CWE-312— Cleartext Storage of Sensitive Information
796 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-312page 9 of 16
- CVE-2022-37401HIGHCVSS 8.8EG 8.82022-08-15
Apache OpenOffice supports the storage of passwords for web connections in the user's configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in OpenOffice existed where master key w…
- CVE-2022-37785HIGHCVSS 7.5EG 7.52023-01-01
An issue was discovered in WeCube Platform 3.2.2. Cleartext passwords are displayed in the configuration for terminal plugins.
- CVE-2022-37857HIGHCVSS 7.5EG 7.52022-09-08
bilde2910 Hauk v1.6.1 requires a hardcoded password which by default is blank. This hardcoded password is hashed but stored within the config.php file server-side as well as in clear-text on the android client device by default.
- CVE-2022-38112HIGHCVSS 7.5EG 7.52023-01-20
In DPA 2022.4 and older releases, generated heap memory dumps contain sensitive information in cleartext.
- CVE-2022-38710MEDIUMCVSS 5.3EG 5.32022-11-03
IBM Robotic Process Automation 21.0.1 and 21.0.2 could disclose sensitive version to an unauthorized control sphere information that could aid in further attacks against the system. IBM X-Force ID: 234292.
- CVE-2022-39351MEDIUMCVSS 4.4EG 4.42022-10-25
Dependency-Track is a Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Prior to version 4.6.0, performing an API request using a valid API key with insufficient permissions cau…
- CVE-2022-39364MEDIUMCVSS 4.0EG 4.02022-10-27
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. In Nextcloud Server prior to versions 23.0.9 and 24.0.5 and Nextcloud Enterprise Server prior to versions 22.2.10.5, 23.0.9, and 24.0.5 an att…
- CVE-2022-41248MEDIUMCVSS 5.3EG 3.32022-09-21
Jenkins BigPanda Notifier Plugin 1.4.0 and earlier does not mask the BigPanda API key on the global configuration form, increasing the potential for attackers to observe and capture it.
- CVE-2022-41734MEDIUMCVSS 5.3EG 7.52023-02-17
IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against th…
- CVE-2022-41740MEDIUMCVSS 4.6EG 4.62023-01-05
IBM Robotic Process Automation 20.12 through 21.0.6 could allow an attacker with physical access to the system to obtain highly sensitive information from system memory. IBM X-Force ID: 238053.
- CVE-2022-41933MEDIUMCVSS 6.2EG 6.22022-11-23
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When the `reset a forgotten password` feature of XWiki was used, the password was then stored in plain text in database. This only con…
- CVE-2022-42284MEDIUMCVSS 6.2EG 5.52023-01-13
NVIDIA BMC stores user passwords in an obfuscated form in a database accessible by the host. This may lead to a credentials exposure.
- CVE-2022-42931LOWCVSS 3.3EG 3.32022-12-22
Logins saved by Firefox should be managed by the Password Manager component which uses encryption to save files on-disk. Instead, the username (not password) was saved by the Form Manager to an unencrypted file on disk. This vulnerability …
- CVE-2022-42955HIGHCVSS 7.5EG 7.52022-11-07
The PassWork extension 5.0.9 for Chrome and other browsers allows an attacker to obtain cleartext cached credentials.
- CVE-2022-42956HIGHCVSS 7.5EG 7.52022-11-07
The PassWork extension 5.0.9 for Chrome and other browsers allows an attacker to obtain the cleartext master password.
- CVE-2022-4312MEDIUMCVSS 5.5EG 5.52022-12-12
A cleartext storage of sensitive information vulnerability exists in PcVue versions 8.10 through 15.2.3. This could allow an unauthorized user with access the email and short messaging service (SMS) accounts configuration files to discove…
- CVE-2022-43757CRITICALCVSS 9.9EG 9.92023-02-07
A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows users on managed clusters to gain access to credentials. The impact depends on the credentials exposed This issue affects: SUSE Rancher Rancher versions prio…
- CVE-2022-43958HIGHCVSS 7.6EG 9.12022-11-08
A vulnerability has been identified in QMS Automotive (All versions < V12.39), QMS Automotive (All versions < V12.39). User credentials are stored in plaintext in the database without any hashing mechanism. This could allow an attacker to …
- CVE-2022-45098MEDIUMCVSS 6.1EG 5.52023-02-01
Dell PowerScale OneFS, 9.0.0.x-9.4.0.x, contain a cleartext storage of sensitive information vulnerability in S3 component. An authenticated local attacker could potentially exploit this vulnerability, leading to information disclosure. …
- CVE-2022-45154MEDIUMCVSS 4.4EG 5.52023-02-15
A Cleartext Storage of Sensitive Information vulnerability in suppportutils of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15, SUSE Linux Enterprise Server 15 SP3 allows attackers that get access to the support logs to ga…
- CVE-2022-45439MEDIUMCVSS 6.5EG 6.52023-01-17
A pair of spare WiFi credentials is stored in the configuration file of the Zyxel AX7501-B0 firmware prior to V5.17(ABPC.3)C0 in cleartext. An unauthenticated attacker could use the credentials to access the WLAN service if the configurati…
- CVE-2022-45787MEDIUMCVSS 5.5EG 5.52023-01-06
Unproper laxist permissions on the temporary files used by MIME4J TempFileStorageProvider may lead to information disclosure to other local users. This issue affects Apache James MIME4J version 0.8.8 and prior versions. We recommend users…
- CVE-2022-45868HIGHCVSS 8.4EG 8.42022-11-23
The web-based admin console in H2 Database Engine before 2.2.220 can be started via the CLI with the argument -webAdminPassword, which allows the user to specify the password in cleartext for the web admin console. Consequently, a local us…
- CVE-2022-45897MEDIUMCVSS 6.5EG 6.52023-01-31
On Xerox WorkCentre 3550 25.003.03.000 devices, an authenticated attacker can view the SMB server settings and can obtain the stored cleartext credentials associated with those settings.
- CVE-2022-46141MEDIUMCVSS 4.2EG 4.22023-12-12
A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) (All versions < V19). An information disclosure vulnerability could allow a local attacker to gain access to the access level password of the SIMATIC S7-1200 and S7-1500 CP…
- CVE-2022-46155HIGHCVSS 7.6EG 7.62022-11-29
Airtable.js is the JavaScript client for Airtable. Prior to version 0.11.6, Airtable.js had a misconfigured build script in its source package. When the build script is run, it would bundle environment variables into the build target of a …
- CVE-2022-47512MEDIUMCVSS 5.5EG 5.52022-12-19
Sensitive information was stored in plain text in a file that is accessible by a user with a local account in Hybrid Cloud Observability (HCO)/ SolarWinds Platform 2022.4. No other versions are affected
- CVE-2022-48071HIGHCVSS 7.5EG 7.52023-01-27
Phicomm K2 v22.6.534.263 was discovered to store the root and admin passwords in plaintext.
- CVE-2022-48073HIGHCVSS 7.5EG 7.52023-01-27
Phicomm K2G v22.6.3.20 was discovered to store the root and admin passwords in plaintext.
- CVE-2022-48310MEDIUMCVSS 5.5EG 5.52023-03-01
An information disclosure vulnerability allows sensitive key material to be included in technical support archives in Sophos Connect versions older than 2.2.90.
- CVE-2023-0005MEDIUMCVSS 4.1EG 4.92023-04-12
A vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to expose the plaintext values of secrets stored in the device configuration and encrypted API keys.
- CVE-2023-0614MEDIUMCVSS 6.5EG 6.52023-04-03
The fix in 4.6.16, 4.7.9, 4.8.4 and 4.9.7 for CVE-2018-10919 Confidential attribute disclosure vi LDAP filters was insufficient and an attacker may be able to obtain confidential BitLocker recovery keys from a Samba AD DC.
- CVE-2023-0690MEDIUMCVSS 5.0EG 5.02023-02-08
HashiCorp Boundary from 0.10.0 through 0.11.2 contain an issue where when using a PKI-based worker with a Key Management Service (KMS) defined in the configuration file, new credentials created after an automatic rotation may not have bee…
- CVE-2023-1683MEDIUMCVSS 4.3EG 7.52023-03-29
A vulnerability was found in Xunrui CMS 4.61 and classified as problematic. Affected by this issue is some unknown functionality of the file /dayrui/Fcms/View/system_log.html. The manipulation leads to information disclosure. The attack ma…
- CVE-2023-1897CRITICALCVSS 9.4EG 9.42023-06-12
Atlas Copco Power Focus 6000 web server does not sanitize the login information stored by the authenticated user’s browser, which could allow an attacker with access to the user’s computer to gain credential information of the controll…
- CVE-2023-20059MEDIUMCVSS 4.3EG 6.52023-03-23
A vulnerability in the implementation of the Cisco Network Plug-and-Play (PnP) agent of Cisco DNA Center could allow an authenticated, remote attacker to view sensitive information in clear text. The attacker must have valid low-privileged…
- CVE-2023-20207MEDIUMCVSS 4.9EG 4.92023-07-12
A vulnerability in the logging component of Cisco Duo Authentication Proxy could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability exists because certain unencr…
- CVE-2023-20914MEDIUMCVSS 5.5EG 5.52023-05-15
In onSetRuntimePermissionGrantStateByDeviceAdmin of AdminRestrictedPermissionsUtils.java, there is a possible way for the work profile to read SMS messages due to a permissions bypass. This could lead to local information disclosure with U…
- CVE-2023-22332MEDIUMCVSS 6.5EG 6.52023-01-30
Information disclosure vulnerability exists in Pgpool-II 4.4.0 to 4.4.1 (4.4 series), 4.3.0 to 4.3.4 (4.3 series), 4.2.0 to 4.2.11 (4.2 series), 4.1.0 to 4.1.14 (4.1 series), 4.0.0 to 4.0.21 (4.0 series), All versions of 3.7 series, All ve…
- CVE-2023-22584HIGHCVSS 7.5EG 7.52023-06-11
The Danfoss AK-EM100 stores login credentials in cleartext.
- CVE-2023-22878MEDIUMCVSS 6.2EG 6.22023-05-19
IBM InfoSphere Information Server 11.7 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 244373.
- CVE-2023-22894MEDIUMCVSS 4.9EG 4.92023-04-19
Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting the query filter. The attacker can filter users by columns that contain sensitive information and infer a value from AP…
- CVE-2023-22949MEDIUMCVSS 4.9EG 4.92023-04-14
An issue was discovered in TigerGraph Enterprise Free Edition 3.x. There is logging of user credentials. All authenticated GSQL access requests are logged by TigerGraph in multiple places. Each request includes both the username and passwo…
- CVE-2023-2335MEDIUMCVSS 6.5EG 6.52023-04-27
Plaintext Password in Registry vulnerability in 42gears surelock windows surelockwinsetupv2.40.0.Exe on Windows (Registery modules) allows Retrieve Admin user credentials This issue affects surelock windows: from 2.3.12 through 2.40.…
- CVE-2023-2358MEDIUMCVSS 4.3EG 4.32023-09-27
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.5.0.0 and 9.3.0.4, including 8.3.x.x, saves passwords of the Hadoop Copy Files step in plaintext.
- CVE-2023-23776MEDIUMCVSS 4.6EG 3.12023-03-07
An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in FortiAnalyzer versions 7.2.0 through 7.2.1, 7.0.0 through 7.0.4 and 6.4.0 through 6.4.10 may allow a remote authenticated attacker to read the client…
- CVE-2023-23944LOWCVSS 2.0EG 2.02023-02-06
Nextcloud mail is an email app for the nextcloud home server platform. In versions prior to 2.2.2 user's passwords were stored in cleartext in the database during the duration of OAuth2 setup procedure. Any attacker or malicious user with …
- CVE-2023-24055MEDIUMCVSS 5.5EG 5.52023-01-22
KeePass through 2.53 (in a default installation) allows an attacker, who has write access to the XML configuration file, to obtain the cleartext passwords by adding an export trigger. NOTE: the vendor's position is that the password databa…
- CVE-2023-24439MEDIUMCVSS 5.5EG 5.52023-01-26
Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier stores the private keys unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file …
- CVE-2023-24442MEDIUMCVSS 5.5EG 5.52023-01-26
Jenkins GitHub Pull Request Coverage Status Plugin 2.2.0 and earlier stores the GitHub Personal Access Token, Sonar access token and Sonar password unencrypted in its global configuration file on the Jenkins controller where they can be vi…
Map vulnerabilities like CWE-312 to your infrastructure
EchelonGraph correlates every CVE — across CWE-312 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →