Weaknesses of type CWE-922

283 results

Armazenamento inseguro de informações sensíveis

É quando dados críticos (senhas, tokens, chaves criptográficas, PII) são guardados em local ou formato que qualquer pessoa com acesso ao sistema consegue ler. O risco: um atacante com acesso ao disco, memória ou arquivo de configuração rouba os dados sem esforço, comprometendo usuários e a aplicação inteira.

Example

Um app grava a senha do usuário em texto plano dentro de um arquivo .txt na raiz do projeto, ou armazena token de API em um cookie sem criptografia. Se o servidor for invadido ou o cliente roubado, as credenciais caem na mão de quem não deveria ter.

How to mitigate

Use criptografia forte (AES-256) para dados em repouso, aplique hash com salt (bcrypt, Argon2) em senhas, armazene segredos em vaults dedicados (AWS Secrets Manager, HashiCorp Vault), e nunca commita chaves ou credenciais no código. Revise regularmente o que é guardado e onde.

CVE-2024-3334MEDIUMUSB Security Feature Bypass in Digital Guardian Windows Agent Prior to version 8.2.0EPSS 0.1%CVE-2024-47122MEDIUMInsecure Storage of Sensitive Information in goTenna ProEPSS 0.1%CVE-2025-61482HIGHImproper handling of OTP/TOTP/HOTP values in NetKnights GmbH privacyIDEA Authenticator v.4.3.0 on Android allows local attackers with root aEPSS 0.1%CVE-2025-37110MEDIUMSensitive Credential Information stored insecurely in System DatabaseEPSS 0.1%CVE-2024-43694MEDIUMgoTenna Pro ATAK Plugin Insecure Storage of Sensitive InformationEPSS 0.1%CVE-2025-14376HIGHVerve Asset Manager – Plaintext Storage VulnerabilitiesEPSS 0.1%CVE-2023-40093MEDIUMIn multiple files, there is a possible way that trimmed content could be included in PDF output due to a logic error in the code. This couldEPSS 0.1%CVE-2025-42979MEDIUMInsecure Key & Secret Management vulnerability in SAP GUI for WindowsEPSS 0.1%CVE-2023-6460MEDIUMInformation leak in nodejs-firestoreEPSS 0.1%CVE-2026-20629MEDIUMA privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Tahoe 26.3. An app may be able to acceEPSS 0.1%CVE-2025-10971HIGHInsecure Storage of Sensitive InformationEPSS 0.1%CVE-2024-0037LOWIn applyCustomDescription of SaveUi.java, there is a possible way to view images belonging to a different user due to a missing permission cEPSS 0.1%CVE-2023-43630HIGHConfig Partition Not Measured From 2 FrontsEPSS 0.1%CVE-2026-7257MEDIUM** UNSUPPORTED WHEN ASSIGNED ** An insecure storage of sensitive information vulnerability in the configuration file of Zyxel WRE6505 v2 firEPSS 0.1%CVE-2024-34721MEDIUMIn ensureFileColumns of MediaProvider.java, there is a possible disclosure of files owned by another user due to improper input validation. EPSS 0.1%CVE-2026-20705MEDIUMInsecure storage of sensitive information in the Intel(R) TDX module for some Intel(R) platform within Ring 0: Trust Domain may allow informEPSS 0.1%CVE-2026-44629HIGHImproper access control to the Synergis Softwire installation folder. This vulnerability affects Streamvault all-in-one appliances (SV-100E EPSS 0.1%CVE-2025-32746MEDIUMDell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information vulnerability. An unauthenticated attackEPSS 0.1%CVE-2025-32751MEDIUMDell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information vulnerability. A low privileged attackerEPSS 0.1%CVE-2024-20050MEDIUMIn flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with SysEPSS 0.1%