CWE-312— Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.— MITRE CWE catalog
903 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-312page 12 of 19
- CVE-2025-47147MEDIUMCVSS 5.7EG 5.72026-03-03
Cleartext Storage of Sensitive Information (CWE-312) in the Command Centre Mobile Client on Android and iOS could allow an attacker with access to a logged-in Operator's mobile device to extract the session token and exploit access for a l…
- CVE-2023-28912MEDIUMCVSS 5.7EG 5.72025-06-28
The MIB3 unit stores the synchronized phone contact book in clear-text, allowing an attacker with either code execution privilege on the system or physical access to the system to obtain vehicle owner's contact data. The vulnerability was …
- CVE-2025-32752MEDIUMCVSS 5.7EG 5.72025-05-29
Dell ThinOS 2502 and prior contain a Cleartext Storage of Sensitive Information vulnerability. A high privileged attacker with physical access could potentially exploit this vulnerability, leading to Information Disclosure.
- CVE-2024-55582MEDIUMCVSS 5.7EG 5.72024-12-09
Oxide before 6 has unencrypted Control Plane datastores.
- CVE-2024-21993MEDIUMCVSS 5.7EG 5.72024-07-09
SnapCenter versions prior to 5.0p1 are susceptible to a vulnerability which could allow an authenticated attacker to discover plaintext credentials.
- CVE-2023-27370MEDIUMCVSS 5.7EG 5.72024-05-03
NETGEAR RAX30 Device Configuration Cleartext Storage Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR RAX30 routers. Although …
- CVE-2023-31423MEDIUMCVSS 5.7EG 5.72023-08-31
Possible information exposure through log file vulnerability where sensitive fields are recorded in the configuration log without masking on Brocade SANnav before v2.3.0 and 2.2.2a. Notes: To access the logs, the local attacker must ha…
- CVE-2021-22194MEDIUMCVSS 5.7EG 5.72021-03-26
In all versions of GitLab, marshalled session keys were being stored in Redis.
- CVE-2026-24311MEDIUMCVSS 5.6EG 5.62026-03-10
The SAP Customer Checkout application exhibits certain design characteristics that involve locally storing operational data using reversible protection mechanisms. Access to this data, combined with user?initiated interaction, may allow mo…
- CVE-2025-2182MEDIUMCVSS 5.6EG 5.62025-08-13
A problem with the implementation of the MACsec protocol in Palo Alto Networks PAN-OS® results in the cleartext exposure of the connectivity association key (CAK). This issue is only applicable to PA-7500 Series devices which are in an NG…
- CVE-2026-100581MEDIUMCVSS 5.5EG 5.52026-09-26
OpenClaw for iOS before 2026.8.11 stores Gateway credentials as cleartext JSON in App Group UserDefaults instead of the device Keychain. Attackers with access to unencrypted device backups or extracted App Group containers can recover vali…
- CVE-2026-80058MEDIUMCVSS 5.5EG 5.52026-09-07
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Cleartext Storage of Sensitive Information vulnerability. A low privileged attacker with local access could potential…
- CVE-2026-82640MEDIUMCVSS 5.5EG 5.52026-08-30
browser-use web-ui versions 2.0.0 through 3.0.0 write configured LLM API keys to disk in cleartext without encryption or access restrictions. Attackers with read access to the temporary settings directory can recover provider API keys from…
- CVE-2026-73834MEDIUMCVSS 5.5EG 5.52026-08-18
A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. Certain ACM wrapper Custom Resources that embed Secret data are collected without redaction. When an administrator runs must-gather, crede…
- CVE-2026-61928MEDIUMCVSS 5.5EG 5.52026-08-11
Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.
- CVE-2026-34490MEDIUMCVSS 5.5EG 5.52026-07-31
Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retrieve Sensitive Data. This issue affects XAAP Application: b…
- CVE-2025-33081MEDIUMCVSS 5.5EG 5.52026-02-03
IBM Concert 1.0.0 through 2.1.0 stores potentially sensitive information in log files that could be read by a local user.
- CVE-2026-22276MEDIUMCVSS 5.5EG 5.52026-01-23
Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Storage of Sensitive Information vulnerability. A low privileged attacker with local access could potentially exploit this vul…
- CVE-2025-3784MEDIUMCVSS 5.5EG 5.52025-11-27
Cleartext Storage of Sensitive Information Vulnerability in GX Works2 all versions allows an attacker to disclose credential information stored in plaintext from project files. As a result, the attacker may be able to open project files pr…
- CVE-2025-21060MEDIUMCVSS 5.5EG 5.52025-10-10
Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access backup data from applications. User interaction is required for triggering this vulnerability.
- CVE-2025-54422MEDIUMCVSS 5.5EG 5.52025-07-29
Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. In versions 1.16.1 and below, a critical security vulnerability exists in password handling mechanisms. During encrypted sandbox crea…
- CVE-2025-54538MEDIUMCVSS 5.5EG 5.52025-07-28
In JetBrains TeamCity before 2025.07 password exposure was possible via command line in the "hg pull" command
- CVE-2025-54537MEDIUMCVSS 5.5EG 5.52025-07-28
In JetBrains TeamCity before 2025.07 user credentials were stored in plain text in memory snapshots
- CVE-2025-41458MEDIUMCVSS 5.5EG 5.52025-07-21
Unencrypted storage in the database in Two App Studio Journey v5.5.9 for iOS allows local attackers to extract sensitive data via direct access to the app’s filesystem.
- CVE-2025-41647MEDIUMCVSS 5.5EG 5.52025-06-25
A local, low-privileged attacker can learn the password of the connected controller in PLC Designer V4 due to an incorrect implementation that results in the password being displayed in plain text under special conditions.
- CVE-2024-56428MEDIUMCVSS 5.5EG 5.52025-05-21
The local iLabClient database in itech iLabClient 3.7.1 allows local attackers to read cleartext credentials (from the CONFIGS table) for their servers configured in the client.
- CVE-2025-31727MEDIUMCVSS 5.5EG 5.52025-04-02
Jenkins AsakusaSatellite Plugin 0.1.1 and earlier stores AsakusaSatellite API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins …
- CVE-2025-31726MEDIUMCVSS 5.5EG 5.52025-04-02
Jenkins Stack Hammer Plugin 1.0.6 and earlier stores Stack Hammer API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller f…
- CVE-2025-31725MEDIUMCVSS 5.5EG 5.52025-04-02
Jenkins monitor-remote-job Plugin 1.0 stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.
- CVE-2024-10404MEDIUMCVSS 5.5EG 5.52025-02-14
CalInvocationHandler in Brocade SANnav before 2.3.1b logs sensitive information in clear text. The vulnerability could allow an authenticated, local attacker to view Brocade Fabric OS switch sensitive information in clear text. An atta…
- CVE-2024-6785MEDIUMCVSS 5.5EG 5.52024-09-21
The configuration file stores credentials in cleartext. An attacker with local access rights can read or modify the configuration file, potentially resulting in the service being abused due to sensitive information exposure.
- CVE-2024-45004MEDIUMCVSS 5.5EG 5.52024-09-04
In the Linux kernel, the following vulnerability has been resolved: KEYS: trusted: dcp: fix leak of blob encryption key Trusted keys unseal the key blob on load, but keep the sealed payload in the blob field so that every subsequent read…
- CVE-2024-4840MEDIUMCVSS 5.5EG 5.52024-05-14
An flaw was found in the OpenStack Platform (RHOSP) director, a toolset for installing and managing a complete RHOSP environment. Plaintext passwords may be stored in log files, which can expose sensitive information to anyone with access …
- CVE-2024-29952MEDIUMCVSS 5.5EG 5.52024-04-17
A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow an authenticated user to print the Auth, Priv, and SSL key store passwords in unencrypted logs by manipulating command variables.
- CVE-2024-24488MEDIUMCVSS 5.5EG 5.52024-02-07
An issue in Shenzen Tenda Technology CP3V2.0 V11.10.00.2311090948 allows a local attacker to obtain sensitive information via the password component.
- CVE-2023-40238MEDIUMCVSS 5.5EG 5.52023-12-07
A LogoFAIL issue was discovered in BmpDecoderDxe in Insyde InsydeH2O with kernel 5.2 before 05.28.47, 5.3 before 05.37.47, 5.4 before 05.45.47, 5.5 before 05.53.47, and 5.6 before 05.60.47 for certain Lenovo devices. Image parsing of craft…
- CVE-2023-4066MEDIUMCVSS 5.5EG 5.52023-09-27
A flaw was found in Red Hat's AMQ Broker, which stores certain passwords in a secret security-properties-prop-module, defined in ActivemqArtemisSecurity CR; however, they are shown in plaintext in the StatefulSet details yaml of AMQ Broker.
- CVE-2023-40715MEDIUMCVSS 5.5EG 5.52023-09-13
A cleartext storage of sensitive information vulnerability [CWE-312] in FortiTester 2.3.0 through 7.2.3 may allow an attacker with access to the DB contents to retrieve the plaintext password of external servers configured in the device.
- CVE-2023-3950MEDIUMCVSS 5.5EG 5.52023-09-01
An information disclosure issue in GitLab EE affecting all versions from 16.2 prior to 16.2.5, and 16.3 prior to 16.3.1 allowed other Group Owners to see the Public Key for a Google Cloud Logging audit event streaming destination, if confi…
- CVE-2023-39210MEDIUMCVSS 5.5EG 5.52023-08-08
Cleartext storage of sensitive information in Zoom Client SDK for Windows before 5.15.0 may allow an authenticated user to enable an information disclosure via local access.
- CVE-2023-32455MEDIUMCVSS 5.5EG 5.52023-07-20
Dell Wyse ThinOS versions prior to 2208 (9.3.2102) contain a sensitive information disclosure vulnerability. An unauthenticated malicious user with local access to the device could exploit this vulnerability to read sensitive information …
- CVE-2023-32447MEDIUMCVSS 5.5EG 5.52023-07-20
Dell Wyse ThinOS versions prior to 2306 (9.4.2103) contain a sensitive information disclosure vulnerability. A malicious user with local access to the device could exploit this vulnerability to read sensitive information written to the lo…
- CVE-2023-32446MEDIUMCVSS 5.5EG 5.52023-07-20
Dell Wyse ThinOS versions prior to 2303 (9.4.1141) contain a sensitive information disclosure vulnerability. An unauthenticated malicious user with local access to the device could exploit this vulnerability to read sensitive information …
- CVE-2023-32448MEDIUMCVSS 5.5EG 5.52023-05-30
PowerPath for Windows, versions 7.0, 7.1 & 7.2 contains License Key Stored in Cleartext vulnerability. A local user with access to the installation directory can retrieve the license key of the product and use it to install and license Po…
- CVE-2023-20914MEDIUMCVSS 5.5EG 5.52023-05-15
In onSetRuntimePermissionGrantStateByDeviceAdmin of AdminRestrictedPermissionsUtils.java, there is a possible way for the work profile to read SMS messages due to a permissions bypass. This could lead to local information disclosure with U…
- CVE-2023-29471MEDIUMCVSS 5.5EG 5.52023-04-27
Lightbend Alpakka Kafka before 5.0.0 logs its configuration as debug information, and thus log files may contain credentials (if plain cleartext login is configured). This occurs in akka.kafka.internal.KafkaConsumerActor.
- CVE-2023-25263MEDIUMCVSS 5.5EG 5.52023-03-27
In Stimulsoft Designer (Desktop) 2023.1.5, and 2023.1.4, once an attacker decompiles the Stimulsoft.report.dll the attacker is able to decrypt any connectionstring stored in .mrt files since a static secret is used. The secret does not dif…
- CVE-2022-48310MEDIUMCVSS 5.5EG 5.52023-03-01
An information disclosure vulnerability allows sensitive key material to be included in technical support archives in Sophos Connect versions older than 2.2.90.
- CVE-2023-24454MEDIUMCVSS 5.5EG 5.52023-01-26
Jenkins TestQuality Updater Plugin 1.3 and earlier stores the TestQuality Updater password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file sy…
- CVE-2023-24442MEDIUMCVSS 5.5EG 5.52023-01-26
Jenkins GitHub Pull Request Coverage Status Plugin 2.2.0 and earlier stores the GitHub Personal Access Token, Sonar access token and Sonar password unencrypted in its global configuration file on the Jenkins controller where they can be vi…
Map vulnerabilities like CWE-312 to your infrastructure
EchelonGraph correlates every CVE — across CWE-312 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →