CWE-312
812 CVEs • Abstraction: Base
Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
CVEs (812)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
TP-Link's TL-WPA4220 4.0.2 Build 20180308 Rel.37064 does not use SSL by default. Attacker on the local network can monitor traffic and capture the cookie and other sensitive information. |
Cleartext Storage of Sensitive Information in Memory vulnerability in Gallagher Command Centre Server allows Cloud end-to-end encryption key to be discoverable in server memory dumps. This issue affects: Gallagher Comman...Show more |
Cleartext Storage of Sensitive Information in Memory vulnerability in Gallagher Command Centre Server allows OSDP reader master keys to be discoverable in server memory dumps. This issue affects: Gallagher Command Centre...Show more |
1Aveva 2Intouch 2017 Intouch 2020Jun 17, 2026 Jun 9, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The vulnerability could expose cleartext credentials from AVEVA InTouch Runtime 2020 R2 and all prior versions (WindowViewer) if an authorized, privileged user creates a diagnostic memory dump of the process and saves it...Show more |
Brocade SANNav before version 2.1.1 contains an information disclosure vulnerability. Successful exploitation of internal server information in the initial login response header. |
The DLink Router DIR-895L MFC v1.21b05 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthenticated attacker to gain access to the firmware and to extract se...Show more |
KDE Messagelib through 5.17.0 reveals cleartext of encrypted messages in some situations. Deleting an attachment of a decrypted encrypted message stored on a remote server (e.g., an IMAP server) causes KMail to upload th...Show more |
1Zte 8Zxa10 F809 Firmware Zxa10 F819 FirmwareZxa10 F821 Firmware+5 moreJun 17, 2026 May 28, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Some PON MDU devices of ZTE stored sensitive information in plaintext, and users with login authority can obtain it by inputing command. This affects: ZTE PON MDU device ZXA10 F821 V1.7.0P3T22, ZXA10 F822 V1.4.3T6, ZXA10...Show more |
1Versa Networks 1Versa Director Nov 21, 2024 May 26, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 In Versa Director, the unencrypted backup files stored on the Versa deployment contain credentials stored within configuration files. These credentials are for various application components such as SNMP, and SSL and Tru...Show more |
1Ibm 1Security Identity Manager Jun 17, 2026 May 20, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 IBM Security Identity Manager 7.0.2 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 199998. |
An issue was discovered in Couchbase Server 5.x and 6.x through 6.6.1 and 7.0.0 Beta. Incorrect commands to the REST API can result in leaked authentication information being stored in cleartext in the debug.log and info...Show more |
Cleartext storage of sensitive information in multiple versions of Octopus Server where in certain situations when running import or export processes, the password used to encrypt and decrypt sensitive values would be wr...Show more |
1Wago 50852 0303 Firmware 0852 1305/000 001 Firmware0852 1305 Firmware+2 moreJun 17, 2026 May 13, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In multiple managed switches by WAGO in different versions the webserver cookies of the web based UI contain user credentials. |
An issue was discovered in Couchbase Server before 6.0.5, 6.1.x through 6.5.x before 6.5.2, and 6.6.x before 6.6.1. An internal user with administrator privileges, @ns_server, leaks credentials in cleartext in the cbcoll...Show more |
An issue has been discovered in GitLab affecting all versions starting from 11.6. Pull mirror credentials are exposed that allows other maintainers to be able to view the credentials in plain-text, |
1Dell 3Unity Operating Environment Unity Xt Operating EnvironmentUnityvsa Operating EnvironmentJun 17, 2026 Apr 30, 2021 N/A· v4 6.7 MEDIUM· v3 2.1 LOW· v2 Dell EMC Unity, UnityVSA, and Unity XT versions prior to 5.0.7.0.5.008 contain a plain-text password storage vulnerability when the Dell Upgrade Readiness Utility is run on the system. The credentials of the Unisphere Ad...Show more |
Etherpad <1.8.3 stored passwords used by users insecurely in the database and in log files. This affects every database backend supported by Etherpad. |
1Sentrysoftware 1Hardware Sentry Km For Bmc Patrol Jun 17, 2026 Apr 23, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Hardware Sentry KM before 10.0.01 for BMC PATROL, a cleartext password may be discovered after a failure or timeout of a command. |
An issue was discovered in svc-login.php in Void Aural Rec Monitor 9.0.0.1. Passwords are stored in unencrypted source-code text files. This was noted when accessing the svc-login.php file. The value is used to authentic...Show more |
Wowza Streaming Engine before 4.8.8.01 (in a default installation) has cleartext passwords stored in the conf/admin.password file. A regular local user is able to read usernames and passwords. |