CVE & Exploit Intelligence Database

Updated 42m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,123 CVEs tracked 53,219 with exploits 4,686 exploited in wild 1,539 CISA KEV 3,912 Nuclei templates 37,757 vendors 42,422 researchers
765 results Clear all
CVE-2024-55027 7.5 HIGH EPSS 0.00
Weintek cMT-3072XH2 v2.1.53 - Info Disclosure
Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to stroe credentials in plaintext in the component uac_temp.db.
CWE-312 Mar 03, 2026
CVE-2025-47147 5.7 MEDIUM EPSS 0.00
Command Centre Mobile Client <9.40.123 - Info Disclosure
Cleartext Storage of Sensitive Information (CWE-312) in the Command Centre Mobile Client on Android and iOS could allow an attacker with access to a logged-in Operator's mobile device to extract the session token and exploit access for a limited duration. This issue affects Command Centre Mobile Client versions prior to 9.40.123.
CWE-312 Mar 03, 2026
CVE-2026-3277 EPSS 0.00
PowerShell Universal <2026.1.3 - Info Disclosure
The OpenID Connect (OIDC) authentication configuration in PowerShell Universal before 2026.1.3 stores the OIDC client secret in cleartext in the .universal/authentication.ps1 script, which allows an attacker with read access to that file to obtain the OIDC client credentials
CWE-312 Feb 27, 2026
CVE-2026-3221 4.9 MEDIUM EPSS 0.00
Devolutions Server <2025.3.14 - Info Disclosure
Sensitive user account information is not encrypted in the database in Devolutions Server 2025.3.14 and earlier, which allows an attacker with access to the database to obtain sensitive user information via direct database access.
CWE-312 Feb 25, 2026
CVE-2026-27520 7.5 HIGH EPSS 0.00
Binardat 10G08-0800GSM <V300SP10260209 - Info Disclosure
Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209 store a user password in a client-side cookie as a Base64-encoded value accessible via the web interface. Because Base64 is reversible and provides no confidentiality, an attacker who can access the cookie value can recover the plaintext password.
CWE-312 Feb 24, 2026
CVE-2026-23655 6.5 MEDIUM EPSS 0.00
Azure Compute Gallery - Info Disclosure
Cleartext storage of sensitive information in Azure Compute Gallery allows an authorized attacker to disclose information over a network.
CWE-312 Feb 10, 2026
CVE-2026-24319 5.8 MEDIUM EPSS 0.00
SAP Business One - Info Disclosure
In SAP Business One, sensitive information is written to the application�s memory dump files without obfuscation. Gaining access to this information could potentially lead to unauthorized operations within the B1 environment, including modification of company data. This issue results in a high impact on confidentiality and integrity, with no impact on availability.
CWE-316 Feb 10, 2026
CVE-2025-10464 6.5 MEDIUM EPSS 0.00
Birtech Senseway <09022026 - Info Disclosure
Insecure Storage of Sensitive Information vulnerability in Birtech Information Technologies Industry and Trade Ltd. Co. Senseway allows Retrieve Embedded Sensitive Data.This issue affects Senseway: through 09022026. NOTE: Because the product was developed using outdated technology, the manufacturer is unable to fix the relevant vulnerabilities. Users of the Sensaway application are advised to contact the manufacturer and review updated products developed with newer technology.
CWE-922 Feb 09, 2026
CVE-2026-25751 7.5 HIGH EPSS 0.00
Frangoteam Fuxa < 1.2.10 - Missing Authentication
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An information disclosure vulnerability in FUXA allows an unauthenticated, remote attacker to retrieve sensitive administrative database credentials. Exploitation allows an unauthenticated, remote attacker to obtain the full system configuration, including administrative credentials for the InfluxDB database. Possession of these credentials may allow an attacker to authenticate directly to the database service, enabling them to read, modify, or delete all historical process data, or perform a Denial of Service by corrupting the database. This affects FUXA through version 1.2.9. This issue has been patched in FUXA version 1.2.10.
CWE-306 Feb 06, 2026
CVE-2025-33081 3.3 LOW EPSS 0.00
IBM Concert <2.1.0 - Info Disclosure
IBM Concert 1.0.0 through 2.1.0 stores potentially sensitive information in log files that could be read by a local user.
CWE-312 Feb 03, 2026
CVE-2025-12774 7.5 HIGH EPSS 0.00
Brocade SANnav <3.0 - Info Disclosure
A vulnerability in the migration script for Brocade SANnav before 3.0 could allow the collection of database sql queries in the SANnav support save file. An attacker with access to Brocade SANnav supportsave file, could open the file and then obtain sensitive information such as details of database tables and encrypted passwords.
CWE-312 Feb 03, 2026
CVE-2025-12772 4.9 MEDIUM EPSS 0.00
Brocade SANnav <2.4.0b - Info Disclosure
Brocade SANnav before 2.4.0b logs the Brocade Fabric OS Switch admin password on the SANnav support save logs. When OOM occurs on a Brocade SANnav server, the call stack trace for the Brocade switch is also collected in the heap dump file which contains this switch password in clear text. The vulnerability could allow a remote authenticated attacker with admin privilege able to access the SANnav logs or the supportsave to read the switch admin password.
CWE-312 Feb 02, 2026
CVE-2025-12680 4.9 MEDIUM EPSS 0.00
Brocade SANnav <2.4.0b - Info Disclosure
Brocade SANnav before Brocade SANnav 2.4.0b logs database passwords in clear text in the standby SANnav server, after disaster recovery failover. The vulnerability could allow a remote authenticated attacker with admin privilege able to access the SANnav logs or the supportsave to read the database password.
CWE-256 Feb 02, 2026
CVE-2025-12679 6.5 MEDIUM EPSS 0.00
Brocade SANnav <2.4.0b - Info Disclosure
A vulnerability in Brocade SANnav before 2.4.0b prints the Password-Based Encryption (PBE) key in plaintext in the system audit log file. The vulnerability could allow a remote authenticated attacker with access to the audit logs to access the pbe key. Note: The vulnerability is only triggered during a migration and not in a new installation. The system audit logs are accessible only to a privileged user on the server. These audit logs are the local server VM’s audit logs and are not controlled by SANnav. These logs are only visible to the server admin of the host server and are not visible to the SANnav admin or any SANnav user.
CWE-312 Feb 02, 2026
CVE-2024-9432 EPSS 0.00
OpenText Vertica <25.X - Info Disclosure
Cleartext Storage of Sensitive Information vulnerability in OpenText™ Vertica allows Retrieve Embedded Sensitive Data.   The vulnerability could read Vertica agent plaintext apikey.This issue affects Vertica versions: 23.X, 24.X, 25.X.
CWE-312 Jan 30, 2026
CVE-2025-59105 EPSS 0.00
Linux-based K7 - Info Disclosure
With physical access to the device and enough time an attacker can desolder the flash memory, modify it and then reinstall it because of missing encryption. Thus, essential files, such as "/etc/passwd", as well as stored certificates, cryptographic keys, stored PINs and so on can be modified and read, in order to gain SSH root access on the Linux-based K7 model. On the Windows CE based K5 model, the password for the Access Manager can additionally be read in plain text from the stored SQLite database.
CWE-312 Jan 26, 2026
CVE-2025-59102 EPSS 0.00
Access Manager - Info Disclosure
The web server of the Access Manager offers a functionality to download a backup of the local database stored on the device. This database contains the whole configuration. This includes encrypted MIFARE keys, card data, user PINs and much more. The PINs are even stored unencrypted. Combined with the fact that an attacker can easily get access to the backup functionality by abusing the session management issue (CVE-2025-59101), or by exploiting the weak default password (CVE-2025-59108), or by simply setting a new password without prior authentication via the SOAP API (CVE-2025-59097), it is easily possible to access the sensitive data on the device.
CWE-312 Jan 26, 2026
CVE-2026-22276 5.5 MEDIUM EPSS 0.00
Dell ECS <3.8.1.7 & Dell ObjectScale <4.2.0.0 - Info Disclosure
Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Storage of Sensitive Information vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
CWE-312 Jan 23, 2026
CVE-2025-14377 EPSS 0.00
Verve Asset Manager - Info Disclosure
A security issue was discovered within the legacy Ansible playbook component of Verve Asset Manager, caused by plaintext secrets incorrectly stored when a playbook is running. This component has been retired and has been optional since the 1.36 release in 2024.
CWE-312 Jan 20, 2026
CVE-2026-22240 7.5 HIGH EPSS 0.00
Blusparkglobal Bluvoyix - Information Disclosure
The vulnerability exists in BLUVOYIX due to an improper password storage implementation and subsequent exposure via unauthenticated APIs. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable users API to retrieve the plaintext passwords of all user users. Successful exploitation of this vulnerability could allow the attacker to gain full access to customers' data and completely compromise the targeted platform by logging in using an exposed admin email address and password.
CWE-522 Jan 14, 2026