CWE-256— Plaintext Storage of a Password
225 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-256page 4 of 5
- CVE-2024-43378HIGHCVSS 7.8EG 7.82024-08-16
calamares-nixos-extensions provides Calamares branding and modules for NixOS, a distribution of GNU/Linux. Users who installed NixOS through the graphical installer who used manual disk partitioning to create a setup where the system was b…
- CVE-2024-43659HIGHCVSS 7.2EG 7.22025-01-09
After gaining access to the firmware of a charging station, a file at <redacted> can be accessed to obtain default credentials that are the same across all Iocharger AC model EV chargers. This issue affects Iocharger firmware for AC model…
- CVE-2024-4425MEDIUMCVSS 5.4EG 5.42024-05-14
The access control in CemiPark software stores integration (e.g. FTP or SIP) credentials in plain-text. An attacker who gained unauthorized access to the device can retrieve clear text passwords used by the system.This issue affects CemiP…
- CVE-2024-44815MEDIUMCVSS 4.6EG 8.02024-09-10
Vulnerability in Hathway Skyworth Router CM5100 v.4.1.1.24 allows a physically proximate attacker to obtain user credentials via SPI flash Firmware W25Q64JV.
- CVE-2024-45283MEDIUMCVSS 6.0EG 6.02024-09-10
SAP NetWeaver AS for Java allows an authorized attacker to obtain sensitive information. The attacker could obtain the username and password when creating an RFC destination. After successful exploitation, an attacker can read the sensitiv…
- CVE-2024-45638MEDIUMCVSS 4.1EG 4.12025-03-14
IBM Security QRadar 3.12 EDR stores user credentials in plain text which can be read by a local privileged user.
- CVE-2024-49351MEDIUMCVSS 5.5EG 5.52024-11-26
IBM Workload Scheduler 9.5, 10.1, and 10.2 stores user credentials in plain text which can be read by a local user.
- CVE-2024-49370MEDIUMCVSS 4.9EG 4.92024-10-23
Pimcore is an open source data and experience management platform. When a PortalUserObject is connected to a PimcoreUser and "Use Pimcore Backend Password" is set to true, the change password function in Portal Profile sets the new passwor…
- CVE-2024-52361MEDIUMCVSS 5.7EG 5.72024-12-18
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9 stores user credentials in plain text which can be read by an authenticated user with access to the pod.
- CVE-2024-53292HIGHCVSS 7.2EG 7.22024-12-11
Dell VxVerify, versions prior to x.40.405, contain a Plain-text Password Storage Vulnerability in the shell wrapper. A local high privileged attacker could potentially exploit this vulnerability, leading to the disclosure of certain user c…
- CVE-2024-5960CRITICALCVSS 9.8EG 9.82024-09-18
Plaintext Storage of a Password vulnerability in Eliz Software Panel allows : Use of Known Domain Credentials. This issue affects Panel: before v2.3.24.
- CVE-2024-6118CRITICALCVSS 9.1EG 9.12024-08-05
A Plaintext Storage of a Password vulnerability in ebooknote function in Hamastar MeetingHub Paperless Meetings 2021 allows remote attackers to obtain the other users’ credentials and gain access to the product via an XML file.
- CVE-2024-9418MEDIUMCVSS 6.5EG 6.52025-03-20
In version 0.0.14 of transformeroptimus/superagi, the API endpoint `/api/users/get/{id}` returns the user's password in plaintext. This vulnerability allows an attacker to retrieve the password of another user, leading to potential account…
- CVE-2025-0936MEDIUMCVSS 6.5EG 6.52025-05-07
On affected platforms running Arista EOS with a gNMI transport enabled, running the gNOI File TransferToRemote RPC with credentials for a remote server may cause these remote-server credentials to be logged or accounted on the local EOS de…
- CVE-2025-11193MEDIUMCVSS 5.5EG 5.52025-11-03
A potential vulnerability was reported in some Lenovo Tablets that could allow a local authenticated user or application to gain access to sensitive device specific information.
