CWE-312— Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.— MITRE CWE catalog
902 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-312page 7 of 19
- CVE-2019-10099HIGHCVSS 7.5EG 7.52019-08-07
Prior to Spark 2.3.3, in certain situations Spark would write user data to local disk unencrypted, even if spark.io.encryption.enabled=true. This includes cached blocks that are fetched to disk (controlled by spark.maxRemoteBlockSizeFetchT…
- CVE-2015-1012HIGHCVSS 7.5EG 7.52019-03-25
Wireless keys are stored in plain text on version 5 of the Hospira LifeCare PCA Infusion System. According to Hospira, version 3 of the LifeCare PCA Infusion System is not indicated for wireless use, is not shipped with wireless capabiliti…
- CVE-2015-3952HIGHCVSS 7.5EG 7.52019-03-25
Wireless keys are stored in plain text on Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior. Hospira recommends that customers close …
- CVE-2018-9065HIGHCVSS 7.5EG 7.52018-07-30
In Lenovo xClarity Administrator versions earlier than 2.1.0, an attacker that gains access to the underlying LXCA file system user may be able to retrieve a credential store containing the service processor user names and passwords for se…
- CVE-2018-8947HIGHCVSS 7.5EG 7.52018-03-25
rap2hpoutre Laravel Log Viewer before v0.13.0 relies on Base64 encoding for l, dl, and del requests, which makes it easier for remote attackers to bypass intended access restrictions, as demonstrated by reading arbitrary files via a dl req…
- CVE-2017-16835HIGHCVSS 7.5EG 7.52018-02-20
The "Photo,Video Locker-Calculator" application 12.0 for Android has android:allowBackup="true" in AndroidManifest.xml, which allows attackers to obtain sensitive cleartext information via an "adb backup '-f smart.calculator.gallerylock'" …
- CVE-2018-0089HIGHCVSS 7.5EG 7.52018-01-18
A vulnerability in the Policy and Charging Rules Function (PCRF) of the Cisco Policy Suite (CPS) could allow an unauthenticated, remote attacker to access sensitive data. The attacker could use this information to conduct additional reconn…
- CVE-2017-9663HIGHCVSS 7.5EG 7.52018-01-09
An Cleartext Storage of Sensitive Information issue was discovered in General Motors (GM) and Shanghai OnStar (SOS) SOS iOS Client 7.1. Successful exploitation of this vulnerability may allow a remote attacker to access an encryption key t…
- CVE-2017-13663HIGHCVSS 7.5EG 7.52017-12-01
Encryption key exposure in firmware in iSmartAlarm CubeOne version 2.2.4.8 and earlier allows attackers to decrypt log files via an exposed key.
- CVE-2017-3214HIGHCVSS 7.5EG 7.52017-06-20
The Milwaukee ONE-KEY Android mobile application stores the master token in plaintext in the apk binary.
- CVE-2016-0876HIGHCVSS 7.5EG 7.52016-05-31
Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to discover cleartext passwords by reading a configuration file.
- CVE-2009-2272HIGHCVSS 7.5EG 7.52009-07-01
The Huawei D100 stores the administrator's account name and password in cleartext in a cookie, which allows context-dependent attackers to obtain sensitive information by (1) reading a cookie file, by (2) sniffing the network for HTTP head…
- CVE-2009-0152HIGHCVSS 7.5EG 7.52009-05-13
iChat in Apple Mac OS X 10.5 before 10.5.7 disables SSL for AOL Instant Messenger (AIM) communication in certain circumstances that are inconsistent with the Require SSL setting, which allows remote attackers to obtain sensitive informatio…
- CVE-2009-1603HIGHCVSS 7.5EG 7.52009-05-11
src/tools/pkcs11-tool.c in pkcs11-tool in OpenSC 0.11.7, when used with unspecified third-party PKCS#11 modules, generates RSA keys with incorrect public exponents, which allows attackers to read the cleartext form of messages that were in…
- CVE-2009-0964HIGHCVSS 7.5EG 7.52009-03-19
UserView_list.php in PHPRunner 4.2, and possibly earlier, stores passwords in cleartext in the database, which allows attackers to gain privileges. NOTE: this can be leveraged with a separate SQL injection vulnerability to obtain password…
- CVE-2008-6157HIGHCVSS 7.5EG 7.52009-02-17
SepCity Classified Ads stores the admin password in cleartext in data/classifieds.mdb, which allows context-dependent attackers to obtain sensitive information.
- CVE-2007-5778HIGHCVSS 7.5EG 7.52007-11-01
Mobile Spy (1) stores login credentials in cleartext under the RetinaxStudios registry key, and (2) sends login credentials and log data over a cleartext HTTP connection, which allows attackers to obtain sensitive information by reading th…
- CVE-2005-2160HIGHCVSS 7.5EG 7.52005-07-06
IMail stores usernames and passwords in cleartext in a cookie, which allows remote attackers to obtain sensitive information.
- CVE-2005-1828HIGHCVSS 7.5EG 7.52005-05-26
D-Link DSL-504T stores usernames and passwords in cleartext in the router configuration file, which allows remote attackers to obtain sensitive information.
- CVE-2004-2397HIGHCVSS 7.5EG 7.52004-12-31
The web-based Management Console in Blue Coat Security Gateway OS 3.0 through 3.1.3.13 and 3.2.1, when importing a private key, stores the key and its passphrase in plaintext in a log file, which allows attackers to steal digital certifica…
- CVE-2002-1800HIGHCVSS 7.5EG 7.52002-12-31
phpRank 1.8 stores the administrative password in plaintext on the server and in the "ap" cookie, which allows remote attackers to retrieve the administrative password.
- CVE-2001-1536HIGHCVSS 7.5EG 7.52001-12-31
Autogalaxy stores usernames and passwords in cleartext in cookies, which makes it easier for remote attackers to obtain authentication information and gain unauthorized access via sniffing or a cross-site scripting attack.
- CVE-2001-1537HIGHCVSS 7.5EG 7.52001-12-31
The default "basic" security setting' in config.php for TWIG webmail 2.7.4 and earlier stores cleartext usernames and passwords in cookies, which could allow attackers to obtain authentication information and gain privileges.
- CVE-2022-29826HIGHCVSS 6.8EG 7.52022-11-25
Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.087R and Motion Control Setting(GX Works3 related software) versions from 1.000A to 1.042U allows a remote unauthenticated …
- CVE-2022-30626HIGHCVSS 6.3EG 7.52022-07-18
Browsing the path: http://ip/wifi_ap_pata_get.cmd, will show in the name of the existing access point on the component, and a password in clear text.
- CVE-2022-34351HIGHCVSS 5.9EG 7.52023-02-17
IBM QRadar SIEM 7.4 and 7.5 is vulnerable to information exposure allowing a non-tenant user with a specific domain security profile assigned to see some data from other domains. IBM X-Force ID: 230402.
- CVE-2018-16889HIGHCVSS 5.5EG 7.52019-01-28
Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files via plaintext. Versions up to v13.2.4 are vulnerable.
- CVE-2022-41734HIGHCVSS 5.3EG 7.52023-02-17
IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against th…
- CVE-2022-2739HIGHCVSS 5.3EG 7.52022-09-01
The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing the fix for CVE-2020-14370, which was previously fixed via RHSA-2020:5056. This issue could…
- CVE-2021-20407HIGHCVSS 5.3EG 7.52021-02-12
IBM Security Verify Information Queue 1.0.6 and 1.0.7 discloses sensitive information in source code that could be used in further attacks against the system. IBM X-Force ID: 196185.
- CVE-2023-1683HIGHCVSS 4.3EG 7.52023-03-29
A vulnerability was found in Xunrui CMS 4.61 and classified as problematic. Affected by this issue is some unknown functionality of the file /dayrui/Fcms/View/system_log.html. The manipulation leads to information disclosure. The attack ma…
- CVE-2022-2813HIGHCVSS 4.3EG 7.52022-08-15
A vulnerability, which was classified as problematic, was found in SourceCodester Guest Management System. Affected is an unknown function. The manipulation leads to cleartext storage of passwords in the database. The identifier of this vu…
- CVE-2024-32474HIGHCVSS 7.3EG 7.32024-04-18
Sentry is an error tracking and performance monitoring platform. Prior to 24.4.1, when authenticating as a superuser to Sentry with a username and password, the password is leaked as cleartext in logs under the _event_: `auth-index.validat…
- CVE-2021-41302HIGHCVSS 7.3EG 7.32021-09-30
ECOA BAS controller stores sensitive data (backup exports) in clear-text, thus the unauthenticated attacker can remotely query user password and obtain user’s privilege.
- CVE-2021-23878HIGHCVSS 7.3EG 7.32021-02-10
Clear text storage of sensitive Information in memory vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update allows a local user to view ENS settings and credentials via accessing process memory af…
- CVE-2016-8366HIGHCVSS 7.3EG 7.32018-04-05
Webvisit in Phoenix Contact ILC PLCs offers a password macro to protect HMI pages on the PLC against casual or coincidental opening of HMI pages by the user. The password macro can be configured in a way that the password is stored and tra…
- CVE-2024-12604HIGHCVSS 6.5EG 7.32025-03-10
Cleartext Storage of Sensitive Information in an Environment Variable, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Tapandsign Technologies Tap&Sign App allows Password Recovery Exploitation, Functionality Misus…
- CVE-2026-100288HIGHCVSS 7.2EG 7.22026-09-29
Cleartext storage of sensitive information in the database in Devolutions Server 2026.3.5.0 and earlier allows an attacker with read access to the database to obtain external identity provider tokens and active session identifiers via dir…
- CVE-2026-83551HIGHCVSS 7.2EG 7.22026-09-01
Cleartext storage of sensitive information in the @step and @remote decorator pipeline component in Amazon SageMaker Python SDK before v3.11.0 and v2.256.0 might allow an authenticated remote user to extract the HMAC signing key from SageM…
- CVE-2026-8596HIGHCVSS 7.2EG 7.22026-05-14
Cleartext storage of sensitive information in the ModelBuilder/Serve component in Amazon SageMaker Python SDK before v2.257.2 and v3 before v3.8.0 might allow a remote authenticated actor to extract the HMAC signing key from SageMaker API …
- CVE-2024-8459HIGHCVSS 7.2EG 7.22024-09-30
Certain switch models from PLANET Technology store SNMPv3 users' passwords in plaintext within the configuration files, allowing remote attackers with administrator privileges to read the file and obtain the credentials.
- CVE-2024-33471HIGHCVSS 7.2EG 7.22024-05-24
An issue in the Sensor Settings of AVTECH Room Alert 4E v4.4.0 allows attackers to gain access to SMTP credentials in plaintext via a crafted AJAX request. NOTE: This vulnerability only affects products that are no longer supported by the …
- CVE-2020-29001HIGHCVSS 7.2EG 7.22021-01-26
An issue was discovered on Geeni GNC-CW028 Camera 2.7.2, Geeni GNC-CW025 Doorbell 2.9.5, Merkury MI-CW024 Doorbell 2.9.6, and Merkury MI-CW017 Camera 2.9.6 devices. A vulnerability exists in the RESTful Services API that allows a remote at…
- CVE-2009-5068HIGHCVSS 7.2EG 7.22020-01-15
There is a file disclosure vulnerability in SMF (Simple Machines Forum) affecting versions through v2.0.3. On some configurations a SMF deployment is shared by several "co-admins" that are not trusted beyond the SMF deployment. This vulner…
- CVE-2018-19981HIGHCVSS 7.2EG 7.22019-04-04
Amazon AWS SDK <=2.8.5 for Android uses Android SharedPreferences to store plain text AWS STS Temporary Credentials retrieved by AWS Cognito Identity Service. An attacker can use these credentials to create authenticated and/or authorized …
- CVE-2019-6549HIGHCVSS 7.2EG 7.22019-02-12
An attacker could retrieve plain-text credentials stored in a XML file on PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166) through FTP.
- CVE-2018-10871HIGHCVSS 3.8EG 7.22018-07-18
389-ds-base before versions 1.3.8.5, 1.4.0.12 is vulnerable to a Cleartext Storage of Sensitive Information. By default, when the Replica and/or retroChangeLog plugins are enabled, 389-ds-base stores passwords in plaintext format in their …
- CVE-2026-4130HIGHCVSS 7.1EG 7.12026-09-10
There is a storage of sensitive information in cleartext vulnerability in NI SystemLink. This vulnerability may allow an attacker with local access to obtain sensitive information stored by the system in the clear. This vulnerability aff…
- CVE-2026-53603HIGHCVSS 7.1EG 7.12026-07-14
nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.8, Operator session tokens are stored in plaintext in the operator_sessions table (the token column is the PRIMARY KEY). The session token is a 32-b…
- CVE-2026-36176HIGHCVSS 7.1EG 7.12026-06-04
GNCC GP5 v7.1.76 was discovered to store pre-signed Backblaze B2 upload URLs (PUT requests) in plaintext to the serial console. This allows physically-proximate attackers to extract these active tokens to perform unauthorized operations vi…
Map vulnerabilities like CWE-312 to your infrastructure
EchelonGraph correlates every CVE — across CWE-312 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →