CWE-313
27 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-313page 1 of 1
- CVE-2016-6538HIGHCVSS 8.8EG 8.82018-07-06
The TrackR Bravo mobile app stores the account password used to authenticate to the cloud API in cleartext in the cache.db file. Updated apps, version 5.1.6 for iOS and 2.2.5 for Android, have been released by the vendor to address the vul…
- CVE-2016-6546HIGHCVSS 7.8EG 7.82018-07-13
The iTrack Easy mobile application stores the account password used to authenticate to the cloud API in base64-encoding in the cache.db file. The base64 encoding format is considered equivalent to cleartext.
- CVE-2016-6547HIGHCVSS 7.8EG 7.82018-07-13
The Zizai Tech Nut mobile app stores the account password used to authenticate to the cloud API in cleartext in the cache.db file.
- CVE-2018-10622MEDIUMCVSS 6.8EG 7.12018-08-10
Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials to modify encrypted drive data.
- CVE-2019-19291MEDIUMCVSS 5.3EG 5.32020-03-10
A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0), SiNVR/SiVMS Video Server (All versions < V5.0.0). The FTP services of the SiVMS/SiNVR Video Server and the Control Center Server (CCS) maintain log…
- CVE-2023-0114LOWCVSS 3.3EG 5.52023-01-07
A vulnerability was found in Netis Netcore Router. It has been rated as problematic. Affected by this issue is some unknown functionality of the file param.file.tgz of the component Backup Handler. The manipulation leads to cleartext stora…
- CVE-2023-2863LOWCVSS 2.3EG 2.32023-05-24
A vulnerability has been found in Simple Design Daily Journal 1.012.GP.B on Android and classified as problematic. Affected by this vulnerability is an unknown functionality of the component SQLite Database. The manipulation leads to clear…
- CVE-2023-35699MEDIUMCVSS 5.3EG 5.32023-07-10
Cleartext Storage on Disk in the SICK ICR890-4 could allow an unauthenticated attacker with local access to the device to disclose sensitive information by accessing a SD card.
- CVE-2023-4066MEDIUMCVSS 5.5EG 5.52023-09-27
A flaw was found in Red Hat's AMQ Broker, which stores certain passwords in a secret security-properties-prop-module, defined in ActivemqArtemisSecurity CR; however, they are shown in plaintext in the StatefulSet details yaml of AMQ Broker.
- CVE-2024-20448MEDIUMCVSS 6.3EG 6.32024-10-02
A vulnerability in the Cisco Nexus Dashboard Fabric Controller (NDFC) software, formerly Cisco Data Center Network Manager (DCNM), could allow an attacker with access to a backup file to view sensitive information. This vulnerability is…
- CVE-2024-30406MEDIUMCVSS 5.5EG 5.52024-04-12
A Cleartext Storage in a File on Disk vulnerability in Juniper Networks Junos OS Evolved ACX Series devices using the Paragon Active Assurance Test Agent software installed on network devices allows a local, authenticated attacker with hi…
- CVE-2024-38280MEDIUMCVSS 4.6EG 4.62024-06-13
An unauthorized user is able to gain access to sensitive data, including credentials, by physically retrieving the hard disk of the product as the data is stored in clear text.
- CVE-2024-49762MEDIUMCVSS 4.6EG 4.62024-10-24
Pterodactyl is a free, open-source game server management panel. When a user disables two-factor authentication via the Panel, a `DELETE` request with their current password in a query parameter will be sent. While query parameters are en…
- CVE-2024-5916MEDIUMCVSS 4.4EG 4.42024-08-14
An information exposure vulnerability in Palo Alto Networks PAN-OS software enables a local system administrator to unintentionally disclose secrets, passwords, and tokens of external systems. A read-only administrator who has access to th…
- CVE-2024-6785MEDIUMCVSS 5.5EG 5.52024-09-21
The configuration file stores credentials in cleartext. An attacker with local access rights can read or modify the configuration file, potentially resulting in the service being abused due to sensitive information exposure.
- CVE-2024-9040LOWCVSS 2.3EG 2.32024-09-20
A vulnerability, which was classified as problematic, was found in code-projects Blood Bank Management System 1.0. This affects an unknown part of the component Password Handler. The manipulation leads to cleartext storage in a file or on …
- CVE-2025-14836LOWCVSS 2.7EG 2.72025-12-17
A flaw has been found in ZZCMS 2025. Affected by this vulnerability is an unknown functionality of the file /reg/user_save.php of the component User Data Storage Module. This manipulation causes cleartext storage in a file or on disk. Remo…
- CVE-2025-2120LOWCVSS 2.1EG 2.12025-03-09
A vulnerability was found in Thinkware Car Dashcam F800 Pro up to 20250226. It has been rated as problematic. This issue affects some unknown processing of the file /tmp/hostapd.conf of the component Configuration File Handler. The manipul…
- CVE-2025-36154MEDIUMCVSS 6.2EG 6.22025-12-24
IBM Concert 1.0.0 through 2.1.0 stores sensitive information in cleartext during recursive docker builds which could be obtained by a local user.
- CVE-2025-4397MEDIUMCVSS 6.8EG 6.82026-05-07
Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials to modify encrypted drive data.
- CVE-2025-5098CRITICALCVSS 9.1EG 9.12025-05-23
PrinterShare Android application allows the capture of Gmail authentication tokens that can be reused to access a user's Gmail account without proper authorization.
- CVE-2025-5154LOWCVSS 2.3EG 2.32025-05-25
A vulnerability, which was classified as problematic, was found in PhonePe App 25.03.21.0 on Android. Affected is an unknown function of the file /data/data/com.phonepe.app/databases/ of the component SQLite Database. The manipulation lead…
- CVE-2025-64305MEDIUMCVSS 6.5EG 6.52026-01-07
MicroServer copies parts of the system firmware to an unencrypted external SD card on boot, which contains user and vendor secrets. An attacker can utilize these plaintext secrets to modify the vendor firmware, or gain admin access to the …
- CVE-2025-6748LOWCVSS 2.1EG 2.12025-06-27
A vulnerability classified as problematic has been found in Bharti Airtel Thanks App 4.105.4 on Android. Affected is an unknown function of the file /Android/data/com.myairtelapp/files/. The manipulation leads to cleartext storage in a fil…
- CVE-2026-5531MEDIUMCVSS 5.3EG 5.32026-04-05
A vulnerability has been found in SourceCodester Student Result Management System 1.0. Impacted is an unknown function of the file /login_credentials.txt of the component HTTP GET Request Handler. The manipulation leads to cleartext storag…
- CVE-2026-6598MEDIUMCVSS 4.3EG 4.32026-04-20
A security vulnerability has been detected in langflow-ai langflow up to 1.8.3. The affected element is the function create_project/encrypt_auth_settings of the file src/backend/base/Langflow/api/v1/projects.py of the component Project Cre…
- CVE-2026-6796MEDIUMCVSS 4.3EG 4.32026-04-21
A vulnerability was determined in Sanluan PublicCMS up to 6.202506.d. Affected is the function log_login of the file core/src/main/java/com/publiccms/controller/admin/LoginAdminController.java of the component Failed Login Handler. This ma…
Map vulnerabilities like CWE-313 to your infrastructure
EchelonGraph correlates every CVE — across CWE-313 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →