Vulnerabilities (CVE)

Filtered by CWE-922
Total 377 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-32236 1 Cmseasy 1 Cmseasy 2026-06-17 N/A 3.5 LOW
An issue in CmsEasy v.7.7 and before allows a remote attacker to obtain sensitive information via the update function in the index.php component.
CVE-2024-32211 1 Logint 1 Lomag Warehouse Management 2026-06-17 N/A 5.5 MEDIUM
An issue in LOGINT LoMag Inventory Management v1.0.20.120 and before allows a local attacker to obtain sensitive information via the UserClass.cs and Settings.cs components.
CVE-2024-31404 1 Cybozu 1 Garoon 2026-06-17 N/A 4.3 MEDIUM
Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.5.0 to 6.0.0, which may allow a user who can log in to the product to view the data of Scheduler.
CVE-2024-31400 1 Cybozu 1 Garoon 2026-06-17 N/A 6.5 MEDIUM
Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.0.0 to 5.15.0. If this vulnerability is exploited, unintended data may be left in forwarded mail.
CVE-2024-31278 1 Leap13 1 Premium Addons For Elementor 2026-06-17 N/A 4.3 MEDIUM
Insertion of Sensitive Information Into Sent Data vulnerability in Leap13 Premium Addons for Elementor premium-addons-for-elementor.This issue affects Premium Addons for Elementor: from n/a through <= 4.10.22.
CVE-2024-30917 1 Eprosima 1 Fast Dds 2026-06-17 N/A 5.5 MEDIUM
An issue was discovered in eProsima FastDDS v.2.14.0 and before, allows a local attacker to cause a denial of service (DoS) and obtain sensitive information via a crafted history_depth parameter in DurabilityService QoS component.
CVE-2024-30896 2026-06-17 N/A 9.1 CRITICAL
InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows authorized users with read access to the authorization resource of the default organization to retrieve the operator token. InfluxDB OSS 1.x, Enterprise, Cloud, Cloud Dedicated and Clustered are not affected. NOTE: The researcher states that InfluxDB allows allAccess administrators to retrieve all raw tokens via an "influx auth ls" command. The supplier indicates that the organizations feature is operating as intended and that users may choose to add users to non-default organizations. A future release of InfluxDB 2.x will remove the ability to retrieve tokens from the API. The supplier has stated that InfluxDB 2.8.0 has addressed this issue.
CVE-2024-30132 1 Hcltech 1 Nomad Server On Domino 2026-06-17 N/A 3.7 LOW
HCL Nomad server on Domino did not configure certain HTTP Security headers by default which could allow an attacker to obtain sensitive information via unspecified vectors.
CVE-2024-30122 1 Hcltech 1 Sametime 2026-06-17 N/A 5.8 MEDIUM
HCL Sametime is impacted by misconfigured security related HTTP headers. It was identified that some HTTP headers were missing on web service responses. This will lead to less secure browser default treatment for the policies controlled by these headers.
CVE-2024-2974 1 Wpdeveloper 1 Essential Addons For Elementor 2026-06-17 N/A 5.3 MEDIUM
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 5.9.13 via the load_more function. This can allow unauthenticated attackers to extract sensitive data including private and draft posts.
CVE-2024-29968 1 Broadcom 1 Brocade Sannav 2026-06-17 N/A 7.7 HIGH
An information disclosure vulnerability exists in Brocade SANnav before v2.3.1 and v2.3.0a when Brocade SANnav instances are configured in disaster recovery mode. SQL Table names, column names, and SQL queries are collected in DR standby Supportsave. This could allow authenticated users to access the database structure and its contents.
CVE-2024-29965 1 Broadcom 1 Brocade Sannav 2026-06-17 N/A 6.8 MEDIUM
In Brocade SANnav before v2.3.1, and v2.3.0a, it is possible to back up the appliance from the web interface or the command line interface ("SSH"). The resulting backups are world-readable. A local attacker can recover backup files, restore them to a new malicious appliance, and retrieve the passwords of all the switches.
CVE-2024-29953 1 Broadcom 1 Fabric Operating System 2026-06-17 N/A 4.3 MEDIUM
A vulnerability in the web interface in Brocade Fabric OS before v9.2.1, v9.2.0b, and v9.1.1d prints encoded session passwords on session storage for Virtual Fabric platforms. This could allow an authenticated user to view other users' session encoded passwords.
CVE-2024-29120 1 Apache 1 Streampark 2026-06-17 N/A 5.9 MEDIUM
In Streampark (version < 2.1.4), when a user logged in successfully, the Backend service would return "Authorization" as the front-end authentication credential. User can use this credential to request other users' information, including the administrator's username, password, salt value, etc.  Mitigation: all users should upgrade to 2.1.4
CVE-2024-28808 1 Nokia 2 Hit 7300, Hit 7300 Firmware 2026-06-17 N/A 2.7 LOW
An issue was discovered in Infinera hiT 7300 5.60.50. Hidden functionality in the web interface allows a remote authenticated attacker to access reserved information by accessing undocumented web applications.
CVE-2024-28132 1 F5 1 Big-ip Next Cloud-native Network Functions 2026-06-17 N/A 4.4 MEDIUM
Exposure of Sensitive Information vulnerability exists in the GSLB container, which may allow an authenticated attacker with local access to view sensitive information.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2024-28069 1 Mitel 1 Micontact Center Business 2026-06-17 N/A 7.5 HIGH
A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct an information disclosure attack due to improper configuration. A successful exploit could allow an attacker to access sensitive information and potentially conduct unauthorized actions within the vulnerable component.
CVE-2024-27789 1 Apple 3 Ipados, Iphone Os, Macos 2026-06-17 N/A 5.5 MEDIUM
A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, macOS Monterey 12.7.5, macOS Sonoma 14.4, macOS Ventura 13.6.7. An app may be able to access user-sensitive data.
CVE-2024-27232 1 Google 1 Android 2026-06-17 N/A 5.5 MEDIUM
In asn1_ec_pkey_parse of asn1_common.c, there is a possible OOB read due to a missing null check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-26559 1 Dagg 1 Uverif 2026-06-17 N/A 5.3 MEDIUM
An issue in uverif v.2.0 allows a remote attacker to obtain sensitive information.