Skip to main content

CWE archive

CWE-312 CVEs

Programmatic archive

813 CVEs tagged with CWE-31248 Critical, 274 High, 445 Medium, 46 Low, 0 Unrated.

CVE-2020-26288

Published Dec 30, 2020

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. It is an npm package "parse-server". In Parse Server before version 4.5.0,…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13473

Published Dec 28, 2020

NCH Express Accounts 8.24 and earlier allows local users to discover the cleartext password by reading the configuration file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-29550

Published Dec 23, 2020

An issue was discovered in URVE Build 24.03.2020. The password of an integration user account (used for the connection of the MS Office 365 Integration Service) is stored in clear…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-17511

Published Dec 14, 2020

In Airflow versions prior to 1.10.13, when creating a user using airflow CLI, the password gets logged in plain text in the Log table in Airflow Metadatase. Same happened when cre…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-26816

Published Dec 9, 2020

SAP AS JAVA (Key Storage Service), versions - 7.10, 7.11, 7.20 ,7.30, 7.31, 7.40, 7.50, has the key material which is stored in the SAP NetWeaver AS Java Key Storage service store…

CVSS 4.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-25677

Published Dec 8, 2020

A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions. This flaw allows any user on the system to read sensit…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26228

Published Nov 23, 2020

TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.23 and 10.4.10 user session identifiers were stored in cleartext - without processing…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-26551

Published Nov 17, 2020

An issue was discovered in Aviatrix Controller before R5.3.1151. Encrypted key values are stored in a readable file.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-8276

Published Nov 9, 2020

The implementation of Brave Desktop's privacy-preserving analytics system (P3A) between 1.1 and 1.18.35 logged the timestamp of when the user last opened an incognito window, incl…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-27986

Published Oct 28, 2020

SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. NOTE: reportedly, the vendor's position for…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-27613

Published Oct 21, 2020

The installation procedure in BigBlueButton before 2.2.28 (or earlier) uses ClueCon as the FreeSWITCH password, which allows local users to achieve unintended FreeSWITCH access.

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2020-6648

Published Oct 21, 2020

A cleartext storage of sensitive information vulnerability in FortiOS command line interface in versions 6.2.4 and earlier and FortiProxy 2.0.0, 1.2.9 and earlier may allow an aut…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4619

Published Sep 22, 2020

IBM Data Risk Manager (iDNA) 2.0.6 stores user credentials in plain in clear text which can be read by an authenticated user. IBM X-Force ID: 184976.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-8225

Published Sep 18, 2020

A cleartext storage of sensitive information in Nextcloud Desktop Client 2.6.4 gave away information about used proxies and their authentication credentials.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-2274

Published Sep 16, 2020

Jenkins ElasTest Plugin 1.2.1 and earlier stores its server password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with ac…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15784

Published Sep 9, 2020

A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP8). Insecure storage of sensitive information in the configuration files could allow the retrieval…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 626-650 of 813 CVEsPage 26 of 33