Skip to main content

CWE archive

CWE-256 CVEs

Programmatic archive

214 CVEs tagged with CWE-25622 Critical, 60 High, 114 Medium, 18 Low, 0 Unrated.

CVE-2026-41874

Published Jul 28, 2026

Quick.Cart stores hard-coded, plaintext admin credentials in a configuration file. This flaw allows attackers with access to the server file system to retrieve authentication deta…

CVSS 6.8 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-61886

Published Jul 24, 2026

Weintek cMT3092X HMI stores user account passwords in plaintext.

CVSS 7.1 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-40430

Published Jul 23, 2026

Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a plaintext storage of a password vulnerability that could expose cleartext credentials through the API.

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-44187

Published Jul 22, 2026

A flaw was found in the Ansible Lightspeed extension for Visual Studio Code. This vulnerability allows an attacker with local access to the workstation, or malware running with th…

CVSS 3.3 · Low
evidence mentions
2
Buzz score
21.0

CVE-2026-46513

Published Jul 16, 2026

Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, Frogman stored API tokens generated by Tools/CreateApiToken.php:33-36 as raw bin2hex(random_bytes(3…

CVSS 7.4 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-14867

Published Jul 7, 2026

Credentials of built-in users are insecurely stored in the User directory of PcVue projects, all versions prior to 17.0.0. A local attacker could retrieve users’ credentials.  Ac…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-57302

Published Jun 24, 2026

Jenkins FitNesse Plugin 1.36 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Extended Read permi…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-50268

Published Jun 17, 2026

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Configuration.Encryption 4.0.0 through 4.1…

CVSS 1.9 · Low
evidence mentions
2
Buzz score
16.0

CVE-2024-39575

Published Jun 16, 2026

update_disk_psu_baseline.sh requires password in plain text

CVSS 7.4 · High

CVE-2026-36174

Published Jun 4, 2026

GNCC GP5 v7.1.76 was discovered to store sensitive wireless network information in plaintext during routine operations to the serial console. This issue allows physically-proximat…

CVSS 4.6 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2018-25396

Published May 29, 2026

Heatmiser Wifi Thermostat 1.7 contains a credential disclosure vulnerability that allows unauthenticated attackers to retrieve administrative credentials by accessing the networkS…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-42151

Published May 4, 2026

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configurati…

CVSS 7.5 · High
evidence mentions
36
Buzz score
48.0
Vendor/product tagsBeta · best-effort

CVE-2026-6500

Published May 4, 2026

Plaintext storage of a password vulnerability in ILM Informatique OpenConcerto allows Retrieve Embedded Sensitive Data. This issue affects OpenConcerto: 1.7.5.

CVSS 4.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-36335

Published Apr 30, 2026

IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.3.0, 5.3.1 stores user credentials in plain text which can be read by a local user.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-6597

Published Apr 20, 2026

A weakness has been identified in langflow-ai langflow up to 1.8.3. Impacted is the function remove_api_keys/has_api_terms of the file src/backend/base/langflow/api/utils/core.py…

CVSS 2.0 · Low
evidence mentions
4
Buzz score
22.6

CVE-2025-15624

Published Apr 17, 2026

Plaintext Storage of a Password vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server.  In a setup where OpenID is used as the primary method of authentication to authent…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-47961

Published Apr 10, 2026

A plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access or influence the user's PIN code due to insecure sto…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2026-33216

Published Mar 25, 2026

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, for MQTT deployments using usercodes/password…

CVSS 8.6 · High
evidence mentions
10
Buzz score
43.5
Vendor/product tagsBeta · best-effort

CVE-2026-4251

Published Mar 16, 2026

A vulnerability was determined in CityData CityChat up to 0.12.6 on Android. Affected by this vulnerability is an unknown functionality of the file resources/assets/flutter_assets…

CVSS 1.1 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-4250

Published Mar 16, 2026

A vulnerability was found in Albert Sağlık Hizmetleri ve Ticaret Albert Health up to 1.7.3 on Android. Affected is an unknown function of the file resources/assets/service-account…

CVSS 1.1 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-4243

Published Mar 16, 2026

A weakness has been identified in La Nacion App 10.2.25 on Android. This impacts an unknown function of the file source/app/lanacion/clublanacion/BuildConfig.java of the component…

CVSS 1.1 · Low
evidence mentions
4
Buzz score
22.6
Showing 1-25 of 214 CVEsPage 1 of 9