CWE-312— Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.— MITRE CWE catalog
903 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-312page 9 of 19
- CVE-2026-65599MEDIUMCVSS 6.5EG 6.52026-07-22
n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a credential exposure vulnerability: when configured with a Google Service Account key, the full PEM private key was mistakenly placed in the JWT header's kid field (intended only fo…
- CVE-2026-10786MEDIUMCVSS 6.5EG 6.52026-06-08
Improper access control in the ticketing integration settings in Devolutions Server allows an authenticated low-privileged user to obtain cleartext credentials for configured ticketing integrations via a crafted API request. This issue af…
- CVE-2026-41385MEDIUMCVSS 6.5EG 6.52026-04-28
OpenClaw before 2026.3.31 stores Nostr privateKey as plaintext in configuration, allowing exposure through config.get method calls that bypass redaction mechanisms. Attackers can retrieve unredacted configuration data to obtain plaintext s…
- CVE-2026-35644MEDIUMCVSS 6.5EG 6.52026-04-09
OpenClaw before 2026.3.22 contains an information disclosure vulnerability that allows attackers with operator.read scope to expose credentials embedded in channel baseUrl and httpUrl fields. Attackers can access gateway snapshots via conf…
- CVE-2026-39943MEDIUMCVSS 6.5EG 6.52026-04-09
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus stores revision records (in directus_revisions) whenever items are created or updated. Due to the revision snapshot code not consis…
- CVE-2026-34214MEDIUMCVSS 6.5EG 6.52026-03-31
Trino is a distributed SQL query engine for big data analytics. From version 439 to before version 480, Iceberg connector REST catalog static credentials (access key) or vended credentials (temporary access key) are accessible to users tha…
- CVE-2026-27877MEDIUMCVSS 6.5EG 6.52026-03-27
When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being used in dashboards. No passwords of proxied data-sources are exposed. We encourage all direct data-sources to be conver…
- CVE-2026-32842MEDIUMCVSS 6.5EG 6.52026-03-17
Edimax GS-5008PL firmware version 1.00.54 and prior contain an insecure credential storage vulnerability that allows attackers to obtain administrator credentials by accessing configuration backup files. Attackers can download the config.b…
- CVE-2025-70050MEDIUMCVSS 6.5EG 6.52026-03-09
An issue pertaining to CWE-312: Cleartext Storage of Sensitive Information was discovered in lesspass lesspass v9.6.9 which allows attackers to obtain sensitive information.
- CVE-2026-3277MEDIUMCVSS 6.5EG 6.52026-02-27
The OpenID Connect (OIDC) authentication configuration in PowerShell Universal before 2026.1.3 stores the OIDC client secret in cleartext in the .universal/authentication.ps1 script, which allows an attacker with read access to that file…
- CVE-2026-23655MEDIUMCVSS 6.5EG 6.52026-02-10
Cleartext storage of sensitive information in Azure Compute Gallery allows an authorized attacker to disclose information over a network.
- CVE-2025-10464MEDIUMCVSS 6.5EG 6.52026-02-09
Insecure Storage of Sensitive Information vulnerability in Birtech Information Technologies Industry and Trade Ltd. Co. Senseway allows Retrieve Embedded Sensitive Data. This issue affects Senseway: through 09022026. NOTE: Because the …
- CVE-2025-12679MEDIUMCVSS 6.5EG 6.52026-02-02
A vulnerability in Brocade SANnav before 2.4.0b prints the Password-Based Encryption (PBE) key in plaintext in the system audit log file. The vulnerability could allow a remote authenticated attacker with access to the audit logs to acc…
- CVE-2025-62261MEDIUMCVSS 6.5EG 6.52025-10-27
Liferay Portal 7.4.0 through 7.4.3.99, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 34, and older unsupported versions stores password reset tokens in plain te…
- CVE-2025-53742MEDIUMCVSS 6.5EG 6.52025-07-09
Jenkins Applitools Eyes Plugin 1.16.5 and earlier stores Applitools API keys unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins contr…
- CVE-2025-53672MEDIUMCVSS 6.5EG 6.52025-07-09
Jenkins Kryptowire Plugin 0.2 and earlier stores the Kryptowire API key unencrypted in its global configuration file on the Jenkins controller, where it can be viewed by users with access to the Jenkins controller file system.
- CVE-2025-53670MEDIUMCVSS 6.5EG 6.52025-07-09
Jenkins Nouvola DiveCloud Plugin 1.08 and earlier stores DiveCloud API Keys and Credentials Encryption Keys unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission…
- CVE-2025-6224MEDIUMCVSS 6.5EG 6.52025-07-01
Certificate generation in juju/utils using the cert.NewLeaf function could include private information. If this certificate were then transferred over the network in plaintext, an attacker listening on that network could sniff the certific…
- CVE-2025-1499MEDIUMCVSS 6.5EG 6.52025-06-01
IBM InfoSphere Information Server 11.7 stores credential information for database authentication in a cleartext parameter file that could be viewed by an authenticated user.
- CVE-2025-27532MEDIUMCVSS 6.5EG 6.52025-04-30
A vulnerability in the “Backup & Restore” functionality of the web application of ctrlX OS allows a remote authenticated (lowprivileged) attacker to access secret information via multiple crafted HTTP requests.
- CVE-2025-2770MEDIUMCVSS 6.5EG 6.52025-04-23
BEC Technologies Multiple Routers Cleartext Password Storage Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of BEC Technologies routers. Authenti…
- CVE-2024-9466MEDIUMCVSS 6.5EG 6.52024-10-09
A cleartext storage of sensitive information vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to reveal firewall usernames, passwords, and API keys generated using those credentials.
- CVE-2024-47529MEDIUMCVSS 6.5EG 6.52024-10-02
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. OpenC3 COSMOS stores the password of a user unencrypted in the LocalStorage of a web browser. This makes the user passw…
- CVE-2024-25658MEDIUMCVSS 6.5EG 6.52024-10-01
Cleartext storage of passwords in Infinera TNMS (Transcend Network Management System) Server 19.10.3 allows attackers (with access to the database or exported configuration files) to obtain SNMP users' usernames and passwords in cleartext.
- CVE-2024-28807MEDIUMCVSS 6.5EG 6.52024-09-30
An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive information in the memory of the @CT desktop management application allows guest OS administrators to obtain various users' passwords by accessing memory …
- CVE-2024-31840MEDIUMCVSS 6.5EG 6.52024-05-21
An issue was discovered in Italtel Embrace 1.6.4. The web application inserts cleartext passwords in the HTML source code. An authenticated user is able to edit the configuration of the email server. Once the user access the edit function,…
- CVE-2024-31587MEDIUMCVSS 6.5EG 6.52024-04-19
SecuSTATION Camera V2.5.5.3116-S50-SMA-B20160811A and lower allows an unauthenticated attacker to download device configuration files via a crafted request.
- CVE-2024-29956MEDIUMCVSS 6.5EG 6.52024-04-18
A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints the Brocade SANnav password in clear text in supportsave logs when a user schedules a switch Supportsave from Brocade SANnav.
- CVE-2023-51702MEDIUMCVSS 6.5EG 6.52024-01-24
Since version 5.2.0, when using deferrable mode with the path of a Kubernetes configuration file for authentication, the Airflow worker serializes this configuration file as a dictionary and sends it to the triggerer by storing it in metad…
- CVE-2023-50294MEDIUMCVSS 6.5EG 6.52023-12-26
The App Settings (/admin/app) page in GROWI versions prior to v6.0.6 stores sensitive information in cleartext form. As a result, the Secret access key for external service may be obtained by an attacker who can access the App Settings pag…
- CVE-2023-48707MEDIUMCVSS 6.5EG 6.52023-11-24
CodeIgniter Shield is an authentication and authorization provider for CodeIgniter 4. The `secretKey` value is an important key for HMAC SHA256 authentication and in affected versions was stored in the database in cleartext form. If a mali…
- CVE-2023-47312MEDIUMCVSS 6.5EG 6.52023-11-22
Headwind MDM Web panel 5.22.1 is vulnerable to Incorrect Access Control due to Login Credential Leakage via Audit Entries.
- CVE-2023-48700MEDIUMCVSS 6.5EG 6.52023-11-21
The Nautobot Device Onboarding plugin uses the netmiko and NAPALM libraries to simplify the onboarding process of a new device into Nautobot down to, in many cases, an IP Address and a Location. Starting in version 2.0.0 and prior to versi…
- CVE-2023-46653MEDIUMCVSS 6.5EG 6.52023-10-25
Jenkins lambdatest-automation Plugin 1.20.10 and earlier logs LAMBDATEST Credentials access token at the INFO level, potentially resulting in its exposure.
- CVE-2023-46128MEDIUMCVSS 6.5EG 6.52023-10-25
Nautobot is a Network Automation Platform built as a web application atop the Django Python framework with a PostgreSQL or MySQL database. In Nautobot 2.0.x, certain REST API endpoints, in combination with the `?depth=<N>` query parameter,…
- CVE-2023-41964MEDIUMCVSS 6.5EG 6.52023-10-10
The BIG-IP and BIG-IQ systems do not encrypt some sensitive information written to Database (DB) variables. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
- CVE-2023-4400MEDIUMCVSS 6.5EG 6.52023-09-13
A password management vulnerability in Skyhigh Secure Web Gateway (SWG) in main releases 11.x prior to 11.2.14, 10.x prior to 10.2.25 and controlled release 12.x prior to 12.2.1, allows some authentication information stored in configurat…
- CVE-2023-40354MEDIUMCVSS 6.5EG 6.52023-08-14
An issue was discovered in MariaDB MaxScale before 23.02.3. A user enters an encrypted password on a "maxctrl create service" command line, but this password is then stored in cleartext in the resulting .cnf file under /var/lib/maxscale/ma…
- CVE-2023-36136MEDIUMCVSS 6.5EG 6.52023-08-08
PHPJabbers Class Scheduling System 1.0 lacks encryption on the password when editing a user account (update user page) allowing an attacker to capture all user names and passwords in clear text.
- CVE-2023-3395MEDIUMCVSS 6.5EG 6.52023-07-03
All versions of the TWinSoft Configuration Tool store encrypted passwords as plaintext in memory. An attacker with access to system files could open a file to load the document into memory, including sensitive information associated wi…
- CVE-2023-24586MEDIUMCVSS 6.5EG 6.52023-05-10
Cleartext storage of sensitive information exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier, which may allow a remote authenticated attacker to obtain an APN credential for the product.
- CVE-2023-2335MEDIUMCVSS 6.5EG 6.52023-04-27
Plaintext Password in Registry vulnerability in 42gears surelock windows surelockwinsetupv2.40.0.Exe on Windows (Registery modules) allows Retrieve Admin user credentials This issue affects surelock windows: from 2.3.12 through 2.40.…
- CVE-2023-30531MEDIUMCVSS 6.5EG 6.52023-04-12
Jenkins Consul KV Builder Plugin 2.0.13 and earlier does not mask the HashiCorp Consul ACL Token on the global configuration form, increasing the potential for attackers to observe and capture it.
- CVE-2023-30528MEDIUMCVSS 6.5EG 6.52023-04-12
Jenkins WSO2 Oauth Plugin 1.0 and earlier does not mask the WSO2 Oauth client secret on the global configuration form, increasing the potential for attackers to observe and capture it.
- CVE-2023-0614MEDIUMCVSS 6.5EG 6.52023-04-03
The fix in 4.6.16, 4.7.9, 4.8.4 and 4.9.7 for CVE-2018-10919 Confidential attribute disclosure vi LDAP filters was insufficient and an attacker may be able to obtain confidential BitLocker recovery keys from a Samba AD DC.
- CVE-2022-31405MEDIUMCVSS 6.5EG 6.52023-02-27
MV iDigital Clinic Enterprise (iDCE) 1.0 stores passwords in cleartext.
- CVE-2022-45897MEDIUMCVSS 6.5EG 6.52023-01-31
On Xerox WorkCentre 3550 25.003.03.000 devices, an authenticated attacker can view the SMB server settings and can obtain the stored cleartext credentials associated with those settings.
- CVE-2023-22332MEDIUMCVSS 6.5EG 6.52023-01-30
Information disclosure vulnerability exists in Pgpool-II 4.4.0 to 4.4.1 (4.4 series), 4.3.0 to 4.3.4 (4.3 series), 4.2.0 to 4.2.11 (4.2 series), 4.1.0 to 4.1.14 (4.1 series), 4.0.0 to 4.0.21 (4.0 series), All versions of 3.7 series, All ve…
- CVE-2023-24450MEDIUMCVSS 6.5EG 6.52023-01-26
Jenkins view-cloner Plugin 1.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.
- CVE-2022-45439MEDIUMCVSS 6.5EG 6.52023-01-17
A pair of spare WiFi credentials is stored in the configuration file of the Zyxel AX7501-B0 firmware prior to V5.17(ABPC.3)C0 in cleartext. An unauthenticated attacker could use the credentials to access the WLAN service if the configurati…
Map vulnerabilities like CWE-312 to your infrastructure
EchelonGraph correlates every CVE — across CWE-312 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →