← Back
CWE-312

856 CVEs • Abstraction: Base

Cleartext Storage of Sensitive Information

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

JSON object

Loading...

CVEs (856)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Appinghouse
1Memono
Jun 17, 2026
Apr 16, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Users can lock their notes with a password in Memono version 3.8. Thus, users needs to know a password to read notes. However, these notes are stored in a database without encryption and an attacker can read the password...Show more
Users can lock their notes with a password in Memono version 3.8. Thus, users needs to know a password to read notes. However, these notes are stored in a database without encryption and an attacker can read the password-protected notes without having the password. Notes are stored in the ZENTITY table in the memono.sqlite database.Show less
1Jetbrains
1Pycharm
Jun 17, 2026
Apr 10, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In JetBrains PyCharm 2019.2.5 and 2019.3 on Windows, Apple Notarization Service credentials were included. This is fixed in 2019.2.6 and 2019.3.3.
1Universal Robots
1Ur Software
Jun 17, 2026
Apr 6, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Universal Robots control box CB 3.1 across firmware versions (tested on 1.12.1, 1.12, 1.11 and 1.10) does not encrypt or protect in any way the intellectual property artifacts installed from the UR+ platform of hardware...Show more
Universal Robots control box CB 3.1 across firmware versions (tested on 1.12.1, 1.12, 1.11 and 1.10) does not encrypt or protect in any way the intellectual property artifacts installed from the UR+ platform of hardware and software components (URCaps). These files (*.urcaps) are stored under '/root/.urcaps' as plain zip files containing all the logic to add functionality to the UR3, UR5 and UR10 robots. This flaw allows attackers with access to the robot or the robot network (while in combination with other flaws) to retrieve and easily exfiltrate all installed intellectual property.Show less
1Grandstream
3Ucm6202 Firmware
Ucm6204 FirmwareUcm6208 Firmware
Jun 17, 2026
Mar 30, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. This could allow an attacker to retrieve all passwords and possibly gain elevated privileges.
1Unisoon
1Ultralog Express Firmware
Jun 17, 2026
Mar 27, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
UltraLog Express device management software stores user’s information in cleartext. Any user can obtain accounts information through a specific page.
1Netsas
1Enigma Network Management Solution
Jun 17, 2026
Mar 19, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
NETSAS Enigma NMS 65.0.0 and prior does not encrypt sensitive data stored within the SQL database. It is possible for an attacker to expose unencrypted sensitive data.
1Django Nopassword Project
1Django Nopassword
Jun 17, 2026
Mar 18, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
django-nopassword before 5.0.0 stores cleartext secrets in the database.
1Rockwellautomation
4Micrologix 1100 Firmware
Micrologix 1400 A FirmwareMicrologix 1400 B Firmware+1 more
Jun 17, 2026
Mar 16, 2020
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, If Simple Mail Transfer Protocol (SMTP...Show more
Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, If Simple Mail Transfer Protocol (SMTP) account data is saved in RSLogix 500, a local attacker with access to a victim’s project may be able to gather SMTP server authentication data as it is written to the project file in cleartext.Show less
1Watchguard
1Ad Helper Firmware
Jun 17, 2026
Mar 12, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The AD Helper component in WatchGuard Fireware before 5.8.5.10317 allows remote attackers to discover cleartext passwords via the /domains/list URI.
1Moxa
6Mb3170 Firmware
Mb3180 FirmwareMb3270 Firmware+3 more
Jun 17, 2026
Mar 11, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. The application's configuration file contains pa...Show more
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. The application's configuration file contains parameters that represent passwords in cleartext.Show less
1Siemens
2Sinvr 3 Central Control Server
Sinvr 3 Video Server
Jun 17, 2026
Mar 10, 2020
N/A· v4
6.5 MEDIUM· v3
3.5 LOW· v2
A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0), SiNVR/SiVMS Video Server (All versions < V5.0.0). The FTP services of the SiVMS/SiNVR Video Server and the Control Center Server...Show more
A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0), SiNVR/SiVMS Video Server (All versions < V5.0.0). The FTP services of the SiVMS/SiNVR Video Server and the Control Center Server (CCS) maintain log files that store login credentials in cleartext. In configurations where the FTP service is enabled, authenticated remote attackers could extract login credentials of other users of the service.Show less
1Jenkins
1Zephyr For Jira Test Management
Jun 17, 2026
Mar 9, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Jenkins Zephyr for JIRA Test Management Plugin 1.5 and earlier stores its credentials in plain text in a global configuration file on the Jenkins master file system.
1Redhat
2Decision Manager
Process Automation Manager
Jun 17, 2026
Mar 5, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability was found in business-central, as shipped in rhdm-7.5.1 and rhpam-7.5.1, where encoded passwords are stored in errai_security_context. The encoding used for storing the passwords is Base64, not an encrypt...Show more
A vulnerability was found in business-central, as shipped in rhdm-7.5.1 and rhpam-7.5.1, where encoded passwords are stored in errai_security_context. The encoding used for storing the passwords is Base64, not an encryption algorithm, and any recovery of these passwords could lead to user passwords being exposed.Show less
2Canonical
Mozilla
2Thunderbird
Ubuntu Linux
Jun 17, 2026
Mar 2, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
If a user saved passwords before Thunderbird 60 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the da...Show more
If a user saved passwords before Thunderbird 60 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the data was copied to a new format starting in Thunderbird 60. The new master password is added only on the new file. This could allow the exposure of stored password data outside of user expectations. This vulnerability affects Thunderbird < 68.5.Show less
1Moxa
20Iologik 2512 Hspa T Firmware
Iologik 2512 Hspa FirmwareIologik 2512 T Firmware+17 more
Jun 17, 2026
Feb 26, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, sensitive information is stored in configuration files without encryption, which may allow an attack...Show more
In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, sensitive information is stored in configuration files without encryption, which may allow an attacker to access an administrative account.Show less
1Iblsoft
1Online Weather
Jun 17, 2026
Feb 26, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBL Online Weather before 4.3.5a allows attackers to obtain sensitive information by reading the IWEBSERVICE_JSONRPC_COOKIE cookie.
1Secom
2Dr.id Access Control
Dr.id Attendance System
Jun 17, 2026
Feb 11, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
TAIWAN SECOM CO., LTD., a Door Access Control and Personnel Attendance Management system, stores users’ information by cleartext in the cookie, which divulges password to attackers.
1Cisco
1Linksys E4200 Firmware
Nov 21, 2024
Feb 5, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Cisco Linksys E4200 1.0.05 Build 7 devices store passwords in cleartext allowing remote attackers to obtain sensitive information.
1Ibm
1Storediq
Jun 17, 2026
Feb 3, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
IBM StoredIQ 7.6.0.17 through 7.6.0.20 could disclose sensitive information to a local user due to data in certain directories not being encrypted when it contained symbolic links. IBM X-Force ID: 175133.
1Parallels
1Parallels
Jun 17, 2026
Jan 21, 2020
N/A· v4
7.5 HIGH· v3
7.6 HIGH· v2
Parallels 13 uses cleartext HTTP as part of the update process, allowing man-in-the-middle attacks. Users of out-of-date versions are presented with a pop-up window for a parallels_updates.xml file on the http://update.p...Show more
Parallels 13 uses cleartext HTTP as part of the update process, allowing man-in-the-middle attacks. Users of out-of-date versions are presented with a pop-up window for a parallels_updates.xml file on the http://update.parallels.com web site.Show less