Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, Wallos endpoints/logos/se
Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to 1.16.4, kyverno’s apiCall serv
Improper access control to the Synergis Softwire installation folder. This vulnerability affects Streamvault all-in-one
Gophish <=0.12.1 is vulnerable to Incorrect Access Control. The administrative dashboard exposes each user’s long-lived
Insecure storage of sensitive information in Windows Cryptographic Services allows an authorized attacker to elevate pri
Insecure Storage of Sensitive Information vulnerability in Birtech Information Technologies Industry and Trade Ltd. Co.
A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Tahoe 26.3. An app
Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information vulnerability. A low
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.0 stores potentially sensitive information in log files that could be
The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for
A vulnerability was found in code-projects Online Application System for Admission 1.0. Impacted is an unknown function
A vulnerability was detected in code-projects Online FIR System 1.0. Affected by this issue is some unknown functionalit
In versions of the Datadog Android application prior to v554-5.9.4, two Room-backed SQLite databases store sensitive con
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 stores TPM2.0 secrets in a serialized format within unused disk s
** UNSUPPORTED WHEN ASSIGNED ** An insecure storage of sensitive information vulnerability in the configuration file of
Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information vulnerability. An un
A security issue was discovered within the legacy ADI server component of Verve Asset Manager, caused by plaintext secre
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an attack chain utilizing
Insecure storage of sensitive information in the Intel(R) TDX module for some Intel(R) platform within Ring 0: Trust Dom
Frequently Asked Questions
What is CWE-922?
CWE-922 (CWE-922) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-922?
There are 20 CVE records associated with CWE-922 in our database. Of these, 1 are critical severity, 4 are high severity, and 11 are medium severity.
How can I protect against CWE-922 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-922 using AI-powered security agents.
Detect CWE-922 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-922 vulnerabilities across your infrastructure.
Get Started