- CVE-2025-12680MEDIUMCVSS 4.9EG 4.92026-02-02
Brocade SANnav before Brocade SANnav 2.4.0b logs database passwords in clear text in the standby SANnav server, after disaster recovery failover. The vulnerability could allow a remote authenticated attacker with admin privilege able to a…
- CVE-2025-13187MEDIUMCVSS 5.3EG 5.32025-11-14
A security vulnerability has been detected in Intelbras ICIP 2.0.20. Affected is an unknown function of the file /xml/sistema/acessodeusuario.xml. Such manipulation of the argument NomeUsuario/SenhaAcess leads to unprotected storage of cre…
- CVE-2025-13221MEDIUMCVSS 5.3EG 5.32025-11-15
A weakness has been identified in Intelbras UnniTI 24.07.11. The affected element is an unknown function of the file /xml/sistema/usuarios.xml. Executing manipulation of the argument Usuario/Senha can lead to unprotected storage of credent…
- CVE-2025-14183MEDIUMCVSS 4.3EG 4.32025-12-07
A vulnerability was found in SGAI Space1 NAS N1211DS up to 1.0.915. This issue affects the function GET_FACTORY_INFO/GET_USER_INFO of the file /cgi-bin/JSONAPI of the component gsaiagent. The manipulation results in unprotected storage of …
- CVE-2025-15113CRITICALCVSS 9.3EG 7.82025-12-30
Ksenia Security lares (legacy model) Home Automation version 1.6 contains an unprotected endpoint vulnerability that allows authenticated attackers to upload MPFS File System binary images. Attackers can exploit this vulnerability to overw…
- CVE-2025-15128MEDIUMCVSS 5.3EG 5.32025-12-28
A vulnerability was detected in ZKTeco BioTime up to 9.0.3/9.0.4/9.5.2. This affects an unknown part of the file /base/safe_setting/ of the component Endpoint. Performing a manipulation of the argument backup_encryption_password_decrypt/ex…
- CVE-2025-15624HIGHCVSS 7.5EG 7.52026-04-17
Plaintext Storage of a Password vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server. In a setup where OpenID is used as the primary method of authentication to authenticate to Sparx EA, Pro Cloud Server creates local passwords…
- CVE-2025-1709MEDIUMCVSS 6.5EG 6.52025-07-03
Several credentials for the local PostgreSQL database are stored in plain text (partially base64 encoded).
- CVE-2025-21102HIGHCVSS 7.5EG 7.52025-01-08
Dell VxRail, versions 7.0.000 through 7.0.532, contain(s) a Plaintext Storage of a Password vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.
- CVE-2025-21111HIGHCVSS 7.5EG 7.52025-01-08
Dell VxRail, versions 8.0.000 through 8.0.311, contain(s) a Plaintext Storage of a Password vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.
- CVE-2025-2355LOWCVSS 3.3EG 3.32025-03-17
A vulnerability was found in BlackVue App 3.65 on Android and classified as problematic. Affected by this issue is some unknown functionality of the component API Endpoint Handler. The manipulation of the argument BCS_TOKEN/SECRET_KEY lead…
- CVE-2025-24375MEDIUMCVSS 5.0EG 5.02025-04-09
Charmed MySQL K8s operator is a Charmed Operator for running MySQL on Kubernetes. Before revision 221, the method for calling a SQL DDL or python based mysql-shell scripts can leak database users credentials. The method mysql-operator call…
- CVE-2025-2500HIGHCVSS 7.4EG 7.42025-05-30
A vulnerability exists in the SOAP Web services of the Asset Suite versions listed below. If successfully exploited, an attacker could gain unauthorized access to the product and the time window of a possible password attack could be exp…
- CVE-2025-25051MEDIUMCVSS 6.1EG 6.12026-01-22
An attacker could decrypt sensitive data, impersonate legitimate users or devices, and potentially gain access to network resources for lateral attacks.
- CVE-2025-25727MEDIUMCVSS 6.2EG 6.22025-02-28
Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 were discovered to store passwords in cleartext.
- CVE-2025-25985LOWCVSS 2.6EG 2.62025-04-18
An issue in Macro-video Technologies Co.,Ltd V380E6_C1 IP camera (Hw_HsAKPIQp_WF_XHR) 1020302 allows a physically proximate attacker to execute arbitrary code via the /mnt/mtd/mvconf/wifi.ini and /mnt/mtd/mvconf/user_info.ini components.
- CVE-2025-27656CRITICALCVSS 9.8EG 9.82025-03-05
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Password Stored in Process List V-2023-011.
