CWE-312— Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.— MITRE CWE catalog
903 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-312page 14 of 19
- CVE-2020-10727MEDIUMCVSS 5.5EG 5.52020-06-26
A flaw was found in ActiveMQ Artemis management API from version 2.7.0 up until 2.12.0, where a user inadvertently stores passwords in plaintext in the Artemis shadow file (etc/artemis-users.properties file) when executing the `resetUsers`…
- CVE-2020-2154MEDIUMCVSS 5.5EG 5.52020-03-09
Jenkins Zephyr for JIRA Test Management Plugin 1.5 and earlier stores its credentials in plain text in a global configuration file on the Jenkins master file system.
- CVE-2020-4224MEDIUMCVSS 5.5EG 5.52020-02-03
IBM StoredIQ 7.6.0.17 through 7.6.0.20 could disclose sensitive information to a local user due to data in certain directories not being encrypted when it contained symbolic links. IBM X-Force ID: 175133.
- CVE-2011-2916MEDIUMCVSS 5.5EG 5.52019-11-15
qtnx 0.9 stores non-custom SSH keys in a world-readable configuration file. If a user has a world-readable or world-executable home directory, another local system user could obtain the private key used to connect to remote NX sessions.
- CVE-2019-10430MEDIUMCVSS 5.5EG 5.52019-09-25
Jenkins NeuVector Vulnerability Scanner Plugin 1.5 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.
- CVE-2019-4566MEDIUMCVSS 5.5EG 5.52019-09-24
IBM Security Key Lifecycle Manager 3.0 and 3.0.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 166627.
- CVE-2019-5765MEDIUMCVSS 5.5EG 5.52019-02-19
An exposed debugging endpoint in the browser in Google Chrome on Android prior to 72.0.3626.81 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted Intent.
- CVE-2009-1466MEDIUMCVSS 5.5EG 5.52009-05-14
Application Access Server (A-A-S) 2.0.48 stores (1) passwords and (2) the port keyword in cleartext in aas.ini, which allows local users to obtain sensitive information by reading this file.
- CVE-2008-1567MEDIUMCVSS 5.5EG 5.52008-03-31
phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.
- CVE-2005-2209MEDIUMCVSS 5.5EG 5.52005-07-11
Capturix ScanShare 1.06 build 50 stores sensitive information such as the password in cleartext in capturixss_cfg.ini, which is readable by local users.
- CVE-2002-1696MEDIUMCVSS 5.5EG 5.52002-12-31
Microsoft Outlook plug-in PGP version 7.0, 7.0.3, and 7.0.4 silently saves a decrypted copy of a message to hard disk when "Automatically decrypt/verify when opening messages" option is checked, "Always use Secure Viewer when decrypting" o…
- CVE-2022-45154MEDIUMCVSS 4.4EG 5.52023-02-15
A Cleartext Storage of Sensitive Information vulnerability in suppportutils of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15, SUSE Linux Enterprise Server 15 SP3 allows attackers that get access to the support logs to ga…
- CVE-2022-34910MEDIUMCVSS 4.1EG 5.52023-02-27
An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It uses a local database to store data and accounts. However, the password is stored in cleartext. Therefore, an attacker can retrieve the passwords of othe…
- CVE-2022-22470MEDIUMCVSS 4.1EG 5.52023-01-09
IBM Security Verify Governance 10.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 225232.
- CVE-2022-27549MEDIUMCVSS 4.0EG 5.52022-07-06
HCL Launch may store certain data for recurring activities in a plain text format.
- CVE-2018-17499MEDIUMCVSS 2.9EG 5.52019-03-21
Envoy Passport for Android and Envoy Passport for iPhone could allow a local attacker to obtain sensitive information, caused by the storing of unencrypted data in logs. An attacker could exploit this vulnerability to obtain two API keys, …
- CVE-2018-17489MEDIUMCVSS 2.9EG 5.52019-03-21
EasyLobby Solo could allow a local attacker to obtain sensitive information, caused by the storing of the social security number in plaintext. By visiting the kiosk and viewing the Visitor table of the database, an attacker could exploit t…
- CVE-2026-102368MEDIUMCVSS 5.4EG 5.42026-10-08
Affected Tapo device firmware stores device-specific cryptographic material in plaintext within nonvolatile storage. An attacker with physical access to an affected device can recover this sensitive material from the firmware. Successfu…
- CVE-2024-12094MEDIUMCVSS 5.4EG 5.42024-12-05
This vulnerability exists in the Tinxy mobile app due to storage of logged-in user information in plaintext on the device database. An attacker with physical access to the rooted device could exploit this vulnerability by accessing its dat…
- CVE-2020-11918MEDIUMCVSS 5.4EG 5.42024-11-07
An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. When a backup file is created through the web interface, information on all users, including passwords, can be found in cleartext in the backup file. An attacker capable of…
- CVE-2023-31925MEDIUMCVSS 5.4EG 5.42023-08-31
Brocade SANnav before v2.3.0 and v2.2.2a stores SNMPv3 Authentication passwords in plaintext. A privileged user could retrieve these credentials with knowledge and access to these log files. SNMP credentials could be seen in SANnav Sup…
- CVE-2022-21818MEDIUMCVSS 5.4EG 5.42022-02-15
NVIDIA License System contains a vulnerability in the installation scripts for the DLS virtual appliance, where a user on a network after signing in to the portal can access other users’ credentials, allowing them to gain escalated privi…
- CVE-2020-15105MEDIUMCVSS 5.4EG 5.42020-07-10
Django Two-Factor Authentication before 1.12, stores the user's password in clear text in the user session (base64-encoded). The password is stored in the session when the user submits their username and password, and is removed once they …
- CVE-2026-86280MEDIUMCVSS 5.3EG 5.32026-09-07
A vulnerability was identified in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This affects an unknown function of the file cict_portal.sql. Such manipulation leads to cleartext storage of sensitive informa…
- CVE-2026-45040MEDIUMCVSS 5.3EG 5.32026-05-28
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, RustFS suffers from sensitive information leakage in log outputs. When the server is run with RUST_LOG=debug sensitive credentials including SessionToken (…
- CVE-2026-5531MEDIUMCVSS 5.3EG 5.32026-04-05
A vulnerability has been found in SourceCodester Student Result Management System 1.0. Impacted is an unknown function of the file /login_credentials.txt of the component HTTP GET Request Handler. The manipulation leads to cleartext storag…
- CVE-2025-59792MEDIUMCVSS 5.3EG 5.32025-11-28
Reveals plaintext credentials in the MONITOR command vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 1.0.0 through 2.13.0. Users are recommended to upgrade to version 2.14.0, which fixes the issue.
- CVE-2024-43429MEDIUMCVSS 5.3EG 5.32024-11-11
A flaw was found in moodle. Some hidden user profile fields are visible in gradebook reports, which could result in users without the "view hidden user fields" capability having access to the information.
- CVE-2024-9802MEDIUMCVSS 5.3EG 5.32024-10-10
The conformance validation endpoint is public so everybody can verify the conformance of onboarded services. The response could contain specific information about the service, including available endpoints, and swagger. It could advise abo…
- CVE-2024-40750MEDIUMCVSS 5.3EG 5.32024-07-09
Linksys Velop Pro 6E 1.0.8 MX6200_1.0.8.215731 and 7 1.0.10.215314 devices send cleartext Wi-Fi passwords over the public Internet during app-based installation.
- CVE-2024-31486MEDIUMCVSS 5.3EG 5.32024-05-14
A vulnerability has been identified in OPUPI0 AMQP/MQTT (All versions < V5.30). The affected devices stores MQTT client passwords without sufficient protection on the devices. An attacker with remote shell access or physical access could …
- CVE-2023-4392MEDIUMCVSS 5.3EG 5.32023-08-17
A vulnerability was found in Control iD Gerencia Web 1.30 and classified as problematic. Affected by this issue is some unknown functionality of the component Cookie Handler. The manipulation leads to cleartext storage of sensitive informa…
- CVE-2022-22302MEDIUMCVSS 5.3EG 5.32023-07-11
A clear text storage of sensitive information (CWE-312) vulnerability in both FortiGate version 6.4.0 through 6.4.1, 6.2.0 through 6.2.9 and 6.0.0 through 6.0.13 and FortiAuthenticator version 5.5.0 and all versions of 6.1 and 6.0 may allo…
- CVE-2023-35699MEDIUMCVSS 5.3EG 5.32023-07-10
Cleartext Storage on Disk in the SICK ICR890-4 could allow an unauthenticated attacker with local access to the device to disclose sensitive information by accessing a SD card.
- CVE-2022-33159MEDIUMCVSS 5.3EG 5.32023-06-15
IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 228567.
- CVE-2023-32983MEDIUMCVSS 5.3EG 5.32023-05-16
Jenkins Ansible Plugin 204.v8191fd551eb_f and earlier does not mask extra variables displayed on the configuration form, increasing the potential for attackers to observe and capture them.
- CVE-2023-31408MEDIUMCVSS 5.3EG 5.32023-05-15
Cleartext Storage of Sensitive Information in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to potentially steal user credentials that are stored in the us…
- CVE-2022-22457MEDIUMCVSS 5.3EG 5.32022-12-22
IBM Security Verify Governance, Identity Manager 10.0.1 stores sensitive information including user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 225007.
- CVE-2022-38710MEDIUMCVSS 5.3EG 5.32022-11-03
IBM Robotic Process Automation 21.0.1 and 21.0.2 could disclose sensitive version to an unauthorized control sphere information that could aid in further attacks against the system. IBM X-Force ID: 234292.
- CVE-2020-15325MEDIUMCVSS 5.3EG 5.32022-09-29
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded Erlang cookie for ejabberd replication.
- CVE-2022-32217MEDIUMCVSS 5.3EG 5.32022-09-23
A cleartext storage of sensitive information exists in Rocket.Chat <v4.6.4 due to Oauth token being leaked in plaintext in Rocket.chat logs.
- CVE-2022-41248MEDIUMCVSS 5.3EG 5.32022-09-21
Jenkins BigPanda Notifier Plugin 1.4.0 and earlier does not mask the BigPanda API key on the global configuration form, increasing the potential for attackers to observe and capture it.
- CVE-2021-36165MEDIUMCVSS 5.3EG 5.32021-09-28
RICON Industrial Cellular Router S9922L 16.10.3(3794) is affected by cleartext storage of sensitive information and sends username and password as base64.
- CVE-2021-31989MEDIUMCVSS 5.3EG 5.32021-08-25
A user with permission to log on to the machine hosting the AXIS Device Manager client could under certain conditions extract a memory dump from the built-in Windows Task Manager application. The memory dump may potentially contain credent…
- CVE-2020-15384MEDIUMCVSS 5.3EG 5.32021-06-09
Brocade SANNav before version 2.1.1 contains an information disclosure vulnerability. Successful exploitation of internal server information in the initial login response header.
- CVE-2021-20995MEDIUMCVSS 5.3EG 5.32021-05-13
In multiple managed switches by WAGO in different versions the webserver cookies of the web based UI contain user credentials.
- CVE-2021-26595MEDIUMCVSS 5.3EG 5.32021-02-23
In Directus 8.x through 8.8.1, an attacker can learn sensitive information such as the version of the CMS, the PHP version used by the site, and the name of the DBMS, simply by view the result of the api-aa, called automatically upon a con…
- CVE-2021-27549MEDIUMCVSS 5.3EG 5.32021-02-22
Genymotion Desktop through 3.2.0 leaks the host's clipboard data to the Android application by default. NOTE: the vendor's position is that this is intended behavior that can be changed through the Settings > Device screen
- CVE-2021-20410MEDIUMCVSS 5.3EG 5.32021-02-12
IBM Security Verify Information Queue 1.0.6 and 1.0.7 sends user credentials in plain clear text which can be read by an authenticated user using man in the middle techniques. IBM X-Force ID: 198190.
- CVE-2019-4687MEDIUMCVSS 5.3EG 5.32021-01-13
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history…
Map vulnerabilities like CWE-312 to your infrastructure
EchelonGraph correlates every CVE — across CWE-312 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →