← Back
CWE-312

812 CVEs • Abstraction: Base

Cleartext Storage of Sensitive Information

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

JSON object

Loading...

CVEs (812)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Debian
FedoraprojectOpensuse+1 more
4Debian Linux
FedoraOpensuse+1 more
Apr 23, 2026
Mar 31, 2008
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.
1Ge
1Proficy Real Time Information Portal
Apr 23, 2026
Jan 29, 2008
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
GE Fanuc Proficy Real-Time Information Portal 2.6 and earlier uses HTTP Basic Authentication, which transmits usernames and passwords in base64-encoded cleartext and allows remote attackers to steal the passwords and gai...Show more
GE Fanuc Proficy Real-Time Information Portal 2.6 and earlier uses HTTP Basic Authentication, which transmits usernames and passwords in base64-encoded cleartext and allows remote attackers to steal the passwords and gain privileges.Show less
1Flexispy
1Mobile Spy
Apr 23, 2026
Nov 1, 2007
N/A· v4
7.5 HIGH· v3
6.4 MEDIUM· v2
Mobile Spy (1) stores login credentials in cleartext under the RetinaxStudios registry key, and (2) sends login credentials and log data over a cleartext HTTP connection, which allows attackers to obtain sensitive inform...Show more
Mobile Spy (1) stores login credentials in cleartext under the RetinaxStudios registry key, and (2) sends login credentials and log data over a cleartext HTTP connection, which allows attackers to obtain sensitive information by reading the registry or sniffing the network.Show less
1Capturix
1Scanshare
Apr 16, 2026
Jul 11, 2005
N/A· v4
5.5 MEDIUM· v3
1.9 LOW· v2
Capturix ScanShare 1.06 build 50 stores sensitive information such as the password in cleartext in capturixss_cfg.ini, which is readable by local users.
1Ipswitch
1Imail
Apr 16, 2026
Jul 6, 2005
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IMail stores usernames and passwords in cleartext in a cookie, which allows remote attackers to obtain sensitive information.
1Dlink
1Dsl 504t Firmware
Apr 16, 2026
May 26, 2005
N/A· v4
7.5 HIGH· v3
7.5 HIGH· v2
D-Link DSL-504T stores usernames and passwords in cleartext in the router configuration file, which allows remote attackers to obtain sensitive information.
1Broadcom
1Bluecoat Security Gateway
Apr 16, 2026
Dec 31, 2004
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The web-based Management Console in Blue Coat Security Gateway OS 3.0 through 3.1.3.13 and 3.2.1, when importing a private key, stores the key and its passphrase in plaintext in a log file, which allows attackers to stea...Show more
The web-based Management Console in Blue Coat Security Gateway OS 3.0 through 3.1.3.13 and 3.2.1, when importing a private key, stores the key and its passphrase in plaintext in a log file, which allows attackers to steal digital certificates.Show less
1Phprank
1Phprank
Apr 16, 2026
Dec 31, 2002
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
phpRank 1.8 stores the administrative password in plaintext on the server and in the "ap" cookie, which allows remote attackers to retrieve the administrative password.
1Pgp
1Personal Privacy
Apr 16, 2026
Dec 31, 2002
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Microsoft Outlook plug-in PGP version 7.0, 7.0.3, and 7.0.4 silently saves a decrypted copy of a message to hard disk when "Automatically decrypt/verify when opening messages" option is checked, "Always use Secure Viewer...Show more
Microsoft Outlook plug-in PGP version 7.0, 7.0.3, and 7.0.4 silently saves a decrypted copy of a message to hard disk when "Automatically decrypt/verify when opening messages" option is checked, "Always use Secure Viewer when decrypting" option is not checked, and the user replies to an encrypted message.Show less
1Symfony
1Twig
Apr 16, 2026
Dec 31, 2001
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The default "basic" security setting' in config.php for TWIG webmail 2.7.4 and earlier stores cleartext usernames and passwords in cookies, which could allow attackers to obtain authentication information and gain privil...Show more
The default "basic" security setting' in config.php for TWIG webmail 2.7.4 and earlier stores cleartext usernames and passwords in cookies, which could allow attackers to obtain authentication information and gain privileges.Show less
1Audiogalaxy
1Audiogalaxy
Apr 16, 2026
Dec 31, 2001
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Autogalaxy stores usernames and passwords in cleartext in cookies, which makes it easier for remote attackers to obtain authentication information and gain unauthorized access via sniffing or a cross-site scripting attac...Show more
Autogalaxy stores usernames and passwords in cleartext in cookies, which makes it easier for remote attackers to obtain authentication information and gain unauthorized access via sniffing or a cross-site scripting attack.Show less
1Xitami
1Xitami
Apr 16, 2026
Dec 31, 2001
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Xitami 2.4 through 2.5 b4 stores the Administrator password in plaintext in the default.aut file, whose default permissions are world-readable, which allows remote attackers to gain privileges.