CWE-312— Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.— MITRE CWE catalog
902 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-312page 3 of 19
- CVE-2019-3767HIGHCVSS 8.2EG 8.22019-10-14
Dell ImageAssist versions prior to 8.7.15 contain an information disclosure vulnerability. Dell ImageAssist stores some sensitive encrypted information in the images it creates. A privileged user of a system running an operating system tha…
- CVE-2019-25279HIGHCVSS 7.5EG 8.22026-01-08
FaceSentry Access Control System 6.4.8 contains a cleartext password storage vulnerability that allows attackers to access unencrypted credentials in the device's SQLite database. Attackers can directly read sensitive login information sto…
- CVE-2026-62376HIGHCVSS 8.1EG 8.12026-10-09
Vikunja is an open-source self-hosted task management platform. Versions prior to 2.4.0 store password-reset, email-confirmation, and account-deletion tokens in the `user_tokens` table in plaintext. If an attacker gains read access to the …
- CVE-2026-46622HIGHCVSS 8.1EG 8.12026-06-11
SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, API tokens used to authenticate all REST API requests are stored as plaintext strings in the api_tokens database table. Any attacker who obtains read access to the…
- CVE-2024-41716HIGHCVSS 8.1EG 8.12024-09-04
Cleartext storage of sensitive information vulnerability exists in WindLDR and WindO/I-NV4. If this vulnerability is exploited, an attacker who obtained the product's project file may obtain user credentials of the PLC or Operator Interfac…
- CVE-2021-22509HIGHCVSS 8.1EG 8.12024-08-28
A vulnerability identified in storing and reusing information in Advance Authentication. This issue can lead to leakage of sensitive data to unauthorized user. The issue affects NetIQ Advance Authentication before 6.3.5.1
- CVE-2023-28713HIGHCVSS 8.1EG 8.12023-06-01
Plaintext storage of a password exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. Because account information of the database is saved in a local file in plaintext, a user who can access the PC where the affected product is ins…
- CVE-2022-0835HIGHCVSS 8.1EG 8.12022-04-11
AVEVA System Platform 2020 stores sensitive information in cleartext, which may allow access to an attacker or a low-privileged user.
- CVE-2020-26228HIGHCVSS 8.1EG 8.12020-11-23
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.23 and 10.4.10 user session identifiers were stored in cleartext - without processing with additional cryptographic hashing algorithms. This vuln…
- CVE-2019-9872HIGHCVSS 8.1EG 8.12019-07-03
In several versions of JetBrains IntelliJ IDEA Ultimate, creating run configurations for cloud application servers leads to saving a cleartext unencrypted record of the server credentials in the IDE configuration files. If the Settings Rep…
- CVE-2023-50957HIGHCVSS 8.0EG 8.02024-02-10
IBM Storage Defender - Resiliency Service 2.0 could allow a privileged user to perform unauthorized actions after obtaining encrypted data from clear text key storage. IBM X-Force ID: 275783.
- CVE-2026-41520HIGHCVSS 7.9EG 7.92026-05-08
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.17.15, 1.18.9, and 1.19.3, the output of cilium-bugtool can contain sensitive data when the tool is run against Cilium deploymen…
- CVE-2021-25502HIGHCVSS 7.9EG 7.92021-11-05
A vulnerability of storing sensitive information insecurely in Property Settings prior to SMR Nov-2021 Release 1 allows attackers to read ESN value without priviledge.
- CVE-2021-31581HIGHCVSS 7.9EG 7.92021-07-22
The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be escaped by abusing the 'Edit MySQL Configuration' command. This command launches a standard vi editor interface which can then be escaped. This issue was re…
- CVE-2025-34428HIGHCVSS 7.8EG 7.82025-12-10
MailEnable versions prior to 10.54 contain a cleartext storage of credentials vulnerability that can lead to local credential compromise and account takeover. The product stores user and administrative passwords in plaintext within AUTH.SA…
- CVE-2025-34427HIGHCVSS 7.8EG 7.82025-12-10
MailEnable versions prior to 10.54 contain a cleartext storage of credentials vulnerability that can lead to local credential compromise and account takeover. The product stores user and administrative passwords in plaintext within AUTH.TA…
- CVE-2025-34200HIGHCVSS 7.8EG 7.82025-09-19
Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) provision the appliance with the network account credentials in clear-text inside /etc/issue, and the file is world-readable by default.…
- CVE-2025-50777HIGHCVSS 7.8EG 7.82025-07-30
The firmware of the AZIOT 2MP Full HD Smart Wi-Fi CCTV Home Security Camera (version V1.00.02) contains an Incorrect Access Control vulnerability that allows local attackers to gain root shell access. Once accessed, the device exposes crit…
- CVE-2023-49113HIGHCVSS 7.8EG 7.82024-06-20
The Kiuwan Local Analyzer (KLA) Java scanning application contains several hard-coded secrets in plain text format. In some cases, this can potentially compromise the confidentiality of the scan results. Several credentials were found i…
- CVE-2023-2809HIGHCVSS 7.8EG 7.82023-10-04
Plaintext credential usage vulnerability in Sage 200 Spain 2023.38.001 version, the exploitation of which could allow a remote attacker to extract SQL database credentials from the DLL application. This vulnerability could be linked to kno…
- CVE-2023-26593HIGHCVSS 7.8EG 7.82023-04-11
CENTUM series provided by Yokogawa Electric Corporation are vulnerable to cleartext storage of sensitive information. If an attacker who can login or access the computer where the affected product is installed tampers the password file sto…
- CVE-2022-22031HIGHCVSS 7.8EG 7.82022-07-12
Windows Credential Guard Domain-joined Public Key Elevation of Privilege Vulnerability
- CVE-2022-28214HIGHCVSS 7.8EG 7.82022-05-11
During an update of SAP BusinessObjects Enterprise, Central Management Server (CMS) - versions 420, 430, authentication credentials are being exposed in Sysmon event logs. This Information Disclosure could cause a high impact on systems’…
- CVE-2021-36460HIGHCVSS 7.8EG 7.82022-04-25
VeryFitPro (com.veryfit2hr.second) 3.2.8 hashes the account's password locally on the device and uses the hash to authenticate in all communication with the backend API, including login, registration and changing of passwords. This allows …
- CVE-2021-3551HIGHCVSS 7.8EG 7.82022-02-16
A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the installation log file. This flaw allows a local attacker to retrieve the file to obtain the admin password and gain ad…
- CVE-2021-40363HIGHCVSS 7.8EG 7.82022-02-09
A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP1), SIMATIC WinCC V15 and earlier (All versions < V15 SP1 Update 7), SIMATIC WinCC V16 (…
- CVE-2021-38422HIGHCVSS 7.8EG 7.82021-11-03
Delta Electronics DIALink versions 1.2.4.0 and prior stores sensitive information in cleartext, which may allow an attacker to have extensive access to the application directory and escalate privileges.
- CVE-2020-35455HIGHCVSS 7.8EG 7.82021-03-17
The Taidii Diibear Android application 2.4.0 and all its derivatives allow attackers to obtain user credentials from Shared Preferences and the SQLite database because of insecure data storage.
- CVE-2021-0337HIGHCVSS 7.8EG 7.82021-02-10
In moveInMediaStore of FileSystemProvider.java, there is a possible file exposure due to stale metadata. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitatio…
- CVE-2020-7516HIGHCVSS 7.8EG 7.82020-07-23
A CWE-316: Cleartext Storage of Sensitive Information in Memory vulnerability exists in Easergy Builder V1.4.7.2 and prior which could allow an attacker access to login credentials.
- CVE-2020-5899HIGHCVSS 7.8EG 7.82020-07-01
In NGINX Controller 3.0.0-3.4.0, recovery code required to change a user's password is transmitted and stored in the database in plain text, which allows an attacker who can intercept the database connection or have read access to the data…
- CVE-2019-4676HIGHCVSS 7.8EG 7.82020-07-01
IBM Security Identity Manager Virtual Appliance 7.0.2 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 171512.
- CVE-2019-10453HIGHCVSS 7.8EG 7.82019-10-16
Jenkins Delphix Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
- CVE-2019-12171HIGHCVSS 7.8EG 7.82019-07-08
Dropbox.exe (and QtWebEngineProcess.exe in the Web Helper) in the Dropbox desktop application 71.4.108.0 store cleartext credentials in memory upon successful login or new account creation. These are not securely freed in the running proce…
- CVE-2019-3937HIGHCVSS 7.8EG 7.82019-04-30
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 stores usernames, passwords, slideshow passcode, and other configuration options in cleartext in the file /tmp/scfgdndf. A local attacker can use this vulnerability to …
- CVE-2018-12572HIGHCVSS 7.8EG 7.82019-03-21
Avast Free Antivirus prior to 19.1.2360 stores user credentials in memory upon login, which allows local users to obtain sensitive information by dumping AvastUI.exe application memory and parsing the data.
- CVE-2018-19009HIGHCVSS 7.8EG 7.82019-01-25
Pilz PNOZmulti Configurator prior to version 10.9 allows an authenticated attacker with local access to the system containing the PNOZmulti Configurator software to view sensitive credential data in clear-text. This sensitive data is appli…
- CVE-2017-1309HIGHCVSS 7.8EG 7.82017-07-19
IBM InfoSphere Master Data Management Server 11.0 - 11.6 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 125463.
- CVE-2008-6828HIGHCVSS 7.8EG 7.82009-06-08
Symantec Altiris Deployment Solution 6.x before 6.9.355 SP1 stores the Application Identity Account password in memory in cleartext, which allows local users to gain privileges and modify clients of the Deployment Solution Server.
- CVE-2022-22069HIGHCVSS 7.7EG 7.82022-09-02
Devices with keyprotect off may store unencrypted keybox in RPMB and cause cryptographic issue in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
- CVE-2021-35526HIGHCVSS 6.3EG 7.82021-09-08
Backup file without encryption vulnerability is found in Hitachi ABB Power Grids System Data Manager – SDM600 allows attacker to gain access to sensitive information. This issue affects: Hitachi ABB Power Grids System Data Manager – SD…
- CVE-2018-1877HIGHCVSS 6.2EG 7.82018-11-02
IBM Robotic Process Automation with Automation Anywhere 11 could store highly sensitive information in the form of unencrypted passwords that would be available to a local user. IBM X-Force ID: 151713.
- CVE-2026-66782HIGHCVSS 5.8EG 7.82026-08-18
A flaw was found in the Submariner operator. This vulnerability allows for the exposure of a long-lived broker service account (SA) bearer token within the Submariner Custom Resource (CR) specification. An attacker with access to the clust…
- CVE-2026-43824HIGHCVSS 7.7EG 7.72026-05-02
In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data.
- CVE-2024-52284HIGHCVSS 7.7EG 7.72025-09-02
Unauthorized disclosure of sensitive data: Any user with `GET` or `LIST` permissions on `BundleDeployment` resources could retrieve Helm values containing credentials or other secrets.
- CVE-2024-25661HIGHCVSS 7.7EG 7.72024-10-01
In Infinera TNMS (Transcend Network Management System) 19.10.3, cleartext storage of sensitive information in memory of the desktop application TNMS Client allows guest OS administrators to obtain various users' passwords by reading memory…
- CVE-2020-26288HIGHCVSS 7.7EG 7.72020-12-30
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. It is an npm package "parse-server". In Parse Server before version 4.5.0, user passwords involved in LDAP authentication are stored in…
- CVE-2019-3606HIGHCVSS 7.7EG 7.72019-03-26
Data Leakage Attacks vulnerability in the web portal component when in an MDR pair in McAfee Network Security Management (NSM) 9.1 < 9.1.7.75 (Update 4) and 9.2 < 9.2.7.31 Update2 allows administrators to view configuration information in …
- CVE-2024-42451HIGHCVSS 6.5EG 7.72024-12-04
A vulnerability in Veeam Backup & Replication allows low-privileged users to leak all saved credentials in plaintext. This is achieved by calling a series of methods over an external protocol, ultimately retrieving the credentials using a …
- CVE-2025-56565HIGHCVSS 7.6EG 7.62026-09-16
DD-WRT firmware, as deployed on TP-Link TL-WR740N v1 through v4 hardware, stores sensitive authentication credentials in cleartext within non-volatile memory. The exposed material includes SSH private keys, dynamic DNS passwords, email not…
Map vulnerabilities like CWE-312 to your infrastructure
EchelonGraph correlates every CVE — across CWE-312 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →