Skip to main content

CWE archive

CWE-312 CVEs

Programmatic archive

814 CVEs tagged with CWE-31248 Critical, 275 High, 445 Medium, 46 Low, 0 Unrated.

CVE-2021-38915

Published Oct 12, 2021

IBM Data Risk Manager 2.0.6 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 209947.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-38150

Published Sep 14, 2021

When an attacker manages to get access to the local memory, or the memory dump of a victim, for example by a social engineering attack, SAP Business Client versions - 7.0, 7.70, w…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-19137

Published Sep 8, 2021

Incorrect Access Control in Autumn v1.0.4 and earlier allows remote attackers to obtain clear-text login credentials via the component "autumn-cms/user/getAllUser/?page=1&limit=10…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-1865

Published Sep 8, 2021

An issue obscuring passwords in screenshots was addressed with improved logic. This issue is fixed in iOS 14.5 and iPadOS 14.5. A user's password may be visible on screen.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-36096

Published Sep 6, 2021

Generated Support Bundles contains private S/MIME and PGP keys if containing folder is not hidden. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and l…

CVSS 5.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22929

Published Aug 31, 2021

An information disclosure exists in Brave Browser Desktop prior to version 1.28.62, where logged warning messages that included timestamps of connections to V2 onion domains in to…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-31989

Published Aug 25, 2021

A user with permission to log on to the machine hosting the AXIS Device Manager client could under certain conditions extract a memory dump from the built-in Windows Task Manager…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-40087

Published Aug 25, 2021

An issue was discovered in PrimeKey EJBCA before 7.6.0. When audit logging changes to the alias configurations of various protocols that use an enrollment secret, any modification…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-30997

Published Aug 24, 2021

A S/MIME issue existed in the handling of encrypted email. This issue was addressed by not automatically loading some MIME parts. This issue is fixed in iOS 15.2 and iPadOS 15.2.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-36473

Published Aug 14, 2021

UCWeb UC 12.12.3.1219 through 12.12.3.1226 uses cleartext HTTP, and thus man-in-the-middle attackers can discover visited URLs.

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-37548

Published Aug 6, 2021

In JetBrains TeamCity before 2021.1, passwords in cleartext sometimes could be stored in VCS.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-37452

Published Jul 25, 2021

NCH Quorum v2.03 and earlier allows local users to discover cleartext login information relating to users by reading the local .dat configuration files.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 526-550 of 814 CVEsPage 22 of 33