CWE-312— Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.— MITRE CWE catalog
902 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-312page 2 of 19
- CVE-2022-43958CRITICALCVSS 7.6EG 9.12022-11-08
A vulnerability has been identified in QMS Automotive (All versions < V12.39), QMS Automotive (All versions < V12.39). User credentials are stored in plaintext in the database without any hashing mechanism. This could allow an attacker to …
- CVE-2025-63729CRITICALCVSS 9.0EG 9.02025-11-25
An issue was discovered in Syrotech SY-GPON-1110-WDONT SYRO_3.7L_3.1.02-240517 allowing attackers to exctract the SSL Private Key, CA Certificate, SSL Certificate, and Client Certificates in .pem format in firmware in etc folder.
- CVE-2024-9798CRITICALCVSS 9.0EG 9.02024-10-10
The health endpoint is public so everybody can see a list of all services. It is potentially valuable information for attackers.
- CVE-2023-50719CRITICALCVSS 7.5EG 9.02023-12-15
XWiki Platform is a generic wiki platform. Starting in 7.2-milestone-2 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the Solr-based search in XWiki discloses the password hashes of all users to anyone with view right on the respec…
- CVE-2026-107807HIGHCVSS 8.8EG 8.82026-10-09
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, Nginx UI accepts the Node.Secret master credential through the node_secret query parameter in HTTP and WebSocket authentication paths instead of requiring t…
- CVE-2026-20312HIGHCVSS 8.8EG 8.82026-08-05
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that ad…
- CVE-2026-55997HIGHCVSS 8.8EG 8.82026-08-05
Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in plaintext with no expiration, so a malicious user could obtain one either through the Ranc…
- CVE-2025-14377HIGHCVSS 8.8EG 8.82026-01-20
A security issue was discovered within the legacy Ansible playbook component of Verve Asset Manager, caused by plaintext secrets incorrectly stored when a playbook is running. This component has been retired and has been optional since the…
- CVE-2024-28809HIGHCVSS 8.8EG 8.82024-09-30
An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive password in firmware update packages allows attackers to access various appliance services via hardcoded credentials.
- CVE-2024-45175HIGHCVSS 8.8EG 8.82024-09-05
An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Sensitive information is stored in cleartext. It was found out that sensitive information, for example login credentials of cameras, is stored in cleartext. Thus, an a…
- CVE-2024-36790HIGHCVSS 8.8EG 8.82024-06-07
Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 was discovered to store credentials in plaintext.
- CVE-2023-45151HIGHCVSS 8.8EG 8.82023-10-16
Nextcloud server is an open source home cloud platform. Affected versions of Nextcloud stored OAuth2 tokens in plaintext which allows an attacker who has gained access to the server to potentially elevate their privilege. This issue has be…
- CVE-2022-35120HIGHCVSS 8.8EG 8.82022-12-01
IXPdata EasyInstall 6.6.14725 contains an access control issue.
- CVE-2022-37401HIGHCVSS 8.8EG 8.82022-08-15
Apache OpenOffice supports the storage of passwords for web connections in the user's configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in OpenOffice existed where master key w…
- CVE-2022-26307HIGHCVSS 8.8EG 8.82022-07-25
LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in LibreOffice existed where master key was …
- CVE-2021-37157HIGHCVSS 8.8EG 8.82021-11-10
An issue was discovered in OpenGamePanel OGP-Agent-Linux through 2021-08-14. $HOME/OGP/Cfg/Config.pm has the root password in cleartext.
- CVE-2020-5805HIGHCVSS 8.8EG 8.82021-01-08
In Marvell QConvergeConsole GUI <= 5.5.0.74, credentials are stored in cleartext in tomcat-users.xml. OS-level users on the QCC host who are not authorized to use QCC may use the plaintext credentials to login to QCC.
- CVE-2019-10449HIGHCVSS 8.8EG 8.82019-10-16
Jenkins Fortify on Demand Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
- CVE-2019-10448HIGHCVSS 8.8EG 8.82019-10-16
Jenkins Extensive Testing Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
- CVE-2019-10443HIGHCVSS 8.8EG 8.82019-10-16
Jenkins iceScrum Plugin 1.1.4 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master file system.
- CVE-2019-10440HIGHCVSS 8.8EG 8.82019-10-16
Jenkins NeoLoad Plugin 2.2.5 and earlier stored credentials unencrypted in its global configuration file and in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the …
- CVE-2019-10351HIGHCVSS 8.8EG 8.82019-07-11
Jenkins Caliper CI Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
- CVE-2019-10350HIGHCVSS 8.8EG 8.82019-07-11
Jenkins Port Allocator Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
- CVE-2019-10348HIGHCVSS 8.8EG 8.82019-07-11
Jenkins Gogs Plugin stored credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
- CVE-2019-11966HIGHCVSS 8.8EG 8.82019-06-05
A remote privilege escalation vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
- CVE-2017-9654HIGHCVSS 8.8EG 8.82018-04-24
The Philips DoseWise Portal web-based application versions 1.1.7.333 and 2.1.1.3069 stores login credentials in clear text within backend system files. CVSS v3 base score: 6.5, CVSS vector string: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N.
- CVE-2017-2672HIGHCVSS 6.5EG 8.82018-06-21
A flaw was found in foreman before version 1.15 in the logging of adding and registering images. An attacker with access to the foreman log file would be able to view passwords for provisioned systems in the log file, allowing them to acce…
- CVE-2022-33928HIGHCVSS 6.4EG 8.82022-08-10
Dell Wyse Management Suite 3.6.1 and below contains an Plain-text Password Storage Vulnerability in UI. An attacker with low privileges could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. Th…
- CVE-2024-58277HIGHCVSS 8.7EG 8.72025-12-04
R Radio Network FM Transmitter 1.07 allows unauthenticated attackers to access the admin user's password through the system.cgi endpoint, enabling authentication bypass and FM station setup access.
- CVE-2025-51055HIGHCVSS 8.6EG 8.62025-08-06
Insecure Data Storage of credentials has been found in /api_vedo/configuration/config.yml file in Vedo Suite version 2024.17. This file contains clear-text credentials, secret keys, and database information.
- CVE-2025-22896HIGHCVSS 8.6EG 8.62025-02-13
mySCADA myPRO Manager stores credentials in cleartext, which could allow an attacker to obtain sensitive information.
- CVE-2023-3489HIGHCVSS 8.6EG 8.62023-08-31
The firmwaredownload command on Brocade Fabric OS v9.2.0 could log the FTP/SFTP/SCP server password in clear text in the SupportSave file when performing a downgrade from Fabric OS v9.2.0 to any earlier version of Fabric OS.
- CVE-2022-25164HIGHCVSS 8.6EG 8.62022-11-25
Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.095Z and Mitsubishi Electric MX OPC UA Module Configurator-R versions 1.08J and prior allows a remote unauthenticated attac…
- CVE-2021-40527HIGHCVSS 8.6EG 8.62021-10-25
Exposure of senstive information to an unauthorised actor in the "com.onepeloton.erlich" mobile application up to and including version 1.7.22 allows a remote attacker to access developer files stored in an AWS S3 bucket, by reading creden…
- CVE-2020-3921HIGHCVSS 8.6EG 8.62020-03-27
UltraLog Express device management software stores user’s information in cleartext. Any user can obtain accounts information through a specific page.
- CVE-2024-8070HIGHCVSS 8.5EG 8.52024-10-13
CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that exposes test credentials in the firmware binary
- CVE-2022-29090HIGHCVSS 8.5EG 8.52022-08-10
Dell Wyse Management Suite 3.6.1 and below contains a Sensitive Data Exposure vulnerability. A low privileged malicious user could potentially exploit this vulnerability in order to obtain credentials. The attacker may be able to use the e…
- CVE-2024-58023HIGHCVSS 8.4EG 8.42026-07-23
Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive information.
- CVE-2024-28327HIGHCVSS 8.4EG 8.42024-04-26
Asus RT-N12+ B1 router stores user passwords in plaintext, which could allow local attackers to obtain unauthorized access and modify router settings.
- CVE-2022-45868HIGHCVSS 8.4EG 8.42022-11-23
The web-based admin console in H2 Database Engine before 2.2.220 can be started via the CLI with the argument -webAdminPassword, which allows the user to specify the password in cleartext for the web admin console. Consequently, a local us…
- CVE-2020-27613HIGHCVSS 8.4EG 8.42020-10-21
The installation procedure in BigBlueButton before 2.2.28 (or earlier) uses ClueCon as the FreeSWITCH password, which allows local users to achieve unintended FreeSWITCH access.
- CVE-2019-14890HIGHCVSS 8.4EG 8.42019-11-26
A vulnerability was found in Ansible Tower before 3.6.1 where an attacker with low privilege could retrieve usernames and passwords credentials from the new RHSM saved in plain text into the database at '/api/v2/config' when applying the A…
- CVE-2026-81683HIGHCVSS 5.5EG 8.42026-08-27
openssl_encrypt (pip package openssl-encrypt) versions 1.4.8 and earlier store an mTLS client private key in cleartext within a world-readable (0644) SharedPreferences file via the desktop GUI's Settings screen 'combined certificate and pr…
- CVE-2026-67236HIGHCVSS 8.2EG 8.22026-09-25
RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.8 and 4.3.2, a successful POST /login caused is_authorized/2 to set an auth cookie containing base64-encoded username:password credentials without HttpOnly, Secure, SameSit…
- CVE-2025-32353HIGHCVSS 8.2EG 8.22025-07-16
Kaseya Rapid Fire Tools Network Detective 2.0.16.0 has Unencrypted Credentials (for privileged access) stored in the collector.txt configuration file.
- CVE-2025-46634HIGHCVSS 8.2EG 8.22025-05-01
Cleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro 16.03.30.14 may allow an unauthenticated attacker to authenticate to the web management portal by collecting credentials from observed/collec…
- CVE-2025-46633HIGHCVSS 8.2EG 8.22025-05-01
Cleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an attacker to decrypt traffic between the client and server by collecting the symmetric AES key from collected and/or obs…
- CVE-2024-53979HIGHCVSS 8.2EG 8.22024-11-29
ibm.ibm_zhmc is an Ansible collection for the IBM Z HMC. The Ansible collection "ibm.ibm_zhmc" writes password-like properties in clear text into its log file and into the output returned by some of its Ansible module in the following case…
- CVE-2024-53865HIGHCVSS 8.2EG 8.22024-11-29
zhmcclient is a pure Python client library for the IBM Z HMC Web Services API. In affected versions the Python package "zhmcclient" writes password-like properties in clear text into its HMC and API logs in the following cases: 1. The 'boo…
- CVE-2024-38877HIGHCVSS 8.2EG 8.22024-08-02
A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 Domain Controller R9.2 (All versions), Omnivise T3000 Network Intrusion Detection System (NIDS) R9.2 (All versions), Omnivise T300…
Map vulnerabilities like CWE-312 to your infrastructure
EchelonGraph correlates every CVE — across CWE-312 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →