CWE-312— Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.— MITRE CWE catalog
836 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-312page 16 of 17
- CVE-2025-54464HIGHCVSS 7.0EG 7.02025-08-13
This vulnerability exists in ZKTeco WL20 due to storage of admin and user credentials without encryption in the device firmware. An attacker with physical access could exploit this vulnerability by extracting the firmware and reverse engin…
- CVE-2025-54537MEDIUMCVSS 5.5EG 5.52025-07-28
In JetBrains TeamCity before 2025.07 user credentials were stored in plain text in memory snapshots
- CVE-2025-54538MEDIUMCVSS 5.5EG 5.52025-07-28
In JetBrains TeamCity before 2025.07 password exposure was possible via command line in the "hg pull" command
- CVE-2025-54855MEDIUMCVSS 4.2EG 4.22025-09-23
Cleartext storage of sensitive information was discovered in Click Programming Software version v3.60. The vulnerability can be exploited by a local user with access to the file system, while an administrator session is active, to steal cr…
- CVE-2025-55280MEDIUMCVSS 5.2EG 5.22025-08-13
This vulnerability exists in ZKTeco WL20 due to storage of Wi-Fi credentials, configuration data and system data in plaintext within the device firmware. An attacker with physical access could exploit this vulnerability by extracting the f…
- CVE-2025-55334MEDIUMCVSS 6.2EG 6.22025-10-14
Cleartext storage of sensitive information in Windows Kernel allows an unauthorized attacker to bypass a security feature locally.
- CVE-2025-55443CRITICALCVSS 9.1EG 9.12025-08-26
Telpo MDM 1.4.6 thru 1.4.9 for Android contains sensitive administrator credentials and MQTT server connection details (IP/port) that are stored in plaintext within log files on the device's external storage. This allows attackers with acc…
- CVE-2025-55717MEDIUMCVSS 4.0EG 4.02026-03-10
A cleartext storage of sensitive information vulnerability [CWE-312] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiRecorder 7.2.0 …
- CVE-2025-57806MEDIUMCVSS 6.9EG 6.92025-09-03
Local Deep Research is an AI-powered research assistant for deep, iterative research. Versions 0.2.0 through 0.6.7 stored confidential information, including API keys, in a local SQLite database without encryption. This behavior was not cl…
- CVE-2025-58401MEDIUMCVSS 6.8EG 6.82025-09-05
Obsidian GitHub Copilot Plugin versions prior to 1.1.7 store Github API token in cleartext form. As a result, an attacker may perform unauthorized operations on the linked Github account.
- CVE-2025-59102MEDIUMCVSS 6.9EG 6.92026-01-26
The web server of the Access Manager offers a functionality to download a backup of the local database stored on the device. This database contains the whole configuration. This includes encrypted MIFARE keys, card data, user PINs and much…
- CVE-2025-59105HIGHCVSS 7.0EG 7.02026-01-26
With physical access to the device and enough time an attacker can desolder the flash memory, modify it and then reinstall it because of missing encryption. Thus, essential files, such as "/etc/passwd", as well as stored certificates, cryp…
- CVE-2025-59409HIGHCVSS 7.5EG 7.52025-10-02
Flock Safety Falcon and Sparrow License Plate Readers OPM1.171019.026 ship with development Wi-Fi credentials (test_flck) stored in cleartext in production firmware.
- CVE-2025-59450MEDIUMCVSS 4.3EG 4.32025-10-06
The YoSmart YoLink Smart Hub firmware 0382 is unencrypted, and data extracted from it can be used to determine network access credentials.
- CVE-2025-59701MEDIUMCVSS 4.1EG 4.12025-12-02
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker (with elevated privileges) to read and modify the Appliance SSD contents (because they are unencrypted).
- CVE-2025-59792MEDIUMCVSS 5.3EG 5.32025-11-28
Reveals plaintext credentials in the MONITOR command vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 1.0.0 through 2.13.0. Users are recommended to upgrade to version 2.14.0, which fixes the issue.
- CVE-2025-6224MEDIUMCVSS 6.5EG 6.52025-07-01
Certificate generation in juju/utils using the cert.NewLeaf function could include private information. If this certificate were then transferred over the network in plaintext, an attacker listening on that network could sniff the certific…
- CVE-2025-62261MEDIUMCVSS 6.5EG 6.52025-10-27
Liferay Portal 7.4.0 through 7.4.3.99, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 34, and older unsupported versions stores password reset tokens in plain te…
- CVE-2025-63208HIGHCVSS 7.5EG 7.52025-11-19
An issue was discovered in bridgetech VB288 Objective QoE Content Extractor, firmware version 5.6.0-8, allowing attackers to gain sensitive information such as administrator passwords via the /probe/core/setup/passwd endpoint.
- CVE-2025-63729CRITICALCVSS 9.0EG 9.02025-11-25
An issue was discovered in Syrotech SY-GPON-1110-WDONT SYRO_3.7L_3.1.02-240517 allowing attackers to exctract the SSL Private Key, CA Certificate, SSL Certificate, and Client Certificates in .pem format in firmware in etc folder.
- CVE-2025-65278HIGHCVSS 7.5EG 7.52025-11-26
An issue was discovered in file users.json in GroceryMart commit 21934e6 (2020-10-23) allowing unauthenticated attackers to gain sensitive information including plaintext usernames and passwords.
- CVE-2025-65320HIGHCVSS 7.5EG 7.52025-12-03
Abacre Restaurant Point of Sale (POS) up to 15.0.0.1656 are vulnerable to Cleartext Storage of Sensitive Information in Memory. The application leaves valid device-bound license keys in process memory during an activation attempt.
- CVE-2025-65826CRITICALCVSS 9.8EG 9.82025-12-10
The mobile application was found to contain stored credentials for the network it was developed on. If an attacker retrieved this, and found the physical location of the Wi-Fi network, they could gain unauthorized access to the Wi-Fi netwo…
- CVE-2025-6748LOWCVSS 2.1EG 2.12025-06-27
A vulnerability classified as problematic has been found in Bharti Airtel Thanks App 4.105.4 on Android. Affected is an unknown function of the file /Android/data/com.myairtelapp/files/. The manipulation leads to cleartext storage in a fil…
- CVE-2025-67637MEDIUMCVSS 4.3EG 4.32025-12-10
Jenkins 2.540 and earlier, LTS 2.528.2 and earlier stores build authorization tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkin…
- CVE-2025-67638MEDIUMCVSS 4.3EG 4.32025-12-10
Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not mask build authorization tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.
- CVE-2025-70050MEDIUMCVSS 6.5EG 6.52026-03-09
An issue pertaining to CWE-312: Cleartext Storage of Sensitive Information was discovered in lesspass lesspass v9.6.9 which allows attackers to obtain sensitive information.
- CVE-2025-7215LOWCVSS 1.6EG 1.62025-07-09
A vulnerability, which was classified as problematic, has been found in FNKvision FNK-GU2 up to 40.1.7. Affected by this issue is some unknown functionality of the file /rom/wpa_supplicant.conf. The manipulation leads to cleartext storage …
- CVE-2025-7397HIGHCVSS 7.1EG 7.12025-07-17
A vulnerability in the ascgshell, of Brocade ASCG before 3.3.0 stores any command executed in the Command Line Interface (CLI) in plain text within the command history. A local authenticated user that can access sensitive information li…
- CVE-2025-7426CRITICALCVSS 9.3EG 9.32025-08-25
Information disclosure and exposure of authentication FTP credentials over the debug port 1604 in the MINOVA TTA service. This allows unauthenticated remote access to an active FTP account containing sensitive internal data and import stru…
- CVE-2025-7738MEDIUMCVSS 4.4EG 4.42025-07-31
A flaw was found in Ansible Automation Platform (AAP) where the Gateway API returns the client secret for certain GitHub Enterprise authenticators in clear text. This vulnerability affects administrators or auditors accessing authenticator…
- CVE-2025-8528MEDIUMCVSS 5.9EG 5.92025-08-04
A vulnerability classified as problematic has been found in Exrick xboot up to 3.3.4. Affected is an unknown function of the file /xboot/permission/getMenuList. The manipulation leads to cleartext storage of sensitive information in a cook…
- CVE-2026-10786MEDIUMCVSS 6.5EG 6.52026-06-08
Improper access control in the ticketing integration settings in Devolutions Server allows an authenticated low-privileged user to obtain cleartext credentials for configured ticketing integrations via a crafted API request. This issue af…
- CVE-2026-13380CRITICALCVSS 9.0EG 9.02026-07-20
VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthenticated endpoints. The credentials are present in these responses only when SFTP connections have been configured within…
- CVE-2026-16213LOWCVSS 3.3EG 3.32026-07-19
A security flaw has been discovered in Fantomas42 django-blog-zinnia up to 0.20. Affected by this vulnerability is an unknown functionality of the file zinnia/views/mixins/entry_protection.py of the component Protected Entry Password Handl…
- CVE-2026-16802MEDIUMCVSS 6.5EG 6.52026-07-24
Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local actor with file system access to read secret values via secret variables stored in cleartext on dis…
- CVE-2026-22240HIGHCVSS 7.5EG 7.52026-01-14
The vulnerability exists in BLUVOYIX due to an improper password storage implementation and subsequent exposure via unauthenticated APIs. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP…
- CVE-2026-22276MEDIUMCVSS 5.5EG 5.52026-01-23
Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Storage of Sensitive Information vulnerability. A low privileged attacker with local access could potentially exploit this vul…
- CVE-2026-23655MEDIUMCVSS 6.5EG 6.52026-02-10
Cleartext storage of sensitive information in Azure Compute Gallery allows an authorized attacker to disclose information over a network.
- CVE-2026-24311MEDIUMCVSS 5.6EG 5.62026-03-10
The SAP Customer Checkout application exhibits certain design characteristics that involve locally storing operational data using reversible protection mechanisms. Access to this data, combined with user?initiated interaction, may allow mo…
- CVE-2026-24319MEDIUMCVSS 5.8EG 5.82026-02-10
In SAP Business One, sensitive information is written to the application�s memory dump files without obfuscation. Gaining access to this information could potentially lead to unauthorized operations within the B1 environment, including m…
- CVE-2026-25751HIGHCVSS 7.5EG 7.52026-02-06
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An information disclosure vulnerability in FUXA allows an unauthenticated, remote attacker to retrieve sensitive administrative database credentials. Exploitation al…
- CVE-2026-27520HIGHCVSS 7.5EG 7.52026-02-24
Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209 store a user password in a client-side cookie as a Base64-encoded value accessible via the web interface. Because Base64 is reversible and provides no confid…
- CVE-2026-27877MEDIUMCVSS 6.5EG 6.52026-03-27
When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being used in dashboards. No passwords of proxied data-sources are exposed. We encourage all direct data-sources to be conver…
- CVE-2026-28758MEDIUMCVSS 4.4EG 4.42026-05-13
When BIG-IP DNS is provisioned, a vulnerability exists in the gtm_add and bigip_add iControl REST commands that return the ssh-password parameter in cleartext in the iControl REST response and is also logged in the audit log. This may a…
- CVE-2026-31848CRITICALCVSS 9.8EG 9.82026-03-23
Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 uses the ecos_pw cookie for authentication, which contains Base64-encoded credential data combined with a static suffix. Because the encoding is reversible and lacks integrit…
- CVE-2026-3221MEDIUMCVSS 4.9EG 4.92026-02-25
Sensitive user account information is not encrypted in the database in Devolutions Server 2025.3.14 and earlier, which allows an attacker with access to the database to obtain sensitive user information via direct database access.
- CVE-2026-3277MEDIUMCVSS 6.5EG 6.52026-02-27
The OpenID Connect (OIDC) authentication configuration in PowerShell Universal before 2026.1.3 stores the OIDC client secret in cleartext in the .universal/authentication.ps1 script, which allows an attacker with read access to that file…
- CVE-2026-32842MEDIUMCVSS 6.5EG 6.52026-03-17
Edimax GS-5008PL firmware version 1.00.54 and prior contain an insecure credential storage vulnerability that allows attackers to obtain administrator credentials by accessing configuration backup files. Attackers can download the config.b…
- CVE-2026-33003MEDIUMCVSS 4.3EG 4.32026-03-18
Jenkins LoadNinja Plugin 2.1 and earlier stores LoadNinja API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file …
Map vulnerabilities like CWE-312 to your infrastructure
EchelonGraph correlates every CVE — across CWE-312 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →