Skip to main content

CWE archive

CWE-312 CVEs

Programmatic archive

814 CVEs tagged with CWE-31248 Critical, 275 High, 445 Medium, 46 Low, 0 Unrated.

CVE-2021-25645

Published May 10, 2021

An issue was discovered in Couchbase Server before 6.0.5, 6.1.x through 6.5.x before 6.5.2, and 6.6.x before 6.6.1. An internal user with administrator privileges, @ns_server, lea…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22206

Published May 6, 2021

An issue has been discovered in GitLab affecting all versions starting from 11.6. Pull mirror credentials are exposed that allows other maintainers to be able to view the credenti…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-22783

Published Apr 28, 2021

Etherpad <1.8.3 stored passwords used by users insecurely in the database and in log files. This affects every database backend supported by Etherpad.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-25898

Published Apr 23, 2021

An issue was discovered in svc-login.php in Void Aural Rec Monitor 9.0.0.1. Passwords are stored in unencrypted source-code text files. This was noted when accessing the svc-login…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-31539

Published Apr 23, 2021

Wowza Streaming Engine before 4.8.8.01 (in a default installation) has cleartext passwords stored in the conf/admin.password file. A regular local user is able to read usernames a…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11923

Published Apr 2, 2021

An issue was discovered in WiZ Colors A60 1.14.0. API credentials are locally logged.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4944

Published Mar 30, 2021

IBM UrbanCode Deploy (UCD) 7.0.3.0, 7.0.4.0, 7.0.5.3, 7.0.5.4, 7.1.0.0, 7.1.1.0, 7.1.1.1, and 7.1.1.2, stores keystore passwords in plain text after a manual edit, which can be re…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4884

Published Mar 30, 2021

IBM UrbanCode Deploy (UCD) 6.2.7.9, 7.0.5.4, and 7.1.1.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 190908.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22194

Published Mar 26, 2021

In all versions of GitLab, marshalled session keys were being stored in Redis.

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21339

Published Mar 23, 2021

TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 user session identifiers were stored in c…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-35455

Published Mar 17, 2021

The Taidii Diibear Android application 2.4.0 and all its derivatives allow attackers to obtain user credentials from Shared Preferences and the SQLite database because of insecure…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-35454

Published Mar 17, 2021

The Taidii Diibear Android application 2.4.0 and all its derivatives allow attackers to obtain user credentials from an Android backup because of insecure application configuratio…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-26595

Published Feb 23, 2021

In Directus 8.x through 8.8.1, an attacker can learn sensitive information such as the version of the CMS, the PHP version used by the site, and the name of the DBMS, simply by vi…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-27549

Published Feb 22, 2021

Genymotion Desktop through 3.2.0 leaks the host's clipboard data to the Android application by default. NOTE: the vendor's position is that this is intended behavior that can be c…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-36248

Published Feb 19, 2021

The ownCloud application before 2.15 for Android allows attackers to use adb to include a PIN preferences value in a backup archive, and consequently bypass the PIN lock feature b…

CVSS 3.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-27233

Published Feb 16, 2021

An issue was discovered in Mutare Voice (EVM) 3.x before 3.3.8. On the admin portal of the web application, password information for external systems is visible in cleartext. The…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 576-600 of 814 CVEsPage 24 of 33