Skip to main content

CWE archive

CWE-312 CVEs

Programmatic archive

813 CVEs tagged with CWE-31248 Critical, 274 High, 445 Medium, 46 Low, 0 Unrated.

CVE-2024-21993

Published Jul 9, 2024

SnapCenter versions prior to 5.0p1 are susceptible to a vulnerability which could allow an authenticated attacker to discover plaintext credentials.

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-40594

Published Jul 6, 2024

The OpenAI ChatGPT app before 2024-07-05 for macOS opts out of the sandbox, and stores conversations in cleartext in a location accessible to other apps.

CVSS 2.3 · Low

CVE-2024-39846

Published Jun 29, 2024

NewPass before 1.2.0 stores passwords (rather than password hashes) directly, which makes it easier to obtain unauthorized access to sensitive information. NOTE: in each case, dat…

CVSS 3.5 · Low

CVE-2024-29954

Published Jun 26, 2024

A vulnerability in a password management API in Brocade Fabric OS versions before v9.2.1, v9.2.0b, v9.1.1d, and v8.2.3e prints sensitive information in log files. This could allow…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-36497

Published Jun 24, 2024

The decrypted configuration file contains the password in cleartext which is used to configure WINSelect. It can be used to remove the existing restrictions and disable WINSelec…

CVSS 9.1 · Critical

CVE-2023-49113

Published Jun 20, 2024

The Kiuwan Local Analyzer (KLA) Java scanning application contains several hard-coded secrets in plain text format. In some cases, this can potentially compromise the confidenti…

CVSS 7.8 · High

CVE-2024-36589

Published Jun 13, 2024

An issue in Annonshop.app DecentralizeJustice/anonymousLocker commit 2b2b4 to ba9fd and DecentralizeJustice/anonBackend commit 57837 to cd815 was discovered to store credentials i…

CVSS 4.3 · Medium

CVE-2024-4540

Published Jun 3, 2024

A flaw was found in Keycloak in OAuth 2.0 Pushed Authorization Requests (PAR). Client-provided parameters were found to be included in plain text in the KC_RESTART cookie returned…

CVSS 7.5 · High

CVE-2024-36119

Published May 30, 2024

Statamic is a, Laravel + Git powered CMS designed for building websites. In affected versions users registering via the `user:register_form` tag will have their password confirmat…

CVSS 1.8 · Low

CVE-2024-33471

Published May 24, 2024

An issue in the Sensor Settings of AVTECH Room Alert 4E v4.4.0 allows attackers to gain access to SMTP credentials in plaintext via a crafted AJAX request. NOTE: This vulnerabilit…

CVSS 7.2 · High

CVE-2024-33470

Published May 24, 2024

An issue in the SMTP Email Settings of AVTECH Room Alert 4E v4.4.0 allows attackers to gain access to credentials in plaintext via a passback attack. NOTE: This vulnerability only…

CVSS 4.9 · Medium

CVE-2024-31840

Published May 21, 2024

An issue was discovered in Italtel Embrace 1.6.4. The web application inserts cleartext passwords in the HTML source code. An authenticated user is able to edit the configuration…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31486

Published May 14, 2024

A vulnerability has been identified in OPUPI0 AMQP/MQTT (All versions < V5.30). The affected devices stores MQTT client passwords without sufficient protection on the devices. An…

CVSS 6.0 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2024-4840

Published May 14, 2024

An flaw was found in the OpenStack Platform (RHOSP) director, a toolset for installing and managing a complete RHOSP environment. Plaintext passwords may be stored in log files, w…

CVSS 5.5 · Medium

CVE-2023-27370

Published May 3, 2024

NETGEAR RAX30 Device Configuration Cleartext Storage Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information o…

CVSS 5.7 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2023-46294

Published May 1, 2024

An issue was discovered in Teledyne FLIR M300 2.00-19. User account passwords are encrypted locally, and can be decrypted to cleartext passwords using the utility umSetup. This ut…

CVSS 3.4 · Low

CVE-2024-28327

Published Apr 26, 2024

Asus RT-N12+ B1 router stores user passwords in plaintext, which could allow local attackers to obtain unauthorized access and modify router settings.

CVSS 8.4 · High

CVE-2024-31587

Published Apr 19, 2024

SecuSTATION Camera V2.5.5.3116-S50-SMA-B20160811A and lower allows an unauthenticated attacker to download device configuration files via a crafted request.

CVSS 6.5 · Medium

CVE-2024-3742

Published Apr 18, 2024

Electrolink transmitters store credentials in clear-text. Use of these credentials could allow an attacker to access the system.

CVSS 8.7 · High
Showing 251-275 of 813 CVEsPage 11 of 33