Skip to main content

CWE archive

CWE-312 CVEs

Programmatic archive

814 CVEs tagged with CWE-31248 Critical, 275 High, 445 Medium, 46 Low, 0 Unrated.

CVE-2020-22741

Published Jul 19, 2021

An issue was discovered in Xuperchain 3.6.0 that allows for attackers to recover any arbitrary users' private key after obtaining the partial signature in multisignature.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-31817

Published Jul 8, 2021

When configuring Octopus Server if it is configured with an external SQL database, on initial configuration the database password is written to the OctopusServer.txt log file in p…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-31816

Published Jul 8, 2021

When configuring Octopus Server if it is configured with an external SQL database, on initial configuration the database password is written to the OctopusServer.txt log file in p…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-36158

Published Jul 5, 2021

In the xrdp package (in branches through 3.14) for Alpine Linux, RDP sessions are vulnerable to man-in-the-middle attacks because pre-generated RSA certificates and private keys a…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-29481

Published Jun 29, 2021

Ratpack is a toolkit for creating web applications. In versions prior to 1.9.0, the default configuration of client side sessions results in unencrypted, but signed, data being se…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-29956

Published Jun 24, 2021

OpenPGP secret keys that were imported using Thunderbird version 78.8.1 up to version 78.10.1 were stored unencrypted on the user's local disk. The master password protection was…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-29954

Published Jun 24, 2021

Proxy functionality built into Hubs Cloud’s Reticulum software allowed access to internal URLs, including the metadata service. This vulnerability affects Hubs Cloud < mozillareal…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-29950

Published Jun 24, 2021

Thunderbird unprotects a secret OpenPGP key prior to using it for a decryption, signing or key import task. If the task runs into a failure, the secret key may remain in memory in…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-27487

Published Jun 16, 2021

ZOLL Defibrillator Dashboard, v prior to 2.2, The affected products contain credentials stored in plaintext. This could allow an attacker to gain access to sensitive information.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-23211

Published Jun 11, 2021

Cleartext Storage of Sensitive Information in Memory vulnerability in Gallagher Command Centre Server allows Cloud end-to-end encryption key to be discoverable in server memory du…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-23182

Published Jun 11, 2021

Cleartext Storage of Sensitive Information in Memory vulnerability in Gallagher Command Centre Server allows OSDP reader master keys to be discoverable in server memory dumps. Thi…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15384

Published Jun 9, 2021

Brocade SANNav before version 2.1.1 contains an information disclosure vulnerability. Successful exploitation of internal server information in the initial login response header.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-31855

Published Jun 2, 2021

KDE Messagelib through 5.17.0 reveals cleartext of encrypted messages in some situations. Deleting an attachment of a decrypted encrypted message stored on a remote server (e.g.,…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21734

Published May 28, 2021

Some PON MDU devices of ZTE stored sensitive information in plaintext, and users with login authority can obtain it by inputing command. This affects: ZTE PON MDU device ZXA10 F82…

CVSS 6.5 · Medium

CVE-2018-16498

Published May 26, 2021

In Versa Director, the unencrypted backup files stored on the Versa deployment contain credentials stored within configuration files. These credentials are for various application…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-25644

Published May 19, 2021

An issue was discovered in Couchbase Server 5.x and 6.x through 6.6.1 and 7.0.0 Beta. Incorrect commands to the REST API can result in leaked authentication information being stor…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-30183

Published May 14, 2021

Cleartext storage of sensitive information in multiple versions of Octopus Server where in certain situations when running import or export processes, the password used to encrypt…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 551-575 of 814 CVEsPage 23 of 33