CWE-256

High likelihood

Plaintext Storage of a Password

Parent: CWE-522 - Insufficiently Protected Credentials

The product stores a password in plaintext within resources such as memory or files.

200 vulnerabilities with CWE-256
CVE-2026-6597 LOW
langflow-ai langflow Flow Using API core.py has_api_terms credentials storage
CVSS 2.7
CVE-2026-35556 HIGH
Plaintext storage of a password in OpenPLC_V3
CVSS 7.5
CVE-2026-33216 HIGH
NATS has MQTT plaintext password disclosure
CVSS 8.6
CVE-2026-31850 MEDIUM
Plaintext storage of credentials in configuration backup in Nexxt Nebula 300+
CVSS 4.9
CVE-2026-4251 LOW
CityData CityChat ai.citydata.citychat credentials.json credentials storage
CVSS 2.5
CVE-2026-4250 LOW
Albert Sağlık Hizmetleri ve Ticaret Albert Health Google Cloud Service Account Key service-account.json credentials storage
CVSS 2.5
CVE-2026-4243 LOW
La Nacion App app.lanacion.activity BuildConfig.java credentials storage
CVSS 2.5
CVE-2026-4242 LOW
BabyChakra Pregnancy & Parenting App app.babychakra.babychakra Configuration.java credentials storage
CVSS 2.5
CVE-2026-4217 LOW
XREAL Nebula App ai.nreal.nebula.universal CloudStoragePlugin.java key management
CVSS 2.5
CVE-2026-22285 MEDIUM
Dell DDMA <26.02 - Info Disclosure
CVSS 4.4
CVE-2026-28360 MEDIUM
NocoDB <0.301.3 - Info Disclosure
CVSS 5.3
CVE-2026-21660 CRITICAL
Frick Controls Quantum HD <10.22 - Info Disclosure
CVSS 9.8
CVE-2026-23797 MEDIUM
Quick.Cart <6.7 - Info Disclosure
CVSS 4.9
CVE-2026-21417 HIGH
Dell CloudBoost Virtual Appliance <19.14.0.0 - Privilege Escalation
CVSS 7.0
CVE-2025-36335 MEDIUM
Vulnerabilities found
CVSS 6.2
CVE-2025-15624 CRITICAL
Plaintext Storage of a Password in Sparx Pro Cloud Server.
CVE-2025-36258 HIGH
IBM InfoSphere Information Server is vulnerable due to plaintext storage of a password
CVSS 7.1
CVE-2025-36425 MEDIUM
IBM Db2 11.5.0-11.5.9/12.1.0-12.1.3 - Info Disclosure
CVSS 5.3
CVE-2025-12680 MEDIUM
Brocade SANnav <2.4.0b - Info Disclosure
CVSS 4.9
CVE-2025-25051 MEDIUM
Unknown - Info Disclosure
CVSS 6.1
CVE-2025-15113 CRITICAL
Ksenia Security Lares 4.0 Home Automation <1.6 - Code Injection
CVSS 9.3
CVE-2025-15128 MEDIUM
ZKTeco BioTime <9.0.3/9.0.4/9.5.2 - Info Disclosure
CVSS 5.3
CVE-2025-66910 MEDIUM
Turms Server v0.10.0-SNAPSHOT - Info Disclosure
CVSS 6.0
CVE-2025-65009 HIGH
WODESYS WD-R608U - Info Disclosure
CVE-2025-14183 MEDIUM
SGAI Space1 NAS N1211DS <1.0.915 - Info Disclosure
CVSS 4.3
Details
Vulnerabilities 200
Exploit Likelihood High