CWE-922: CWE-922

72
Total CVEs
6
Critical
30
High
6.5
Avg CVSS

Yearly Trend

2026
1
2025
25
2024
33
2023
7
2022
2

Top Affected Vendors

1 Apple 7
2 Samsung 5
3 Broadcom 3
4 Google 2
5 Thecosy 2
6 Microsoft 2
7 Ovaledge 2
8 Ruoyi 1
9 Rhymix 1
10 Jenkins 1

All CWE-922 CVEs (72)

CVE-2024-23229
5.5

A macOS vulnerability allows malicious applications to access Find My data, which could expose location information and device details. This affects m...

May 14, 2024
CVE-2020-1493
5.5

This CVE describes an information disclosure vulnerability in Microsoft Outlook where files attached as links to emails could be accessed by unauthori...

Aug 17, 2020
CVE-2025-46660
5.3

This vulnerability in 4C Strategies Exonaut 21.6 allows attackers to more easily crack user passwords if they gain access to the database, since passw...

Aug 6, 2025
CVE-2022-30361
5.3

OvalEdge versions 5.2.8.0 and earlier expose sensitive user information through an unauthenticated GET request to /user/getUserType. This vulnerabilit...

Oct 25, 2024
CVE-2024-21258
5.3

This vulnerability in Oracle E-Business Suite's Installed Base component allows unauthenticated attackers to read sensitive data via HTTP requests. It...

Oct 15, 2024
CVE-2022-44581
5.0

This vulnerability in WPMU DEV Defender Security WordPress plugin allows attackers to access sensitive information stored in temporary files. It affec...

May 17, 2024
CVE-2024-10041
4.7

This CVE describes a speculative execution vulnerability in PAM (Pluggable Authentication Modules) where an attacker can manipulate branch prediction ...

Oct 23, 2024
CVE-2019-20469
4.6

This vulnerability allows attackers with physical access to One2Track smartwatches to retrieve confidential audio recordings stored on the device. The...

Nov 7, 2024
CVE-2024-28132
4.4

This CVE describes an information disclosure vulnerability in F5's GSLB container where authenticated local attackers can access sensitive information...

May 8, 2024
CVE-2024-20050
4.4

This vulnerability in the flashc component allows local information disclosure when exploited by a process with System execution privileges. It affect...

Apr 1, 2024
CVE-2024-48883
4.3

This vulnerability in Samsung Exynos processors allows information leakage when a malformed uplink scheduling message is incorrectly handled. It affec...

Jan 13, 2025
CVE-2022-30359
4.3

OvalEdge versions 5.2.8.0 and earlier expose sensitive user data through an authenticated GET request to /user/getUserList. This vulnerability allows ...

Oct 25, 2024
CVE-2024-39459
4.3

The Jenkins Plain Credentials Plugin versions 182.v468b_97b_9dcb_8 and earlier store secret file credentials unencrypted (only Base64 encoded) on the ...

Jun 26, 2024
CVE-2024-29953
4.3

This vulnerability in Brocade Fabric OS web interface exposes encoded session passwords in session storage on Virtual Fabric platforms. It allows auth...

Jun 26, 2024
CVE-2024-31404
4.3

This vulnerability in Cybozu Garoon allows authenticated users to view sensitive Scheduler data they shouldn't have access to. It affects users who ca...

Jun 11, 2024
CVE-2023-6748
4.3

The Custom Field Template WordPress plugin up to version 2.6.1 contains a vulnerability that allows authenticated attackers with contributor-level acc...

Jun 11, 2024
CVE-2025-2440
4.2

A CWE-922 vulnerability in Schneider Electric products allows unauthorized access to sensitive information when a malicious user with physical access ...

Apr 9, 2025
CVE-2025-21045
4.0

This vulnerability allows local attackers to access sensitive information stored insecurely on Galaxy Watch devices. It affects Galaxy Watch users who...

Oct 10, 2025
CVE-2025-43203
4.0

This vulnerability allows an attacker with physical access to an unlocked iOS/iPadOS device to view an image from the most recently viewed locked note...

Sep 15, 2025
CVE-2025-21003
4.0

This vulnerability allows local attackers to access sensitive information stored insecurely in the Emergency SOS feature on Samsung devices. It affect...

Jul 8, 2025
CVE-2025-48929
4.0

This vulnerability in TeleMessage allows attackers to reuse stolen long-lived authentication credentials to gain unauthorized access to the service. I...

May 28, 2025
CVE-2025-10971
N/A

The MeetMe mobile application stores sensitive information insecurely, allowing attackers to retrieve embedded data from the app's storage. This affec...

Dec 2, 2025

About CWE-922 (CWE-922)

Our database tracks 72 CVEs classified as CWE-922, with 6 rated critical and 30 rated high severity. The average CVSS score for CWE-922 vulnerabilities is 6.5.

External reference: View CWE-922 on MITRE CWE →

Monitor CWE-922 Vulnerabilities

Get alerted when new CWE-922 CVEs affect your infrastructure.

Start Monitoring Free