CWE-312— Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.— MITRE CWE catalog
902 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-312page 4 of 19
- CVE-2025-27460HIGHCVSS 7.6EG 7.62025-07-03
The hard drives of the device are not encrypted using a full volume encryption feature such as BitLocker. This allows an attacker with physical access to the device to use an alternative operating system to interact with the hard drives, c…
- CVE-2023-30853HIGHCVSS 7.6EG 7.62023-04-28
Gradle Build Action allows users to execute a Gradle Build in their GitHub Actions workflow. A vulnerability impacts GitHub workflows using the Gradle Build Action prior to version 2.4.2 that have executed the Gradle Build Tool with the co…
- CVE-2022-46155HIGHCVSS 7.6EG 7.62022-11-29
Airtable.js is the JavaScript client for Airtable. Prior to version 0.11.6, Airtable.js had a misconfigured build script in its source package. When the build script is run, it would bundle environment variables into the build target of a …
- CVE-2026-103097HIGHCVSS 7.5EG 7.52026-10-02
An API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may allow unauthorized users to extract and …
- CVE-2026-103096HIGHCVSS 7.5EG 7.52026-10-02
API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may allow unauthorized users to extract and mis…
- CVE-2026-59657HIGHCVSS 7.5EG 7.52026-08-21
Cleartext Storage of Sensitive Information vulnerability in Apache CloudStack with AsyncJob storage in the database. This issue affects Apache CloudStack: from 4.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommen…
- CVE-2026-13380HIGHCVSS 7.5EG 7.52026-07-20
VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthenticated endpoints. The credentials are present in these responses only when SFTP connections have been configured within…
- CVE-2026-6332HIGHCVSS 7.5EG 7.52026-05-14
CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that could cause the disclosure of a sensitive information which could result in revealing protected source code and loss of confidentiality, When an authorized atta…
- CVE-2026-42151HIGHCVSS 7.5EG 7.52026-05-04
Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of S…
- CVE-2026-6553HIGHCVSS 7.5EG 7.52026-04-21
Changing backend users' passwords via the user settings module results in storing the cleartext password in the uc and user_settings fields of the be_users database table. This issue affects TYPO3 CMS version 14.2.0.
- CVE-2026-34833HIGHCVSS 7.5EG 7.52026-04-02
Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to version 1.4.10, the GET /api/auth/session endpoint previously included the user's plaintext password in the JSON response. This exposed credentials to brows…
- CVE-2026-33867HIGHCVSS 7.5EG 7.52026-03-27
WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo allows content owners to password-protect individual videos. The video password is stored in the database in plaintext — no hashing, salting, or e…
- CVE-2026-33512HIGHCVSS 7.5EG 7.52026-03-23
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the API plugin exposes a `decryptString` action without any authentication. Anyone can submit ciphertext and receive plaintext. Ciphertext is issued public…
- CVE-2024-55027HIGHCVSS 7.5EG 7.52026-03-03
Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to stroe credentials in plaintext in the component uac_temp.db.
- CVE-2026-27520HIGHCVSS 7.5EG 7.52026-02-24
Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209 store a user password in a client-side cookie as a Base64-encoded value accessible via the web interface. Because Base64 is reversible and provides no confid…
- CVE-2026-25751HIGHCVSS 7.5EG 7.52026-02-06
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An information disclosure vulnerability in FUXA allows an unauthenticated, remote attacker to retrieve sensitive administrative database credentials. Exploitation al…
- CVE-2025-12774HIGHCVSS 7.5EG 7.52026-02-03
A vulnerability in the migration script for Brocade SANnav before 3.0 could allow the collection of database sql queries in the SANnav support save file. An attacker with access to Brocade SANnav supportsave file, could open the file and …
- CVE-2026-22240HIGHCVSS 7.5EG 7.52026-01-14
The vulnerability exists in BLUVOYIX due to an improper password storage implementation and subsequent exposure via unauthenticated APIs. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP…
- CVE-2020-36887HIGHCVSS 7.5EG 7.52025-12-10
SpinetiX Fusion Digital Signage 3.4.8 contains an unauthenticated information disclosure vulnerability in the database backup directory. Attackers can access the /content/files/backups/ endpoint to download sensitive backup files containin…
- CVE-2025-65320HIGHCVSS 7.5EG 7.52025-12-03
Abacre Restaurant Point of Sale (POS) up to 15.0.0.1656 are vulnerable to Cleartext Storage of Sensitive Information in Memory. The application leaves valid device-bound license keys in process memory during an activation attempt.
- CVE-2025-65278HIGHCVSS 7.5EG 7.52025-11-26
An issue was discovered in file users.json in GroceryMart commit 21934e6 (2020-10-23) allowing unauthenticated attackers to gain sensitive information including plaintext usernames and passwords.
- CVE-2025-25613HIGHCVSS 7.5EG 7.52025-11-20
FS Inc S3150-8T2F 8-Port Gigabit Ethernet L2+ Switch, 8 x Gigabit RJ45, with 2 x 1Gb SFP, Fanless. All versions before 2.2.0D Build 135103 were discovered to transmit cookies for their web based administrative application containing userna…
- CVE-2025-63208HIGHCVSS 7.5EG 7.52025-11-19
An issue was discovered in bridgetech VB288 Objective QoE Content Extractor, firmware version 5.6.0-8, allowing attackers to gain sensitive information such as administrator passwords via the /probe/core/setup/passwd endpoint.
- CVE-2025-59409HIGHCVSS 7.5EG 7.52025-10-02
Flock Safety Falcon and Sparrow License Plate Readers OPM1.171019.026 ship with development Wi-Fi credentials (test_flck) stored in cleartext in production firmware.
- CVE-2025-44649HIGHCVSS 7.5EG 7.52025-07-21
In the configuration file of racoon in the TRENDnet TEW-WLC100P 2.03b03, the first item of exchage_mode is set to aggressive. Aggressive mode in IKE Phase 1 exposes identity information in plaintext, is vulnerable to offline dictionary att…
- CVE-2025-45001HIGHCVSS 7.5EG 7.52025-06-09
react-native-keys 0.7.11 is vulnerable to sensitive information disclosure (remote) as encryption cipher and Base64 chunks are stored as plaintext in the compiled native binary. Attackers can extract these secrets using basic static analys…
- CVE-2025-44614HIGHCVSS 7.5EG 7.52025-05-30
Tinxy WiFi Lock Controller v1 RF was discovered to store users' sensitive information, including credentials and mobile phone numbers, in plaintext.
- CVE-2025-25758HIGHCVSS 7.5EG 7.52025-03-20
An issue in KukuFM Android v1.12.7 (11207) allows attackers to access sensitive cleartext data via the android:allowBackup="true" in the ANdroidManifest.xml
- CVE-2025-27685HIGHCVSS 7.5EG 7.52025-03-05
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Configuration File Contains CA & Private Key V-2022-001.
- CVE-2025-26495HIGHCVSS 7.5EG 7.52025-02-11
Cleartext Storage of Sensitive Information vulnerability in Salesforce Tableau Server can record the Personal Access Token (PAT) into logging repositories.This issue affects Tableau Server: before 2022.1.3, before 2021.4.8, before 2021.3.1…
- CVE-2024-55196HIGHCVSS 7.5EG 7.52024-12-19
Insufficiently Protected Credentials in the Mail Server Configuration in GoPhish v0.12.1 allows an attacker to access cleartext passwords for the configured IMAP and SMTP servers.
- CVE-2024-51175HIGHCVSS 7.5EG 7.52024-12-17
An issue in H3C switch h3c-S1526 allows a remote attacker to obtain sensitive information via the S1526.cfg component.
- CVE-2024-40582HIGHCVSS 7.5EG 7.52024-12-09
Pentaminds CuroVMS v2.0.1 was discovered to contain exposed sensitive information.
- CVE-2024-7783HIGHCVSS 7.5EG 7.52024-10-29
mintplex-labs/anything-llm version latest contains a vulnerability where sensitive information, specifically a password, is improperly stored within a JWT (JSON Web Token) used as a bearer token in single user mode. When decoded, the JWT r…
- CVE-2024-6400HIGHCVSS 7.5EG 7.52024-10-04
Cleartext Storage of Sensitive Information, Exposure of Sensitive Information Through Data Queries vulnerability in Finrota Netahsilat allows Retrieve Embedded Sensitive Data, Authentication Bypass, IMAP/SMTP Command Injection, Collect Dat…
- CVE-2024-8644HIGHCVSS 7.5EG 7.52024-09-27
Cleartext Storage of Sensitive Information in a Cookie vulnerability in Oceanic Software ValeApp allows Protocol Manipulation, : JSON Hijacking (aka JavaScript Hijacking). This issue affects ValeApp: before v2.0.0.
- CVE-2024-45862HIGHCVSS 7.5EG 7.52024-09-19
Kastle Systems firmware prior to May 1, 2024, stored machine credentials in cleartext, which may allow an attacker to access sensitive information.
- CVE-2024-45391HIGHCVSS 7.5EG 7.52024-09-03
Tina is an open-source content management system (CMS). Sites building with Tina CMS's command line interface (CLI) prior to version 1.6.2 that use a search token may be vulnerable to the search token being leaked via lock file (tina-lock.…
- CVE-2024-6921HIGHCVSS 7.5EG 7.52024-09-02
Cleartext Storage of Sensitive Information vulnerability in NAC Telecommunication Systems Inc. NACPremium allows Retrieve Embedded Sensitive Data. This issue affects NACPremium: through 01082024.
- CVE-2024-33892HIGHCVSS 7.5EG 7.52024-08-02
Insecure Permissions vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are susceptible to leaking information through cookies. This is fixed in version 21.2s10 and 22.1s3
- CVE-2019-16638HIGHCVSS 7.5EG 7.52024-07-16
An issue was found on the Ruijie EG-2000 series gateway. An attacker can easily dump cleartext stored passwords in /data/config.text with simple XORs. This affects EG-2000SE EG_RGOS 11.1(1)B1.
- CVE-2024-4540HIGHCVSS 7.5EG 7.52024-06-03
A flaw was found in Keycloak in OAuth 2.0 Pushed Authorization Requests (PAR). Client-provided parameters were found to be included in plain text in the KC_RESTART cookie returned by the authorization server's HTTP response to a `request_u…
- CVE-2024-3742HIGHCVSS 7.5EG 7.52024-04-18
Electrolink transmitters store credentials in clear-text. Use of these credentials could allow an attacker to access the system.
- CVE-2024-28387HIGHCVSS 7.5EG 7.52024-03-25
An issue in axonaut v.3.1.23 and before allows a remote attacker to obtain sensitive information via the log.txt component.
- CVE-2024-22084HIGHCVSS 7.5EG 7.52024-03-20
An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Cleartext passwords and hashes are exposed through log files.
- CVE-2023-49341HIGHCVSS 7.5EG 7.52024-03-09
An issue was discovered in Newland Nquire 1000 Interactive Kiosk version NQ1000-II_G_V1.00.011, allows remote attackers to obtain sensitive information via cleartext credential storage in backup.htm component.
- CVE-2024-24375HIGHCVSS 7.5EG 7.52024-03-07
SQL injection vulnerability in Jfinalcms v.5.0.0 allows a remote attacker to obtain sensitive information via /admin/admin name parameter.
- CVE-2023-6874HIGHCVSS 7.5EG 7.52024-02-05
Prior to v7.4.0, Ember ZNet is vulnerable to a denial of service attack through manipulation of the NWK sequence number
- CVE-2023-27098HIGHCVSS 7.5EG 7.52024-01-09
TP-Link Tapo APK up to v2.12.703 uses hardcoded credentials for access to the login panel.
- CVE-2023-6250HIGHCVSS 7.5EG 7.52023-12-26
The BestWebSoft's Like & Share WordPress plugin before 2.74 discloses the content of password protected posts to unauthenticated users via a meta tag
Map vulnerabilities like CWE-312 to your infrastructure
EchelonGraph correlates every CVE — across CWE-312 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →