Skip to main content

CWE archive

CWE-312 CVEs

Programmatic archive

816 CVEs tagged with CWE-31248 Critical, 275 High, 447 Medium, 46 Low, 0 Unrated.

CVE-2026-55985

Published Jul 24, 2026

The web management interface in  Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
28.9

CVE-2026-16802

Published Jul 24, 2026

Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local actor with file system access to read s…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2024-58023

Published Jul 23, 2026

Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive information.

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-65599

Published Jul 22, 2026

n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a credential exposure vulnerability: when configured with a Google Service Account key, the full PEM private key was mista…

CVSS 5.1 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-13380

Published Jul 20, 2026

VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthenticated endpoints. The credentials are present in these resp…

CVSS 9.0 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2026-16213

Published Jul 19, 2026

A security flaw has been discovered in Fantomas42 django-blog-zinnia up to 0.20. Affected by this vulnerability is an unknown functionality of the file zinnia/views/mixins/entry_p…

CVSS 4.8 · Medium
evidence mentions
6
Buzz score
26.0

CVE-2026-55885

Published Jul 10, 2026

Grav is a file-based Web platform. Prior to 1.7.53, an authenticated administrator with backup permissions can download a ZIP archive containing the full Grav installation root, i…

CVSS 6.8 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-8804

Published Jul 3, 2026

Puppet resource_api (shipped in Puppet Core 8.x and Puppet Enterprise 2023.8.x and 2025.x) does not preserve the sensitive flag on parameters defined via the resource-api, causing…

CVSS 6.7 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-38571

Published Jun 26, 2026

Cleartext storage and exposure of WPA2 credentials, and missing authentication on the rr/wr memory read/write commands, in the unauthenticated UART debug console of the Tenda N300…

CVSS 4.6 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-57287

Published Jun 24, 2026

Jenkins Job Configuration History Plugin 1356.ve360da_6c523a_ and earlier does not redact the encrypted values of secrets when displaying historical job and agent configurations,…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-50267

Published Jun 17, 2026

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Configuration.Abstractions 4.0.0 through 4…

CVSS 4.7 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-46622

Published Jun 11, 2026

SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, API tokens used to authenticate all REST API requests are stored as plaintext strings in the api_tokens…

CVSS 8.1 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-10786

Published Jun 8, 2026

Improper access control in the ticketing integration settings in Devolutions Server allows an authenticated low-privileged user to obtain cleartext credentials for configured tick…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-36176

Published Jun 4, 2026

GNCC GP5 v7.1.76 was discovered to store pre-signed Backblaze B2 upload URLs (PUT requests) in plaintext to the serial console. This allows physically-proximate attackers to extra…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-4387

Published May 29, 2026

StrongDM Desktop Application before 23.74.0 (Desktop Client before 53.77.0) on Microsoft Windows stores authentication state, including a JSON Web Token and asymmetric key materia…

CVSS 2.0 · Low
evidence mentions
2
Buzz score
17.5

CVE-2026-45040

Published May 28, 2026

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, RustFS suffers from sensitive information leakage in log outputs. When the server is run with R…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-9274

Published May 25, 2026

This vulnerability exists in CP Plus Wi-Fi Camera due to improper protection of sensitive information in runtime memory. An attacker with physical access could exploit this vulner…

CVSS 5.2 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-8596

Published May 14, 2026

Cleartext storage of sensitive information in the ModelBuilder/Serve component in Amazon SageMaker Python SDK before v2.257.2 and v3 before v3.8.0 might allow a remote authenticat…

CVSS 8.5 · High
evidence mentions
4
Buzz score
26.1

CVE-2026-6332

Published May 14, 2026

CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that could cause the disclosure of a sensitive information which could result in revealing protected sour…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-28758

Published May 13, 2026

When BIG-IP DNS is provisioned, a vulnerability exists in the gtm_add and bigip_add iControl REST commands that return the ssh-password parameter in cleartext in the iControl REST…

CVSS 6.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-43992

Published May 12, 2026

JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, every MCP write tool (send_tokens, execute_contract, instantiate_contract, upload_wasm, ibc_tr…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2026-45362

Published May 12, 2026

Sangoma Switchvox before 8.4 places cleartext SIP authentication credentials in a backup file.

CVSS 3.2 · Low
evidence mentions
2
Buzz score
16.0

CVE-2026-41520

Published May 8, 2026

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.17.15, 1.18.9, and 1.19.3, the output of cilium-bugtool can contain…

CVSS 7.9 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-43942

Published May 8, 2026

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In versions 3.8.15 and prior, the getConstants() IPC handler in src/app/lib/ipc-sync.js s…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 816 CVEsPage 1 of 33