Skip to main content

CWE archive

CWE-257 CVEs

Programmatic archive

64 CVEs tagged with CWE-2572 Critical, 21 High, 36 Medium, 5 Low, 0 Unrated.

CVE-2026-1836

Published Jun 12, 2026

The system stores the username and password from the login form after submitting the request. This could allow an attacker with access to the platform to return to the browser and…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-22576

Published Apr 14, 2026

A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, Fort…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-22574

Published Apr 14, 2026

A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, Fort…

CVSS 4.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-8095

Published Apr 14, 2026

The OECH1 prefix encoding is intended to obfuscate values across the OpenEdge platform.  It has been identified as cryptographically weak and unsuitable for stored encodings and e…

CVSS 9.1 · Critical

CVE-2016-15058

Published Apr 3, 2026

Hirschmann HiLCOS Classic Platform switches Classic L2E, L2P, L3E, L3P versions prior to 09.0.06 and Classic L2B prior to 05.3.07 contain a credential exposure vulnerability where…

CVSS 8.6 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-22614

Published Mar 10, 2026

The encryption mechanism used in Eaton's EasySoft project file was insecure and susceptible to brute force attacks, an attacker with access to this file and the local host machine…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-20128

Published Feb 25, 2026

A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain DCA user privileges on an affec…

CVSS 7.5 · High
evidence mentions
18
Buzz score
74.4
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2025-57796

Published Jan 28, 2026

Explorance Blue versions prior to 8.14.12 use reversible symmetric encryption with a hardcoded static key to protect sensitive data, including user passwords and system configurat…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-14295

Published Jan 22, 2026

Storing Passwords in a Recoverable Format vulnerability in Automated Logic WebCTRL on Windows, Carrier i-Vu on Windows. Storing Passwords in a Recoverable Format vulnerability (CW…

CVSS 7.0 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-8307

Published Jan 8, 2026

Asseco InfoMedica is a comprehensive solution used to manage both administrative and medical tasks in the healthcare sector. Passwords of all users are stored in a database in an…

CVSS 5.9 · Medium

CVE-2025-34180

Published Dec 15, 2025

NetSupport Manager < 14.12.0001 relies on a shared Gateway Key for authentication between Manager/Control, Client, and Connectivity Server components. The key is stored using a r…

CVSS 8.4 · High

CVE-2025-40774

Published Oct 14, 2025

A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications store user passwords encrypted in its database. Decryption keys are ac…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-35054

Published Oct 9, 2025

Newforma Info Exchange (NIX) stores credentials used to configure NPCS in 'HKLM\Software\WOW6432Node\Newforma\<version>\Credentials'. The credentials are encrypted but the encryp…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-0280

Published Sep 3, 2025

A security vulnerability in HCL Compass can allow attacker to gain unauthorized database access.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-58049

Published Aug 28, 2025

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions from 14.4.2 to before 16.4.8, 16.5.0-rc-1 to before 16.10.7, a…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-57789

Published Aug 20, 2025

During the brief window between installation and the first administrator login, remote attackers may exploit the default credential to gain admin control. This is limited to the s…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-8904

Published Aug 13, 2025

Amazon EMR Secret Agent creates a keytab file containing Kerberos credentials. This file is stored in the /tmp/ directory. A user with access to this directory and another account…

CVSS 9.0 · Critical

CVE-2025-6996

Published Jul 8, 2025

Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated attacker to decrypt other us…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-6995

Published Jul 8, 2025

Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated attacker to decrypt other us…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-51552

Published May 22, 2025

Weak password storage vulnerabilities exist in ASPECT if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*;…

CVSS 7.1 · High

CVE-2025-25983

Published Apr 18, 2025

An issue in Macro-video Technologies Co.,Ltd V380 Pro android application 2.1.44 and V380 Pro android application 2.1.64 allows an attacker to obtain sensitive information via the…

CVSS 3.4 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-32122

Published Apr 8, 2025

A storing passwords in a recoverable format in Fortinet FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions allows attacker t…

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort
Showing 1-25 of 64 CVEsPage 1 of 3