Skip to main content

CWE archive

CWE-312 CVEs

Programmatic archive

814 CVEs tagged with CWE-31248 Critical, 275 High, 445 Medium, 46 Low, 0 Unrated.

CVE-2024-3742

Published Apr 18, 2024

Electrolink transmitters store credentials in clear-text. Use of these credentials could allow an attacker to access the system.

CVSS 8.7 · High

CVE-2024-32474

Published Apr 18, 2024

Sentry is an error tracking and performance monitoring platform. Prior to 24.4.1, when authenticating as a superuser to Sentry with a username and password, the password is leaked…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-29956

Published Apr 18, 2024

A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints the Brocade SANnav password in clear text in supportsave logs when a user schedules a switch Supportsave from Br…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-29952

Published Apr 17, 2024

A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow an authenticated user to print the Auth, Priv, and SSL key store passwords in unencrypted logs by manipulat…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23584

Published Apr 8, 2024

The NMAP Importer service​ may expose data store credentials to authorized users of the Windows Registry.

CVSS 6.6 · Medium

CVE-2024-28065

Published Apr 5, 2024

In Unify CP IP Phone firmware 1.10.4.3, files are not encrypted and contain sensitive information such as the root password hash.

CVSS 5.9 · Medium

CVE-2024-28387

Published Mar 25, 2024

An issue in axonaut v.3.1.23 and before allows a remote attacker to obtain sensitive information via the log.txt component.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-49341

Published Mar 9, 2024

An issue was discovered in Newland Nquire 1000 Interactive Kiosk version NQ1000-II_G_V1.00.011, allows remote attackers to obtain sensitive information via cleartext credential st…

CVSS 7.5 · High

CVE-2023-50957

Published Feb 10, 2024

IBM Storage Defender - Resiliency Service 2.0 could allow a privileged user to perform unauthorized actions after obtaining encrypted data from clear text key storage. IBM X-Forc…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-24488

Published Feb 7, 2024

An issue in Shenzen Tenda Technology CP3V2.0 V11.10.00.2311090948 allows a local attacker to obtain sensitive information via the password component.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6250

Published Dec 26, 2023

The BestWebSoft's Like & Share WordPress plugin before 2.74 discloses the content of password protected posts to unauthenticated users via a meta tag

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-50294

Published Dec 26, 2023

The App Settings (/admin/app) page in GROWI versions prior to v6.0.6 stores sensitive information in cleartext form. As a result, the Secret access key for external service may be…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-50719

Published Dec 15, 2023

XWiki Platform is a generic wiki platform. Starting in 7.2-milestone-2 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the Solr-based search in XWiki discloses the password…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-50777

Published Dec 13, 2023

Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier does not mask PaaSLane authentication tokens displayed on the job configuration form, increasing the potential for attackers to…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-50776

Published Dec 13, 2023

Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier stores PaaSLane authentication tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-50773

Published Dec 13, 2023

Jenkins Dingding JSON Pusher Plugin 2.0 and earlier does not mask access tokens displayed on the job configuration form, increasing the potential for attackers to observe and capt…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-50772

Published Dec 13, 2023

Jenkins Dingding JSON Pusher Plugin 2.0 and earlier stores access tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 276-300 of 814 CVEsPage 12 of 33