← Back
CWE-256

220 CVEs • Abstraction: Base • Likelihood of Exploit: High

Plaintext Storage of a Password

Storing a password in plaintext may result in a system compromise.

JSON object

Loading...

CVEs (220)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 17, 2026
Apr 25, 2024
N/A· v4
7.3 HIGH· v3
N/A· v2
A flaw was found in Quay, where Quay's database is stored in plain text in mirror-registry on Jinja's config.yaml file. This issue leaves the possibility of a malicious actor with access to this file to gain access to Qu...Show more
A flaw was found in Quay, where Quay's database is stored in plain text in mirror-registry on Jinja's config.yaml file. This issue leaves the possibility of a malicious actor with access to this file to gain access to Quay's Redis instance.Show less
-
-
Jun 17, 2026
Apr 25, 2024
N/A· v4
7.3 HIGH· v3
N/A· v2
A flaw was found in how Quay's database is stored in plain-text in mirror-registry on the jinja's config.yaml file. This flaw allows a malicious actor with access to this file to gain access to Quay's database.
1Redhat
1Mirror Registry
Jun 17, 2026
Apr 25, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A flaw was found when using mirror-registry to install Quay. It uses a default database secret key, which is stored in plain-text format in one of the configuration template files. This issue may lead to all instances of...Show more
A flaw was found when using mirror-registry to install Quay. It uses a default database secret key, which is stored in plain-text format in one of the configuration template files. This issue may lead to all instances of Quay deployed using mirror-registry to have the same database secret key. This flaw allows a malicious actor to access sensitive information from Quay's database.Show less
1Redhat
1Mirror Registry
Jun 17, 2026
Apr 25, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
A flaw was found when using mirror-registry to install Quay. It uses a default secret, which is stored in plain-text format in one of the configuration template files. This issue may lead to all instances of Quay deploye...Show more
A flaw was found when using mirror-registry to install Quay. It uses a default secret, which is stored in plain-text format in one of the configuration template files. This issue may lead to all instances of Quay deployed using mirror-registry to have the same secret key. This flaw allows a malicious actor to craft session cookies and as a consequence, it may lead to gaining access to the affected Quay instance.Show less
1Buffalo
4Wsr 2533dhp2 Firmware
Wsr 2533dhp FirmwareWsr 2533dhpl Firmware+1 more
Jun 17, 2026
Apr 15, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Plaintext storage of a password issue exists in BUFFALO wireless LAN routers, which may allow a network-adjacent unauthenticated attacker with access to the product's login page may obtain configured credentials.
1Ibm
2Cloud Pak For Security
Qradar Suite
Jun 17, 2026
Apr 3, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
IBM QRadar Suite Software 1.10.12.0 through 1.10.18.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 28...Show more
IBM QRadar Suite Software 1.10.12.0 through 1.10.18.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 285698.Show less
-
-
Jun 17, 2026
Mar 26, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In AutomationDirect C-MORE EA9 HMI, credentials used by the platform are stored as plain text on the device.
1Microsoft
1Visual Studio Code
Jun 17, 2026
Mar 12, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Visual Studio Code Elevation of Privilege Vulnerability
1Inpsyde
1Backwpup
Jun 17, 2026
Feb 26, 2024
N/A· v4
2.7 LOW· v3
N/A· v2
The BackWPup plugin for WordPress is vulnerable to Plaintext Storage of Backup Destination Password in all versions up to, and including, 4.0.2. This is due to to the plugin improperly storing backup destination password...Show more
The BackWPup plugin for WordPress is vulnerable to Plaintext Storage of Backup Destination Password in all versions up to, and including, 4.0.2. This is due to to the plugin improperly storing backup destination passwords in plaintext. This makes it possible for authenticated attackers, with administrator-level access, to retrieve the password from the password input field in the UI or from the options table where the password is stored.Show less
1Kurrent
1Eventstoredb
Jun 17, 2026
Feb 21, 2024
N/A· v4
4.9 MEDIUM· v3
N/A· v2
EventStoreDB (ESDB) is an operational database built to store events. A vulnerability has been identified in the projections subsystem in versions 20 prior to 20.10.6, 21 prior to 21.10.11, 22 prior to 22.10.5, and 23 pr...Show more
EventStoreDB (ESDB) is an operational database built to store events. A vulnerability has been identified in the projections subsystem in versions 20 prior to 20.10.6, 21 prior to 21.10.11, 22 prior to 22.10.5, and 23 prior to 23.10.1. Only database instances that use custom projections are affected by this vulnerability. User passwords may become accessible to those who have access to the chunk files on disk, and users who have read access to system streams. Only users in the `$admins` group can access system streams by default. ESDB 23.10.1, 22.10.5, 21.10.11, and 20.10.6 contain a patch for this issue. Users should upgrade EventStoreDB, reset the passwords for current and previous members of `$admins` and `$ops` groups, and, if a password was reused in any other system, reset it in those systems to a unique password to follow best practices. If an upgrade cannot be done immediately, reset the passwords for current and previous members of `$admins` and `$ops` groups. Avoid creating custom projections until the patch has been applied.Show less
1Ibm
1Storage Defender Resiliency Service
Jun 17, 2026
Feb 10, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
IBM Storage Defender - Resiliency Service 2.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 278748.
1Miateknoloji
1Mia Med
Jun 17, 2026
Feb 8, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Plaintext Storage of a Password vulnerability in Mia Technology Inc. MİA-MED allows Read Sensitive Strings Within an Executable. This issue affects MİA-MED: before 1.0.7.
1Ibm
1Security Access Manager Container
Jun 17, 2026
Feb 7, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
IBM Security Access Manager Container 10.0.0.0 through 10.0.6.1 temporarily stores sensitive information in files that could be accessed by a local user. IBM X-Force ID: 254657.
1Rapidscada
1Rapid Scada
Jun 17, 2026
Feb 2, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the affected product stores plaintext credentials in various places. This may allow an attacker with local access to see them.
1Dell
1Networker
Jun 17, 2026
Jan 25, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Networker 19.9 and all prior versions contains a Plain-text Password stored in temporary config file during backup duration in NMDA MySQL Database backups. User has low privilege access to Networker Client system could...Show more
Networker 19.9 and all prior versions contains a Plain-text Password stored in temporary config file during backup duration in NMDA MySQL Database backups. User has low privilege access to Networker Client system could potentially exploit this vulnerability, leading to the disclosure of configured MySQL Database user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application Database with privileges of the compromised account. Show less
1Dell
1Powerprotect Data Manager Dm5500 Firmware
Jun 17, 2026
Dec 4, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Dell DM5500 5.14.0.0, contain a Plain-text Password Storage Vulnerability in the appliance. A local attacker with privileges could potentially exploit this vulnerability, leading to the disclosure of certain service c...Show more
Dell DM5500 5.14.0.0, contain a Plain-text Password Storage Vulnerability in the appliance. A local attacker with privileges could potentially exploit this vulnerability, leading to the disclosure of certain service credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account. Show less
1Nautobot
1Nautobot Plugin Device Onboarding
Jun 17, 2026
Nov 21, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The Nautobot Device Onboarding plugin uses the netmiko and NAPALM libraries to simplify the onboarding process of a new device into Nautobot down to, in many cases, an IP Address and a Location. Starting in version 2.0.0...Show more
The Nautobot Device Onboarding plugin uses the netmiko and NAPALM libraries to simplify the onboarding process of a new device into Nautobot down to, in many cases, an IP Address and a Location. Starting in version 2.0.0 and prior to version 3.0.0, credentials provided to onboarding task are visible via Job Results from an execution of an Onboarding Task. Version 3.0.0 fixes this issue; no known workarounds are available. Mitigation recommendations include deleting all Job Results for any onboarding task to remove clear text credentials from database entries that were run while on v2.0.X, upgrading to v3.0.0, and rotating any exposed credentials.Show less
1Busbaer
1Eisbaer Scada
Jun 17, 2026
Oct 25, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
EisBaer Scada - CWE-256: Plaintext Storage of a Password
1Eaton
1Easysoft
Jun 17, 2026
Oct 17, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Eaton easySoft software is used to program easy controllers and displays for configuring, programming and defining parameters for all the intelligent relays. This software has a password protection functionality to secur...Show more
Eaton easySoft software is used to program easy controllers and displays for configuring, programming and defining parameters for all the intelligent relays. This software has a password protection functionality to secure the project file from unauthorized access. This password was being stored insecurely and could be retrieved by skilled adversaries. Show less
1Netapp
1Snapgathers
Jun 17, 2026
Oct 12, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
SnapGathers versions prior to 4.9 are susceptible to a vulnerability which could allow a local authenticated attacker to discover plaintext domain user credentials