CWE-312
812 CVEs • Abstraction: Base
Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
CVEs (812)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Insecure Permissions vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are susceptible to leaking information through cookies. This is fixed in version 21.2s10 and 22.1s...Show more |
1Siemens 7Omnivise T3000 Application Server Omnivise T3000 Domain ControllerOmnivise T3000 Network Intrusion Detection System+4 moreJun 17, 2026 Aug 2, 2024 8.3 HIGH· v4 8.8 HIGH· v3 N/A· v2 A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 Domain Controller R9.2 (All versions), Omnivise T3000 Network Intrusion Detection System (NIDS) R9.2 (All versi...Show more |
1Syrotech 1Sy Gpon 1110 Wdont Firmware Jun 17, 2026 Jul 26, 2024 7.0 HIGH· v4 4.6 MEDIUM· v3 N/A· v2 This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to storing of FTP credentials in plaintext within the SquashFS-root filesystem associated with the router's firmware. An attacker with physical access c...Show more |
1Syrotech 1Sy Gpon 1110 Wdont Firmware Jun 17, 2026 Jul 26, 2024 7.0 HIGH· v4 4.6 MEDIUM· v3 N/A· v2 This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to storing of default username and password credentials in plaintext within the router's firmware/ database. An attacker with physical access could expl...Show more |
1Syrotech 1Sy Gpon 1110 Wdont Firmware Jun 17, 2026 Jul 26, 2024 5.2 MEDIUM· v4 4.6 MEDIUM· v3 N/A· v2 This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to unencrypted storing of WPA/ WPS credentials within the router's firmware/ database. An attacker with physical access could exploit this by extracting...Show more |
1Syrotech 1Sy Gpon 1110 Wdont Firmware Jun 17, 2026 Jul 26, 2024 7.0 HIGH· v4 4.6 MEDIUM· v3 N/A· v2 This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due lack of encryption in storing of usernames and passwords within the router's firmware/ database. An attacker with physical access could exploit this by...Show more |
Plaintext vulnerability in the Gallery search module.
Impact: Successful exploitation of this vulnerability will affect availability. |
An issue was found on the Ruijie EG-2000 series gateway. An attacker can easily dump cleartext stored passwords in /data/config.text with simple XORs. This affects EG-2000SE EG_RGOS 11.1(1)B1. |
IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 temporarily stores data from different environments that could be obtained by a malicious user. IBM X-Force ID: 295791. |
1Ibm 2Cloud Pak For Security Qradar SuiteJun 17, 2026 Jul 10, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.22.0 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID:...Show more |
SnapCenter versions prior to 5.0p1 are susceptible to a vulnerability
which could allow an authenticated attacker to discover plaintext
credentials. |
1Linksys 2Mbe7000 Firmware Mx6200 FirmwareJun 17, 2026 Jul 9, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Linksys Velop Pro 6E 1.0.8 MX6200_1.0.8.215731 and 7 1.0.10.215314 devices send cleartext Wi-Fi passwords over the public Internet during app-based installation. |
The OpenAI ChatGPT app before 2024-07-05 for macOS opts out of the sandbox, and stores conversations in cleartext in a location accessible to other apps. |
NewPass before 1.2.0 stores passwords (rather than password hashes) directly, which makes it easier to obtain unauthorized access to sensitive information. NOTE: in each case, data at rest is encrypted, but is decrypted...Show more |
A vulnerability in a password management API in Brocade Fabric OS versions before v9.2.1, v9.2.0b, v9.1.1d, and v8.2.3e prints sensitive information in log files. This could allow an authenticated user to view the server...Show more |
The decrypted configuration file contains the password in cleartext
which is used to configure WINSelect. It can be used to remove the
existing restrictions and disable WINSelect entirely. |
The Kiuwan Local Analyzer (KLA) Java scanning application contains several hard-coded secrets in plain text format. In some cases, this can potentially compromise the confidentiality of the scan results. Several creden...Show more |
An issue in Annonshop.app DecentralizeJustice/anonymousLocker commit 2b2b4 to ba9fd and DecentralizeJustice/anonBackend commit 57837 to cd815 was discovered to store credentials in plaintext. |
1Motorola 1Vigilant Fixed Lpr Coms Box Firmware Jun 17, 2026 Jun 13, 2024 7.0 HIGH· v4 4.6 MEDIUM· v3 N/A· v2 An unauthorized user is able to gain access to sensitive data, including credentials, by physically retrieving the hard disk of the product as the data is stored in clear text. |
A vulnerability exists in the FOXMAN-UN/UNEM in which sensitive information is
stored in cleartext within a resource that might be accessible to another control sphere. |