CWE-256— Plaintext Storage of a Password
The product stores a password in plaintext within resources such as memory or files.— MITRE CWE catalog
264 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-256page 1 of 6
- CVE-2020-6961CRITICALCVSS 10.0EG 10.02020-01-24
In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Telemetry Server Version 4.3, CARESCAPE Central Station (CSCS) Versions 1.X, a …
- CVE-2024-55026CRITICALCVSS 9.8EG 9.82026-03-03
An issue in the reset_pj.cgi endpoint of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to execute arbitrary commands via supplying a crafted GET request.
- CVE-2026-21660CRITICALCVSS 9.8EG 9.82026-02-27
A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to unauthorized access, exposure of sensitive information, and…
- CVE-2025-6561CRITICALCVSS 9.8EG 9.82025-06-26
Certain hybrid DVR models ((HBF-09KD and HBF-16NK)) from Hunt Electronic have an Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to directly access a system configuration file and obtain plaintext…
- CVE-2025-6560CRITICALCVSS 9.8EG 9.82025-06-24
Multiple wireless router models from Sapido have an Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to directly access a system configuration file and obtain plaintext administrator credentials. …
- CVE-2025-5893CRITICALCVSS 9.8EG 9.82025-06-09
Smart Parking Management System from Honding Technology has an Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to access a specific page and obtain plaintext administrator credentials.
- CVE-2025-27662CRITICALCVSS 9.8EG 9.82025-03-05
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Password in URL OVE-20230524-0005.
- CVE-2025-27656CRITICALCVSS 9.8EG 9.82025-03-05
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Password Stored in Process List V-2023-011.
- CVE-2024-5960CRITICALCVSS 9.8EG 9.82024-09-18
Plaintext Storage of a Password vulnerability in Eliz Software Panel allows : Use of Known Domain Credentials. This issue affects Panel: before v2.3.24.
- CVE-2024-33375CRITICALCVSS 9.8EG 9.82024-06-14
LB-LINK BL-W1210M v2.0 was discovered to store user credentials in plaintext within the router's firmware.
- CVE-2024-36081CRITICALCVSS 9.8EG 9.82024-05-19
Westermo EDW-100 devices through 2024-05-03 allow an unauthenticated user to download a configuration file containing a cleartext password. NOTE: this is a serial-to-Ethernet converter that should not be placed at the edge of the network.
- CVE-2024-23486CRITICALCVSS 9.8EG 9.82024-04-15
Plaintext storage of a password issue exists in BUFFALO wireless LAN routers, which may allow a network-adjacent unauthenticated attacker with access to the product's login page may obtain configured credentials.
- CVE-2023-42493CRITICALCVSS 9.8EG 9.82023-10-25
EisBaer Scada - CWE-256: Plaintext Storage of a Password
- CVE-2017-16714CRITICALCVSS 9.8EG 9.82018-09-06
In Ice Qube Thermal Management Center versions prior to version 4.13, passwords are stored in plaintext in a file that is accessible without authentication.
- CVE-2018-8851CRITICALCVSS 9.8EG 9.82018-07-24
Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The devices store passwords in plaintext, which may allow an attacker with access to the configur…
- CVE-2018-7510CRITICALCVSS 9.8EG 9.82018-06-06
In the web application in BeaconMedaes TotalAlert Scroll Medical Air Systems running software versions prior to 4107600010.23, passwords are presented in plaintext in a file that is accessible without authentication.
- CVE-2017-7913CRITICALCVSS 9.8EG 9.82017-05-29
A Plaintext Storage of a Password issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3110-HSDPA Version 1.2 Build 09123015 and previous versions, OnCell G3150-HSDPA Version 1.4 Build 11…
- CVE-2017-9856CRITICALCVSS 3.4EG 9.82017-08-05
An issue was discovered in SMA Solar Technology products. Sniffed passwords from SMAdata2+ communication can be decrypted very easily. The passwords are "encrypted" using a very simple encryption algorithm. This enables an attacker to find…
- CVE-2025-15113CRITICALCVSS 9.3EG 9.32025-12-30
Ksenia Security lares (legacy model) Home Automation version 1.6 contains an unprotected endpoint vulnerability that allows authenticated attackers to upload MPFS File System binary images. Attackers can exploit this vulnerability to overw…
- CVE-2026-46488CRITICALCVSS 9.1EG 9.12026-06-22
motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Prior to 0.44.0, motionEye accepts the client-controlled meye_username and meye_password_hash coo…
- CVE-2024-6118CRITICALCVSS 9.1EG 9.12024-08-05
A Plaintext Storage of a Password vulnerability in ebooknote function in Hamastar MeetingHub Paperless Meetings 2021 allows remote attackers to obtain the other users’ credentials and gain access to the product via an XML file.
- CVE-2022-36308CRITICALCVSS 9.1EG 9.12022-08-16
Airspan AirVelocity 1500 web management UI displays SNMP credentials in plaintext on software versions older than 15.18.00.2511, and stores SNMPv3 credentials unhashed on the filesystem, enabling anyone with web access to use these credent…
- CVE-2022-43958CRITICALCVSS 7.6EG 9.12022-11-08
A vulnerability has been identified in QMS Automotive (All versions < V12.39), QMS Automotive (All versions < V12.39). User credentials are stored in plaintext in the database without any hashing mechanism. This could allow an attacker to …
- CVE-2023-35067CRITICALCVSS 7.5EG 9.12023-07-25
Plaintext Storage of a Password vulnerability in Infodrom Software E-Invoice Approval System allows Read Sensitive Strings Within an Executable. This issue affects E-Invoice Approval System: before v.20230701.
- CVE-2023-41610HIGHCVSS 8.8EG 8.82024-09-18
Victure PC420 1.1.39 was discovered to contain a hardcoded root password which is stored in plaintext.
- CVE-2024-3622HIGHCVSS 8.8EG 8.82024-04-25
A flaw was found when using mirror-registry to install Quay. It uses a default secret, which is stored in plain-text format in one of the configuration template files. This issue may lead to all instances of Quay deployed using mirror-regi…
- CVE-2024-26165HIGHCVSS 8.8EG 8.82024-03-12
Visual Studio Code Elevation of Privilege Vulnerability
- CVE-2023-4918HIGHCVSS 8.8EG 8.82023-09-12
A flaw was found in the Keycloak package, more specifically org.keycloak.userprofile. When a user registers itself through registration flow, the "password" and "password-confirm" field from the form will occur as regular user attributes. …
- CVE-2020-5315HIGHCVSS 8.8EG 8.82021-07-19
Dell EMC Repository Manager (DRM) version 3.2 contains a plain-text password storage vulnerability. Proxy server user password is stored in a plain text in a local database. A local authenticated malicious user with access to the local fil…
- CVE-2020-5374HIGHCVSS 8.8EG 8.82020-07-14
Dell EMC OpenManage Integration for Microsoft System Center (OMIMSSC) for SCCM and SCVMM versions prior to 7.2.1 contain a hard-coded cryptographic key vulnerability. A remote unauthenticated attacker may exploit this vulnerability to gain…
- CVE-2022-33928HIGHCVSS 6.4EG 8.82022-08-10
Dell Wyse Management Suite 3.6.1 and below contains an Plain-text Password Storage Vulnerability in UI. An attacker with low privileges could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. Th…
- CVE-2026-104892HIGHCVSS 8.7EG 8.72026-10-05
Plane is an open-source project management tool. Prior to 1.4.0, aPITokenLogMiddleware logs API keys in plaintext. This allows someone with low privileges to steal user API keys and further escalate their privileges. This issue is fixed in…
- CVE-2025-7357HIGHCVSS 8.7EG 8.72025-07-16
LITEON IC48A firmware versions prior to 01.00.19r and LITEON IC80A firmware versions prior to 01.01.12e store FTP-server-access-credentials in cleartext in their system logs.
- CVE-2025-3758HIGHCVSS 8.7EG 8.72025-05-08
WF2220 exposes endpoint /cgi-bin-igd/netcore_get.cgi that returns configuration of the device to unauthorized users. Returned configuration includes cleartext password. The vendor was contacted early about this disclosure but did not res…
- CVE-2026-55765HIGHCVSS 8.5EG 8.52026-08-20
CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG embedded cleartext role passwords in `ALTER ROLE` and `CREATE ROLE` statements generated by SetUs…
- CVE-2024-20489HIGHCVSS 8.4EG 8.42024-09-11
A vulnerability in the storage method of the PON Controller configuration file could allow an authenticated, local attacker with low privileges to obtain the MongoDB credentials. This vulnerability is due to improper storage of the unen…
- CVE-2022-0555HIGHCVSS 8.4EG 8.42024-06-03
Subiquity Shows Guided Storage Passphrase in Plaintext with Read-all Permissions
- CVE-2021-38489HIGHCVSS 8.2EG 8.22026-09-03
HDD password plaintext is stored in a UEFI variable.
- CVE-2025-52164HIGHCVSS 8.2EG 8.22025-07-18
Software GmbH Agorum core open v11.9.2 & v11.10.1 was discovered to store credentials in plaintext.
- CVE-2022-22554HIGHCVSS 8.2EG 8.22022-01-24
Dell EMC System Update, version 1.9.2 and prior, contain an Unprotected Storage of Credentials vulnerability. A local attacker with user privleges could potentially exploit this vulnerability leading to the disclosure of user passwords.
- CVE-2021-47961HIGHCVSS 8.1EG 8.12026-04-10
A plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access or influence the user's PIN code due to insecure storage. This may lead to unauthorized VPN configuration and po…
- CVE-2024-36460HIGHCVSS 8.1EG 8.12024-08-12
The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain text.
- CVE-2024-40116HIGHCVSS 8.1EG 8.12024-07-26
An issue in Solar-Log 1000 before v2.8.2 and build 52-23.04.2013 was discovered to store plaintext passwords in the export.html, email.html, and sms.html files -- fixed with 3.0.0-60 11.10.2013 for SL 200, 500, 1000 / not existing for SL 2…
- CVE-2024-3623HIGHCVSS 6.5EG 8.12024-04-25
A flaw was found when using mirror-registry to install Quay. It uses a default database secret key, which is stored in plain-text format in one of the configuration template files. This issue may lead to all instances of Quay deployed usin…
- CVE-2024-44815HIGHCVSS 4.6EG 8.02024-09-10
Vulnerability in Hathway Skyworth Router CM5100 v.4.1.1.24 allows a physically proximate attacker to obtain user credentials via SPI flash Firmware W25Q64JV.
- CVE-2024-43378HIGHCVSS 7.8EG 7.82024-08-16
calamares-nixos-extensions provides Calamares branding and modules for NixOS, a distribution of GNU/Linux. Users who installed NixOS through the graphical installer who used manual disk partitioning to create a setup where the system was b…
- CVE-2024-22432HIGHCVSS 7.8EG 7.82024-01-25
Networker 19.9 and all prior versions contains a Plain-text Password stored in temporary config file during backup duration in NMDA MySQL Database backups. User has low privilege access to Networker Client system could potentially exploit…
- CVE-2020-25184HIGHCVSS 7.8EG 7.82022-03-18
Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x stores the password in plaintext in a file that is in the same directory as the executable file. ISaGRAF Runtime reads the file and saves the data in a variable without any additiona…
- CVE-2019-0032HIGHCVSS 7.8EG 7.82019-04-10
A password management issue exists where the Organization authentication username and password were stored in plaintext in log files. A locally authenticated attacker who is able to access these stored plaintext credentials can use them to…
- CVE-2022-22557HIGHCVSS 7.5EG 7.82022-06-02
PowerStore contains Plain-Text Password Storage Vulnerability in PowerStore X & T environments running versions 2.0.0.x and 2.0.1.x A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure of…
Map vulnerabilities like CWE-256 to your infrastructure
EchelonGraph correlates every CVE — across CWE-256 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →