← Back
CWE-312

812 CVEs • Abstraction: Base

Cleartext Storage of Sensitive Information

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

JSON object

Loading...

CVEs (812)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ucweb
1Ucweb Uc
Jun 17, 2026
Aug 14, 2021
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
UCWeb UC 12.12.3.1219 through 12.12.3.1226 uses cleartext HTTP, and thus man-in-the-middle attackers can discover visited URLs.
1Dcce
1Mac1100 Plc Firmware
Jun 17, 2026
Aug 13, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An information disclosure vulnerability exists in the EPA protocol of Dut Computer Control Engineering Co.'s PLC MAC1100.
1Jetbrains
1Teamcity
Jun 17, 2026
Aug 6, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In JetBrains TeamCity before 2021.1, passwords in cleartext sometimes could be stored in VCS.
1Liferay
2Digital Experience Platform
Liferay Portal
Jun 17, 2026
Aug 3, 2021
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
The Portal Workflow module in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 93, 7.1 before fix pack 19, and 7.2 before fix pack 7, user's clear text passwords are stored in the database if workflo...Show more
The Portal Workflow module in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 93, 7.1 before fix pack 19, and 7.2 before fix pack 7, user's clear text passwords are stored in the database if workflow is enabled for user creation, which allows attackers with access to the database to obtain a user's password.Show less
1Liferay
2Digital Experience Platform
Liferay Portal
Jun 17, 2026
Aug 3, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Dynamic Data Mapping module in Liferay Portal 7.1.0 through 7.3.2, and Liferay DXP 7.1 before fix pack 19, and 7.2 before fix pack 7, autosaves form values for unauthenticated users, which allows remote attackers to...Show more
The Dynamic Data Mapping module in Liferay Portal 7.1.0 through 7.3.2, and Liferay DXP 7.1 before fix pack 19, and 7.2 before fix pack 7, autosaves form values for unauthenticated users, which allows remote attackers to view the autosaved values by viewing the form as an unauthenticated user.Show less
1Nch
1Reflect Customer Relationship Management
Jun 17, 2026
Jul 25, 2021
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
NCH Reflect CRM 3.01 allows local users to discover cleartext user account information by reading the configuration files.
1Nch
1Quorum
Jun 17, 2026
Jul 25, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
NCH Quorum v2.03 and earlier allows local users to discover cleartext login information relating to users by reading the local .dat configuration files.
1Akkadianlabs
2Ova Appliance
Provisioning Manager
Jun 17, 2026
Jul 22, 2021
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be escaped by abusing the 'Edit MySQL Configuration' command. This command launches a standard vi editor interface which can then be escaped...Show more
The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be escaped by abusing the 'Edit MySQL Configuration' command. This command launches a standard vi editor interface which can then be escaped. This issue was resolved in Akkadian OVA appliance version 3.0 (and later), Akkadian Provisioning Manager 5.0.2 (and later), and Akkadian Appliance Manager 3.3.0.314-4a349e0 (and later).Show less
1Baidu
1Xuperchain
Jun 17, 2026
Jul 19, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Xuperchain 3.6.0 that allows for attackers to recover any arbitrary users' private key after obtaining the partial signature in multisignature.
1Ibm
1Qradar Security Information And Event Manager
Jun 17, 2026
Jul 16, 2021
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
IBM QRadar SIEM 7.3 and 7.4 uses less secure methods for protecting data in transit between hosts when encrypt host connections is not enabled as well as data at rest. IBM X-Force ID: 192539.
1Ibm
1Security Verify Access
Jun 17, 2026
Jul 15, 2021
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
IBM Security Verify Access Docker 10.0.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 198299
1Magicsmotion
1Flamingo 2 Firmware
Jun 17, 2026
Jul 15, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The MagicMotion Flamingo 2 application for Android stores data on an sdcard under com.vt.magicmotion/files/Pictures, whence it can be read by other applications.
1Octopus
1Server
Jun 17, 2026
Jul 8, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
When configuring Octopus Server if it is configured with an external SQL database, on initial configuration the database password is written to the OctopusServer.txt log file in plaintext.
1Octopus
1Server
Jun 17, 2026
Jul 8, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
When configuring Octopus Server if it is configured with an external SQL database, on initial configuration the database password is written to the OctopusServer.txt log file in plaintext.
1Alpinelinux
1Aports
Jun 17, 2026
Jul 5, 2021
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
In the xrdp package (in branches through 3.14) for Alpine Linux, RDP sessions are vulnerable to man-in-the-middle attacks because pre-generated RSA certificates and private keys are used.
1Ratpack Project
1Ratpack
Jun 17, 2026
Jun 29, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Ratpack is a toolkit for creating web applications. In versions prior to 1.9.0, the default configuration of client side sessions results in unencrypted, but signed, data being set as cookie values. This means that if so...Show more
Ratpack is a toolkit for creating web applications. In versions prior to 1.9.0, the default configuration of client side sessions results in unencrypted, but signed, data being set as cookie values. This means that if something sensitive goes into the session, it could be read by something with access to the cookies. For this to be a vulnerability, some kind of sensitive data would need to be stored in the session and the session cookie would have to leak. For example, the cookies are not configured with httpOnly and an adjacent XSS vulnerability within the site allowed capture of the cookies. As of version 1.9.0, a securely randomly generated signing key is used. As a workaround, one may supply an encryption key, as per the documentation recommendation.Show less
1Mozilla
1Thunderbird
Jun 17, 2026
Jun 24, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
OpenPGP secret keys that were imported using Thunderbird version 78.8.1 up to version 78.10.1 were stored unencrypted on the user's local disk. The master password protection was inactive for those keys. Version 78.10.2...Show more
OpenPGP secret keys that were imported using Thunderbird version 78.8.1 up to version 78.10.1 were stored unencrypted on the user's local disk. The master password protection was inactive for those keys. Version 78.10.2 will restore the protection mechanism for newly imported keys, and will automatically protect keys that had been imported using affected Thunderbird versions. This vulnerability affects Thunderbird < 78.10.2.Show less
1Mozilla
1Hubs Cloud Reticulum
Jun 17, 2026
Jun 24, 2021
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Proxy functionality built into Hubs Cloud’s Reticulum software allowed access to internal URLs, including the metadata service. This vulnerability affects Hubs Cloud < mozillareality/reticulum/1.0.1/20210428201255.
1Mozilla
1Thunderbird
Jun 17, 2026
Jun 24, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Thunderbird unprotects a secret OpenPGP key prior to using it for a decryption, signing or key import task. If the task runs into a failure, the secret key may remain in memory in its unprotected state. This vulnerabilit...Show more
Thunderbird unprotects a secret OpenPGP key prior to using it for a decryption, signing or key import task. If the task runs into a failure, the secret key may remain in memory in its unprotected state. This vulnerability affects Thunderbird < 78.8.1.Show less
1Zoll
1Defibrillator Dashboard
Jun 17, 2026
Jun 16, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
ZOLL Defibrillator Dashboard, v prior to 2.2, The affected products contain credentials stored in plaintext. This could allow an attacker to gain access to sensitive information.