CWE-312— Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.— MITRE CWE catalog
903 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-312page 8 of 19
- CVE-2025-7397HIGHCVSS 7.1EG 7.12025-07-17
A vulnerability in the ascgshell, of Brocade ASCG before 3.3.0 stores any command executed in the Command Line Interface (CLI) in plain text within the command history. A local authenticated user that can access sensitive information li…
- CVE-2025-46820HIGHCVSS 7.1EG 7.12025-05-06
phpgt/Dom provides access to modern DOM APIs. Versions of phpgt/Dom prior to 4.1.8 expose the GITHUB_TOKEN in the Dom workflow run artifact. The ci.yml workflow file uses actions/upload-artifact@v4 to upload the build artifact. This artifa…
- CVE-2025-3395HIGHCVSS 7.1EG 7.12025-04-30
Incorrect Permission Assignment for Critical Resource, Cleartext Storage of Sensitive Information vulnerability in ABB Automation Builder.This issue affects Automation Builder: through 2.8.0.
- CVE-2024-23942HIGHCVSS 7.1EG 7.12025-03-18
A local user may find a configuration file on the client workstation with unencrypted sensitive data. This allows an attacker to impersonate the device or prevent the device from accessing the cloud portal which leads to a DoS.
- CVE-2024-56362HIGHCVSS 7.1EG 7.12024-12-23
Navidrome is an open source web-based music collection server and streamer. Navidrome stores the JWT secret in plaintext in the navidrome.db database file under the property table. This practice introduces a security risk because anyone wi…
- CVE-2023-27706HIGHCVSS 7.1EG 7.12023-06-09
Bitwarden Windows desktop application versions prior to v2023.4.0 store biometric keys in Windows Credential Manager, accessible to other local unprivileged processes.
- CVE-2022-34388HIGHCVSS 7.1EG 7.12023-02-11
Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain information disclosure vulnerability. A local malicious user with low privileges could exploit this vulnerab…
- CVE-2022-2513HIGHCVSS 7.1EG 7.12022-11-22
A vulnerability exists in the Intelligent Electronic Device (IED) Connectivity Package (ConnPack) credential storage function in Hitachi Energy’s PCM600 product included in the versions listed below, where IEDs credentials are stored in …
- CVE-2025-21061HIGHCVSS 5.5EG 7.12025-10-10
Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access sensitive data. User interaction is required for triggering this vulnerability.
- CVE-2025-59105HIGHCVSS 7.0EG 7.02026-01-26
With physical access to the device and enough time an attacker can desolder the flash memory, modify it and then reinstall it because of missing encryption. Thus, essential files, such as "/etc/passwd", as well as stored certificates, cryp…
- CVE-2025-54464HIGHCVSS 7.0EG 7.02025-08-13
This vulnerability exists in ZKTeco WL20 due to storage of admin and user credentials without encryption in the device firmware. An attacker with physical access could exploit this vulnerability by extracting the firmware and reverse engin…
- CVE-2024-9991HIGHCVSS 7.0EG 7.02024-10-25
This vulnerability exists in Philips lighting devices due to storage of Wi-Fi credentials in plain text within the device firmware. An attacker with physical access could exploit this by extracting the firmware and analyzing the binary dat…
- CVE-2026-63207MEDIUMCVSS 6.9EG 6.92026-09-25
Zammad is a web based open source helpdesk/customer support system. In 7.0.3 and 7.1.1, an authenticated administrator can obtain stored integration credentials in cleartext through the integration administration API. Certain responses do …
- CVE-2026-86443MEDIUMCVSS 6.9EG 6.92026-09-16
Cleartext storage of sensitive information in the DuoxMe application for Android, in versions prior to 4.3.4, allows an attacker with local access to the device to retrieve the credentials stored by the application and impersonate the user…
- CVE-2024-9432MEDIUMCVSS 6.9EG 6.92026-01-30
Cleartext Storage of Sensitive Information vulnerability in OpenText™ Vertica allows Retrieve Embedded Sensitive Data. The vulnerability could read Vertica agent plaintext apikey.This issue affects Vertica versions: 23.X, 24.X, 25.X.
- CVE-2025-59102MEDIUMCVSS 6.9EG 6.92026-01-26
The web server of the Access Manager offers a functionality to download a backup of the local database stored on the device. This database contains the whole configuration. This includes encrypted MIFARE keys, card data, user PINs and much…
- CVE-2025-57806MEDIUMCVSS 6.9EG 6.92025-09-03
Local Deep Research is an AI-powered research assistant for deep, iterative research. Versions 0.2.0 through 0.6.7 stored confidential information, including API keys, in a local SQLite database without encryption. This behavior was not cl…
- CVE-2025-2909MEDIUMCVSS 6.9EG 6.92025-03-28
The lack of encryption in the DuoxMe (formerly Blue) application binary in versions prior to 3.3.1 for iOS devices allows an attacker to gain unauthorised access to the application code and discover sensitive information.
- CVE-2020-15085MEDIUMCVSS 6.9EG 6.92020-06-30
In Saleor Storefront before version 2.10.3, request data used to authenticate customers was inadvertently cached in the browser's local storage mechanism, including credentials. A malicious user with direct access to the browser could extr…
- CVE-2026-55885MEDIUMCVSS 6.8EG 6.82026-06-18
Grav is a file-based Web platform. Prior to 1.7.53, an authenticated administrator with backup permissions can download a ZIP archive containing the full Grav installation root, including user/accounts/admin.yaml with the administrator pas…
- CVE-2026-4346MEDIUMCVSS 6.8EG 6.82026-03-26
The vulnerability affecting TL-WR850N v3 allows cleartext storage of administrative and Wi-Fi credentials in a region of the device’s flash memory while the serial interface remains enabled and protected by weak authentication. An attac…
- CVE-2025-58401MEDIUMCVSS 6.8EG 6.82025-09-05
Obsidian GitHub Copilot Plugin versions prior to 1.1.7 store Github API token in cleartext form. As a result, an attacker may perform unauthorized operations on the linked Github account.
- CVE-2025-4394MEDIUMCVSS 6.8EG 6.82025-07-24
Medtronic MyCareLink Patient Monitor uses an unencrypted filesystem on internal storage, which allows an attacker with physical access to read and modify files. This issue affects MyCareLink Patient Monitor models 24950 and 24952: before…
- CVE-2025-4053MEDIUMCVSS 6.8EG 6.82025-05-26
The data stored in Be-Tech Mifare Classic card is stored in cleartext. An attacker having access to a Be-Tech hotel guest Mifare Classic card can create a master key card that unlocks all the locks in the building. This issue affect…
- CVE-2024-34891MEDIUMCVSS 6.8EG 6.82024-11-04
Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to read Exchange account passwords via HTTP GET request.
- CVE-2022-24410MEDIUMCVSS 6.8EG 6.82023-02-10
Dell BIOS contains an information exposure vulnerability. An unauthenticated local attacker with physical access to the system and knowledge of the system configuration could potentially exploit this vulnerability to read system informati…
- CVE-2021-22206MEDIUMCVSS 6.8EG 6.82021-05-06
An issue has been discovered in GitLab affecting all versions starting from 11.6. Pull mirror credentials are exposed that allows other maintainers to be able to view the credentials in plain-text,
- CVE-2020-35454MEDIUMCVSS 6.8EG 6.82021-03-17
The Taidii Diibear Android application 2.4.0 and all its derivatives allow attackers to obtain user credentials from an Android backup because of insecure application configuration.
- CVE-2018-20008MEDIUMCVSS 6.8EG 6.82019-05-28
iBall Baton iB-WRB302N20122017 devices have improper access control over the UART interface, allowing physical attackers to discover Wi-Fi credentials (plain text) and the web-console password (base64) via the debugging console.
- CVE-2024-55928MEDIUMCVSS 6.5EG 6.82025-01-23
Xerox Workplace Suite exposes sensitive secrets in clear text, both locally and remotely. This vulnerability allows attackers to intercept or access secrets without encryption
- CVE-2023-41096MEDIUMCVSS 6.1EG 6.82023-10-26
Missing Encryption of Security Keys vulnerability in Silicon Labs Ember ZNet SDK on 32 bit, ARM (SecureVault High modules) allows potential modification or extraction of network credentials stored in flash. This issue affects Silicon La…
- CVE-2026-66016MEDIUMCVSS 6.7EG 6.72026-08-12
Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessible to highly privileged local users.
- CVE-2026-8804MEDIUMCVSS 6.7EG 6.72026-07-03
Puppet resource_api (shipped in Puppet Core 8.x and Puppet Enterprise 2023.8.x and 2025.x) does not preserve the sensitive flag on parameters defined via the resource-api, causing values such as passwords to be stored in cleartext in the a…
- CVE-2025-48428MEDIUMCVSS 6.7EG 6.72025-10-23
Cleartext Storage of Sensitive Information (CWE-312) in the Gallagher Morpho integration could allow an authenticated user with access to the Command Centre Server to export a specific signing key while in use allowing them to deploy a com…
- CVE-2017-2723MEDIUMCVSS 6.7EG 6.72017-11-22
The Files APP 7.1.1.308 and earlier versions in some Huawei mobile phones has a vulnerability of plaintext storage of users' Safe passwords. An attacker with the root privilege of an Android system could forge the Safe to read users' plain…
- CVE-2018-1621MEDIUMCVSS 4.4EG 6.72018-07-06
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local attacker to obtain clear text password in a trace file caused by improper handling of some datasource custom properties. IBM X-Force ID: 144346.
- CVE-2024-28810MEDIUMCVSS 6.6EG 6.62024-09-30
An issue was discovered in Infinera hiT 7300 5.60.50. Sensitive information inside diagnostic files (exported by the @CT application) allows an attacker to achieve loss of confidentiality by analyzing these files.
- CVE-2024-23584MEDIUMCVSS 6.6EG 6.62024-04-08
The NMAP Importer service may expose data store credentials to authorized users of the Windows Registry.
- CVE-2021-32942MEDIUMCVSS 6.6EG 6.62021-06-09
The vulnerability could expose cleartext credentials from AVEVA InTouch Runtime 2020 R2 and all prior versions (WindowViewer) if an authorized, privileged user creates a diagnostic memory dump of the process and saves it to a non-protected…
- CVE-2020-10706MEDIUMCVSS 6.3EG 6.62020-05-12
A flaw was found in OpenShift Container Platform where OAuth tokens are not encrypted when the encryption of data at rest is enabled. This flaw allows an attacker with access to a backup to obtain OAuth tokens and then use them to log into…
- CVE-2024-41629MEDIUMCVSS 5.5EG 6.62024-09-12
An issue in Texas Instruments Fusion Digital Power Designer v.7.10.1 allows a local attacker to obtain sensitive information via the plaintext storage of credentials
- CVE-2026-108728MEDIUMCVSS 6.5EG 6.52026-10-11
Flyte 2.0.1 through 2.0.51 contains a cleartext secret storage vulnerability that allows users with Pod read access to obtain secrets by reading init container environment variables. The embedded secret manager webhook writes base64-encode…
- CVE-2026-93763MEDIUMCVSS 6.5EG 6.52026-09-18
A protection mechanism failure in the object-document mapper's encryption configuration generation can cause fields that an application declared for client-side field-level encryption to be written and kept in cleartext, without any error …
- CVE-2026-93764MEDIUMCVSS 6.5EG 6.52026-09-18
Mongoid may omit encryption rules for fields declared on embedded models when generating the client-side field-level encryption schema. Applications that enable this feature can therefore store values intended to be encrypted in readable f…
- CVE-2026-77975MEDIUMCVSS 6.5EG 6.52026-08-31
The affected Ebyte product exports administrative credentials and other sensitive configuration information without adequate protection. An unauthenticated attacker on the adjacent network who can obtain an exported configuration file…
- CVE-2026-59244MEDIUMCVSS 6.5EG 6.52026-08-12
Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates UI — the dict value failed an `isinstance(str)` guard — so a secret stored as a JSON Variable and referenced in a t…
- CVE-2026-68970MEDIUMCVSS 6.5EG 6.52026-08-12
Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in cleartext in task logs and in the Rendered Templates UI. Masking was applied only when the deserializ…
- CVE-2026-19391MEDIUMCVSS 6.5EG 6.52026-08-11
A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the literal string 'password'. This allows SSSD LDAP bind passwords (ldap_default_authtok) and Pacemaker fence device crede…
- CVE-2026-21080MEDIUMCVSS 6.5EG 6.52026-08-10
Cleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.
- CVE-2026-16802MEDIUMCVSS 6.5EG 6.52026-07-24
Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local actor with file system access to read secret values via secret variables stored in cleartext on dis…
Map vulnerabilities like CWE-312 to your infrastructure
EchelonGraph correlates every CVE — across CWE-312 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →