CWE-312— Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.— MITRE CWE catalog
903 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-312page 11 of 19
- CVE-2020-29501MEDIUMCVSS 6.4EG 6.42021-01-05
Dell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerability in PowerStore X & T environments. A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclos…
- CVE-2020-29489MEDIUMCVSS 6.4EG 6.42021-01-05
Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contains a plain-text password storage vulnerability. A user credentials (including the Unisphere admin privilege user) password is stored in a plain text in a system f…
- CVE-2025-23027MEDIUMCVSS 6.3EG 6.32025-01-13
next-forge is a Next.js project boilerplate for modern web application. The BASEHUB_TOKEN commited in apps/web/.env.example. Users should avoid use of this token and should remove any access it may have in their systems.
- CVE-2024-20448MEDIUMCVSS 6.3EG 6.32024-10-02
A vulnerability in the Cisco Nexus Dashboard Fabric Controller (NDFC) software, formerly Cisco Data Center Network Manager (DCNM), could allow an attacker with access to a backup file to view sensitive information. This vulnerability is…
- CVE-2024-31415MEDIUMCVSS 6.3EG 6.32024-09-13
The Eaton Foreseer software provides the feasibility for the user to configure external servers for multiple purposes such as network management, user management, etc. The software uses encryption to store these configurations securely on …
- CVE-2025-55334MEDIUMCVSS 6.2EG 6.22025-10-14
Cleartext storage of sensitive information in Windows Kernel allows an unauthorized attacker to bypass a security feature locally.
- CVE-2025-40753MEDIUMCVSS 6.2EG 6.22025-08-12
A vulnerability has been identified in POWER METER SICAM Q100 (7KG9501-0AA01-0AA1) (All versions >= V2.60 < V2.62), POWER METER SICAM Q100 (7KG9501-0AA01-2AA1) (All versions >= V2.60 < V2.62), POWER METER SICAM Q100 (7KG9501-0AA31-0AA1) (A…
- CVE-2025-40752MEDIUMCVSS 6.2EG 6.22025-08-12
A vulnerability has been identified in POWER METER SICAM Q100 (7KG9501-0AA01-0AA1) (All versions >= V2.60 < V2.62), POWER METER SICAM Q100 (7KG9501-0AA01-2AA1) (All versions >= V2.60 < V2.62), POWER METER SICAM Q100 (7KG9501-0AA31-0AA1) (A…
- CVE-2025-4737MEDIUMCVSS 6.2EG 6.22025-05-15
Insufficient encryption vulnerability in the mobile application (com.transsion.aivoiceassistant) may lead to the risk of sensitive information leakage.
- CVE-2024-39674MEDIUMCVSS 6.2EG 6.22024-07-25
Plaintext vulnerability in the Gallery search module. Impact: Successful exploitation of this vulnerability will affect availability.
- CVE-2023-22878MEDIUMCVSS 6.2EG 6.22023-05-19
IBM InfoSphere Information Server 11.7 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 244373.
- CVE-2023-24964MEDIUMCVSS 6.2EG 6.22023-02-17
IBM InfoSphere Information Server 11.7 could allow a local user to obtain sensitive information from a log files. IBM X-Force ID: 246463.
- CVE-2022-42284MEDIUMCVSS 6.2EG 6.22023-01-13
NVIDIA BMC stores user passwords in an obfuscated form in a database accessible by the host. This may lead to a credentials exposure.
- CVE-2022-41933MEDIUMCVSS 6.2EG 6.22022-11-23
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When the `reset a forgotten password` feature of XWiki was used, the password was then stored in plain text in database. This only con…
- CVE-2024-25024MEDIUMCVSS 5.5EG 6.22024-08-15
IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 281430.
- CVE-2024-25023MEDIUMCVSS 5.5EG 6.22024-07-10
IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.22.0 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 281429.
- CVE-2026-77250MEDIUMCVSS 6.1EG 6.12026-09-22
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, OAuthConfig writes a plaintext fallback file containing access and refresh tokens under the user's .mcp-atlassian directo…
- CVE-2024-24915MEDIUMCVSS 6.1EG 6.12025-06-29
Credentials are not cleared from memory after being used. A user with Administrator permissions can execute memory dump for SmartConsole process and fetch them.
- CVE-2022-45098MEDIUMCVSS 6.1EG 6.12023-02-01
Dell PowerScale OneFS, 9.0.0.x-9.4.0.x, contain a cleartext storage of sensitive information vulnerability in S3 component. An authenticated local attacker could potentially exploit this vulnerability, leading to information disclosure. …
- CVE-2022-22789MEDIUMCVSS 6.1EG 6.12022-01-25
Charactell - FormStorm Enterprise Account takeover – An attacker can modify (add, remove and update) passwords file for all the users. The xx_users.ini file in the FormStorm folder contains usernames in cleartext and an obfuscated passwo…
- CVE-2021-22929MEDIUMCVSS 6.1EG 6.12021-08-31
An information disclosure exists in Brave Browser Desktop prior to version 1.28.62, where logged warning messages that included timestamps of connections to V2 onion domains in tor.log.
- CVE-2026-7163MEDIUMCVSS 5.5EG 6.12026-04-30
A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multicluster Engine (MCE), allows an authenticated user with minimal namespace-scoped privileges to obtain administrative …
- CVE-2024-13843MEDIUMCVSS 6.0EG 6.02025-02-11
Cleartext storage of information in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a local authenticated attacker with admin privileges to read sensitive data.
- CVE-2024-8689MEDIUMCVSS 6.0EG 6.02024-09-11
A problem with the ActiveMQ integration for both Cortex XSOAR and Cortex XSIAM can result in the cleartext exposure of the configured ActiveMQ credentials in log bundles.
- CVE-2024-24595MEDIUMCVSS 6.0EG 6.02024-02-05
Allegro AI’s open-source version of ClearML stores passwords in plaintext within the MongoDB instance, resulting in a compromised server leaking all user emails and passwords.
- CVE-2023-37468MEDIUMCVSS 6.0EG 6.02023-07-13
Feedbacksystem is a personalized feedback system for students using artificial intelligence. Passwords of users using LDAP login are stored in clear text in the database. The LDAP users password is passed unencrypted in the LoginController…
- CVE-2021-43590MEDIUMCVSS 6.0EG 6.02022-03-04
Dell EMC Enterprise Storage Analytics for vRealize Operations, versions 4.0.1 to 6.2.1, contain a Plain-text password storage vulnerability. A local high privileged malicious user may potentially exploit this vulnerability, leading to the …
- CVE-2021-23211MEDIUMCVSS 6.0EG 6.02021-06-11
Cleartext Storage of Sensitive Information in Memory vulnerability in Gallagher Command Centre Server allows Cloud end-to-end encryption key to be discoverable in server memory dumps. This issue affects: Gallagher Command Centre 8.40 versi…
- CVE-2021-23182MEDIUMCVSS 6.0EG 6.02021-06-11
Cleartext Storage of Sensitive Information in Memory vulnerability in Gallagher Command Centre Server allows OSDP reader master keys to be discoverable in server memory dumps. This issue affects: Gallagher Command Centre 8.40 versions prio…
- CVE-2020-4095MEDIUMCVSS 6.0EG 6.02020-07-16
"BigFix Platform is storing clear text credentials within the system's memory. An attacker who is able to gain administrative privileges can use a program to create a memory dump and extract the credentials. These credentials can be used t…
- CVE-2026-67221MEDIUMCVSS 5.9EG 5.92026-09-23
RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, The AMQP 0-9-1 shovel calls amqp_uri:remove_credentials before storing its connection URI, but the AMQP 1.0 shovel stores the raw UR…
- CVE-2026-63406MEDIUMCVSS 5.9EG 5.92026-09-18
AnyCable is a realtime server for reliable two-way communication that supports any backend. Prior to 1.6.15, the telemetry subsystem in telemetry/config.go enables tracking with a hardcoded public authToken, while clusterFingerprint in tel…
- CVE-2026-77970MEDIUMCVSS 5.9EG 5.92026-08-30
Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover sensitive values nested inside embedded resources, unions, or lists. …
- CVE-2026-75847MEDIUMCVSS 5.9EG 5.92026-08-30
Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover the plaintext of sensitive? attributes. AshPaperTrail stores the valu…
- CVE-2025-2181MEDIUMCVSS 5.9EG 5.92025-08-13
A sensitive information disclosure vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can result in the cleartext exposure of Prisma Cloud access keys in Checkov's output.
- CVE-2025-8528MEDIUMCVSS 5.9EG 5.92025-08-04
A vulnerability classified as problematic has been found in Exrick xboot up to 3.3.4. Affected is an unknown function of the file /xboot/permission/getMenuList. The manipulation leads to cleartext storage of sensitive information in a cook…
- CVE-2025-0123MEDIUMCVSS 5.9EG 5.92025-04-11
A vulnerability in the Palo Alto Networks PAN-OS® software enables unlicensed administrators to view clear-text data captured using the packet capture feature https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/monitoring/take-pac…
- CVE-2024-29146MEDIUMCVSS 5.9EG 5.92024-11-26
User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved from the coredump file. As for the details of affected product names, model numbers, and versions, refer to the informa…
- CVE-2024-29954MEDIUMCVSS 5.9EG 5.92024-06-26
A vulnerability in a password management API in Brocade Fabric OS versions before v9.2.1, v9.2.0b, v9.1.1d, and v8.2.3e prints sensitive information in log files. This could allow an authenticated user to view the server passwords for prot…
- CVE-2024-28065MEDIUMCVSS 5.9EG 5.92024-04-05
In Unify CP IP Phone firmware 1.10.4.3, files are not encrypted and contain sensitive information such as the root password hash.
- CVE-2023-39903MEDIUMCVSS 5.9EG 5.92023-08-07
An issue was discovered in Fujitsu Software Infrastructure Manager (ISM) before 2.8.0.061. The ismsnap component (in this specific case at /var/log/fujitsu/ServerViewSuite/ism/FirmwareManagement/FirmwareManagement.log) allows insecure coll…
- CVE-2017-20040MEDIUMCVSS 5.9EG 5.92022-06-11
A vulnerability was found in SICUNET Access Controller 0.32-05z. It has been declared as problematic. This vulnerability affects unknown code of the component Password Storage. The manipulation leads to weak encryption. Attacking locally i…
- CVE-2022-25160MEDIUMCVSS 5.9EG 5.92022-04-01
Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU all versions, Mitsubishi Electric MELSEC iQ-F series FX5UJ CPU all versions, Mitsubishi Electric MELSEC iQ-R series R00/01/02CPU…
- CVE-2021-36158MEDIUMCVSS 5.9EG 5.92021-07-05
In the xrdp package (in branches through 3.14) for Alpine Linux, RDP sessions are vulnerable to man-in-the-middle attacks because pre-generated RSA certificates and private keys are used.
- CVE-2021-26833MEDIUMCVSS 5.9EG 5.92021-04-06
Cleartext Storage in a File or on Disk in TimelyBills <= 1.7.0 for iOS and versions <= 1.21.115 for Android allows attacker who can locally read user's files obtain JWT tokens for user's account due to insufficient cache clearing mechanism…
- CVE-2021-21339MEDIUMCVSS 5.9EG 5.92021-03-23
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 user session identifiers were stored in cleartext - without processing of additional cryptographic ha…
- CVE-2026-24319MEDIUMCVSS 5.8EG 5.82026-02-10
In SAP Business One, sensitive information is written to the application�s memory dump files without obfuscation. Gaining access to this information could potentially lead to unauthorized operations within the B1 environment, including m…
- CVE-2025-53103MEDIUMCVSS 5.8EG 5.82025-07-01
JUnit is a testing framework for Java and the JVM. From version 5.12.0 to 5.13.1, JUnit's support for writing Open Test Reporting XML files can leak Git credentials. The impact depends on the level of the access token exposed through the O…
- CVE-2026-44940MEDIUMCVSS 5.7EG 5.72026-09-17
The rancher-extension-stackstate extension in SUSE Observability exposes service tokens in plain configuration or insecure locations rather than managing them securely. An attacker with minimal access could obtain the token to gain unautho…
- CVE-2026-5224MEDIUMCVSS 5.7EG 5.72026-08-18
Cleartext storage of sensitive information vulnerability in Kriptok Crypto and Information Technologies Industry Trade Inc. Cryptosim allows Retrieve Embedded Sensitive Data. This issue affects Cryptosim: before 3.1.0.229.
Map vulnerabilities like CWE-312 to your infrastructure
EchelonGraph correlates every CVE — across CWE-312 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →