CWE-922
CVEs classified under CWE-922, newest first.
5 CVEsRSS
CVE-2026-77875Medium· 6.8The application protects access through its calculator-style vault passcode, but the stored data is not bound to that authentication boundary
The application protects access through its calculator-style vault passcode, but the stored data is not bound to that authentication boundary. A local actor who can access shared external storage, such as through an authorized non-root A…
CVE-2026-44629High· 7.9Improper access control to the Synergis Softwire installation folder
Improper access control to the Synergis Softwire installation folder. This vulnerability affects Streamvault all-in-one appliances (SV-100E and SV-300E series) and Synergis Softwire installed on Windows servers.
CVE-2025-2241High· 8.2A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM)
A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Us…
CVE-2024-10041Medium· 4.7A vulnerability was found in PAM
A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the br…
CVE-2024-38312Medium· 6.5When browsing private tabs, some data related to location history or webpage thumbnails could be persisted incorrectly within the sandboxed app bundle after app termination This vulnerability affects Firefox for iOS < 127.
When browsing private tabs, some data related to location history or webpage thumbnails could be persisted incorrectly within the sandboxed app bundle after app termination This vulnerability affects Firefox for iOS < 127.