

The TNC Toolbox: Web Performance WordPress plugin exposes cPanel API credentials in publicly accessible files, allowing unauthenticated attackers to r...

Nov 11, 2025
CVE-2023-32191
9.9

CVE-2023-32191 is a privilege escalation vulnerability in Rancher Kubernetes Engine (RKE) where non-admin users can access the 'full-cluster-state' Co...

Oct 16, 2024
CVE-2023-29727
9.8

CVE-2023-29727 is a critical vulnerability in Call Blocker 6.6.3 for Android that allows unauthorized applications to delete privacy-related data from...

May 30, 2023
CVE-2021-42371
9.8

CVE-2021-42371 is a critical vulnerability in XoruX LPAR2RRD and STOR2RRD monitoring software where a hardcoded 'lpar2rrd' system account exists with ...

Nov 8, 2021
CVE-2024-30896
9.1

InfluxDB OSS 2.x through 2.7.11 stores administrative operator tokens under the default organization, allowing users with read access to authorization...

Nov 21, 2024
CVE-2024-10943
9.1

This authentication bypass vulnerability allows attackers to impersonate legitimate users by exploiting shared secrets across accounts. Organizations ...

Nov 12, 2024
CVE-2025-28244
8.8

This vulnerability allows remote attackers to steal valid user session tokens from localStorage in Alteryx Server, enabling account takeover. Attacker...

Jul 10, 2025
CVE-2023-42913
8.8

This macOS vulnerability allows Remote Login sessions to bypass security controls and obtain full disk access permissions. It affects macOS systems wi...

Mar 28, 2024
CVE-2025-2241
8.2

This vulnerability exposes VCenter credentials in ClusterProvision objects within Hive (part of Multicluster Engine and Advanced Cluster Management). ...

Mar 17, 2025
CVE-2022-44619
8.2

This vulnerability in Intel DCM software allows authenticated local users to access insecurely stored sensitive information, potentially enabling priv...

May 10, 2023
CVE-2023-32184
7.8

This vulnerability allows local attackers to execute arbitrary code as the user running opensuse-welcome by exploiting insecure storage of sensitive i...

Sep 19, 2023
CVE-2023-29755
7.8

This vulnerability in Twilight v.13.3 for Android allows unauthorized apps to escalate privileges by manipulating SharedPreference files. Attackers ca...

Jun 9, 2023
CVE-2023-29757
7.8

This vulnerability in Blue Light Filter v1.5.5 for Android allows unauthorized apps to manipulate SharedPreference files, leading to privilege escalat...

Jun 9, 2023
CVE-2025-45242
7.7

This vulnerability in Rhymix CMS allows authenticated administrators to delete arbitrary files on the server through the procFileAdminEditImage method...

May 5, 2025
CVE-2024-42018
7.7

This vulnerability in Atos Eviden SMC xScale allows unprivileged users to access sensitive configuration parameters containing credentials after a reb...

Oct 11, 2024
CVE-2024-29968
7.7

An information disclosure vulnerability in Brocade SANnav allows authenticated users to access database structure and contents when configured in disa...

Apr 19, 2024
CVE-2024-12315
7.5

This vulnerability allows unauthenticated attackers to access sensitive exported data files stored in an insecure directory in the Export All Posts pl...

Feb 12, 2025
CVE-2024-57546
7.5

This vulnerability in CMSimple v5.16 allows remote attackers to perform Server-Side Request Forgery (SSRF) attacks through the validate link function....

Jan 27, 2025
CVE-2025-22983
7.5

An access control vulnerability in iceCMS v2.2.0 allows unauthenticated attackers to access sensitive information via the /square/getAllSquare/circle ...

Jan 14, 2025
CVE-2025-22984
7.5

An unauthenticated access control vulnerability in iceCMS v2.2.0 allows attackers to access sensitive information via the /api/squareComment/DelectSqu...

Jan 14, 2025
CVE-2024-56113
7.5

This vulnerability exposes sensitive configuration information from Django settings files when debug mode is enabled. Attackers can trigger verbose er...

Jan 9, 2025
CVE-2024-47043
7.5

This vulnerability in Ruijie Reyee OS allows attackers to correlate device serial numbers with user phone numbers and partial email addresses. It affe...

Dec 6, 2024
CVE-2024-48939
7.5

Paxton Net2 versions before 6.07.14023.5015 (SR4) have insufficient validation of REST API license files, allowing attackers to use the API with inval...

Nov 11, 2024
CVE-2024-10028
7.5

The Everest Backup WordPress plugin exposes sensitive information during backup operations, allowing unauthenticated attackers to discover backup arch...

Nov 6, 2024
CVE-2024-39339
7.5

A misconfiguration vulnerability in Smartplay headunits used in Suzuki and Toyota vehicles allows unauthorized access to sensitive information. This a...

Sep 18, 2024
CVE-2024-22808
7.5

This vulnerability allows attackers to cause a Denial of Service (DoS) in Tormach xsTECH CNC routers by overwriting the card's name in device memory, ...

Apr 22, 2024
CVE-2024-28069
7.5

An unauthenticated attacker can exploit an improper configuration in Mitel MiContact Center Business's legacy chat component to access sensitive infor...

Mar 16, 2024
CVE-2024-1936
7.5

This vulnerability in Thunderbird allows encrypted email subjects to be incorrectly assigned to other cached emails. When replying to contaminated ema...

Mar 4, 2024
CVE-2021-36546
7.5

KiteCMS 1.1 has an incorrect access control vulnerability that allows remote attackers to view sensitive files by manipulating URL paths. This affects...

Feb 3, 2023
CVE-2022-28168
7.5

Brocade SANnav versions before v2.2.0.2 and v2.1.1.8 store SCP server passwords in log files using only Base64 encoding, which provides no real securi...

Jun 27, 2022
CVE-2022-25264
7.5

This vulnerability in JetBrains TeamCity allows environment variables marked as 'password' type to be logged in certain cases, potentially exposing se...

Feb 25, 2022
CVE-2021-36786
7.5

The miniorange_saml extension for TYPO3 before version 1.4.3 exposes sensitive API credentials and private keys, allowing attackers to access authenti...

Aug 13, 2021
CVE-2021-22914
7.5

CVE-2021-22914 is an information disclosure vulnerability in Citrix Cloud Connector where sensitive authentication parameters are stored in plaintext ...

Jun 16, 2021
CVE-2023-40728
7.3

QMS Automotive versions before V12.39 store sensitive application data in insecure external storage via the QMS.Mobile module. This allows attackers w...

Sep 12, 2023
CVE-2024-57436
7.2

CVE-2024-57436 is a session ID exposure vulnerability in RuoYi v4.8.0 that allows unauthorized attackers to view admin session IDs through system moni...

Jan 29, 2025
CVE-2025-29809
7.1

This vulnerability allows an authorized attacker with local access to bypass a security feature in Windows Kerberos by exploiting insecure storage of ...

Apr 8, 2025
CVE-2025-22492
6.3

This vulnerability exposes database connection strings to users with access to the FRSCore database in Foreseer Reporting Software, allowing attackers...

Feb 28, 2025
CVE-2025-21041
6.2

This vulnerability allows local attackers to access sensitive information stored in Samsung's Secure Folder on Android devices. It affects Samsung dev...

Sep 3, 2025
CVE-2025-20912
6.2

An incorrect default permission vulnerability in DiagMonAgent on Samsung Galaxy Watch devices allows local attackers to access sensitive data. This af...

Mar 6, 2025
CVE-2024-37654
6.1

This vulnerability in BAS-IP video intercom devices allows remote attackers to obtain sensitive information via crafted HTTP GET requests. It affects ...

Jun 21, 2024
CVE-2024-44213
5.9

A URL parsing vulnerability in macOS allows attackers in privileged network positions to leak sensitive user information. This affects macOS Ventura a...

Oct 28, 2024
CVE-2024-6916
5.9

CVE-2024-6916 is an information disclosure vulnerability in Zowe CLI that allows local, privileged users to view securely stored properties in clearte...

Jul 19, 2024
CVE-2024-35526
5.9

This vulnerability in the FarCry Core framework allows attackers to access sensitive information stored in the /facade directory without authenticatio...

Jun 25, 2024
CVE-2024-51399
5.7

This vulnerability in Altai IX500 APs allows authenticated attackers to read sensitive files after login, potentially exposing credentials, configurat...

Nov 1, 2024
CVE-2025-42979
5.6

CVE-2025-42979 is a vulnerability in GuiXT application integrated with SAP GUI for Windows where RFC user credentials are stored using weak obfuscatio...

Jul 8, 2025
CVE-2026-20629
5.5

This macOS vulnerability allows applications to access sensitive user data through improper handling of temporary files. It affects macOS systems befo...

Feb 11, 2026
CVE-2025-21098
5.5

This vulnerability in OpenHarmony allows a local attacker to bypass permission checks and perform out-of-bounds reads, potentially leaking sensitive i...

Mar 4, 2025
CVE-2025-24101
5.5

A macOS vulnerability allows applications to access user-sensitive data that should be redacted. This affects macOS users running versions before Sequ...

Jan 27, 2025
CVE-2024-34721
5.5

This vulnerability in Android's MediaProvider allows improper file access across user boundaries due to insufficient input validation in the ensureFil...

Jul 9, 2024
CVE-2024-27789
5.5

This CVE-2024-27789 is a logic flaw in Apple operating systems that allows applications to access sensitive user data they shouldn't normally have per...

May 14, 2024

About CWE-922 (CWE-922)

Our database tracks 72 CVEs classified as CWE-922, with 6 rated critical and 30 rated high severity. The average CVSS score for CWE-922 vulnerabilities is 6.5.

External reference: View CWE-922 on MITRE CWE →

Monitor CWE-922 Vulnerabilities

Get alerted when new CWE-922 CVEs affect your infrastructure.

Start Monitoring Free