- CVE-2025-27662CRITICALCVSS 9.8EG 9.82025-03-05
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Password in URL OVE-20230524-0005.
- CVE-2025-2770MEDIUMCVSS 6.5EG 4.92025-04-23
BEC Technologies Multiple Routers Cleartext Password Storage Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of BEC Technologies routers. Authenti…
- CVE-2025-31724MEDIUMCVSS 4.3EG 4.32025-04-02
Jenkins Cadence vManager Plugin 4.0.0-282.v5096a_c2db_275 and earlier stores Verisium Manager vAPI keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or acces…
- CVE-2025-33079MEDIUMCVSS 6.5EG 6.52025-05-27
IBM Controller 11.0.0, 11.0.1, and 11.1.0 application could allow an authenticated user to obtain sensitive credentials that may be inadvertently included within the source code.
- CVE-2025-34210MEDIUMCVSS 5.5EG 5.52025-10-02
Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) store a large number of sensitive credentials (database passwords, MySQL root password, SaaS keys, Portainer admin password, etc.) in clearte…
- CVE-2025-36002MEDIUMCVSS 5.5EG 5.52025-10-16
IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5, and 6.2.1.0 stores user credentials in configuration files which can be read by a local user.
- CVE-2025-36335MEDIUMCVSS 6.2EG 6.22026-04-30
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.3.0, 5.3.1 stores user credentials in plain text which can be read by a local user.
- CVE-2025-36425MEDIUMCVSS 5.3EG 5.32026-02-17
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 could allow an authenticated user to obtain sensitive information under specific HADR configuration.
- CVE-2025-3758HIGHCVSS 8.7EG 0.02025-05-08
WF2220 exposes endpoint /cgi-bin-igd/netcore_get.cgi that returns configuration of the device to unauthorized users. Returned configuration includes cleartext password. The vendor was contacted early about this disclosure but did not res…
- CVE-2025-4286LOWCVSS 2.7EG 2.72025-05-05
A vulnerability was found in Intelbras InControl up to 2.21.59. It has been classified as problematic. Affected is an unknown function of the component Dispositivos Edição Page. The manipulation of the argument Senha de Comunicação lea…
- CVE-2025-43005MEDIUMCVSS 4.3EG 4.32025-05-13
SAP GUI for Windows allows an unauthenticated attacker to exploit insecure obfuscation algorithms used by the GuiXT application to store user credentials. While this issue does not impact the Integrity or Availability of the application, i…
- CVE-2025-43938MEDIUMCVSS 5.0EG 5.02025-09-10
Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) a Plaintext Storage of a Password vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to the discl…
- CVE-2025-45702MEDIUMCVSS 6.5EG 6.52025-07-24
SoftPerfect Pty Ltd Connection Quality Monitor v1.1 was discovered to store all credentials in plaintext.
- CVE-2025-46366MEDIUMCVSS 6.7EG 6.72025-11-05
Dell CloudLink, versions prior to 8.1.1, contain a vulnerability where a privileged user may exploit and gain parallel privilege escalation or access to the database to obtain confidential information.
- CVE-2025-46809MEDIUMCVSS 5.7EG 5.72025-07-31
A Plaintext Storage of a Password vulnerability in SUSE exposes the credentials for the HTTP proxy in the log files. This issue affects Container suse/manager/4.3/proxy-httpd:4.3.16.9.67.1: from ? before 4.3.33-150400.3.55.2; Container su…
- CVE-2025-48046MEDIUMCVSS 5.3EG 0.02025-05-29
An authenticated user can disclose the cleartext password of a configured SMTP server via an HTTP GET request to the /config.php endpoint.
- CVE-2025-52164HIGHCVSS 8.2EG 8.22025-07-18
Software GmbH Agorum core open v11.9.2 & v11.10.1 was discovered to store credentials in plaintext.
- CVE-2025-53655MEDIUMCVSS 5.3EG 4.32025-07-09
Jenkins Statistics Gatherer Plugin 2.0.3 and earlier does not mask the AWS Secret Key on the global configuration form, increasing the potential for attackers to observe and capture it.
Map vulnerabilities like CWE-256 to your infrastructure
EchelonGraph correlates every CVE — across CWE-256 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →