CWE-256

High likelihood

Plaintext Storage of a Password

Parent: CWE-522 - Insufficiently Protected Credentials

The product stores a password in plaintext within resources such as memory or files.

215 vulnerabilities with CWE-256
CVE-2025-7357 HIGH
LITEON IC48A <01.00.19r - Info Disclosure
CVE-2025-53677 MEDIUM
Jenkins Xooa Plugin <0.0.7 - Info Disclosure
CVSS 5.3
CVE-2025-53675 MEDIUM
Jenkins Warrior Framework Plugin <1.2 - Info Disclosure
CVSS 6.5
CVE-2025-53674 MEDIUM
Jenkins Sensedia Api Platform tools Plugin 1.0 - Info Disclosure
CVSS 5.3
CVE-2025-53671 MEDIUM
Jenkins Nouvola DiveCloud Plugin <1.08 - Info Disclosure
CVSS 6.5
CVE-2025-53669 MEDIUM
Jenkins VAddy Plugin <1.2.8 - Info Disclosure
CVSS 4.3
CVE-2025-53665 MEDIUM
Jenkins Apica Loadtest Plugin <1.10 - Info Disclosure
CVSS 4.3
CVE-2025-53664 MEDIUM
Jenkins Apica Loadtest Plugin <1.10 - Info Disclosure
CVSS 6.5
CVE-2025-53662 MEDIUM
Jenkins IFTTT Build Notifier Plugin 1.2- - Info Disclosure
CVSS 6.5
CVE-2025-53660 MEDIUM
Jenkins QMetry Test Management Plugin <1.13 - Info Disclosure
CVSS 4.3
CVE-2025-53656 MEDIUM
Jenkins ReadyAPI Functional Testing Plugin <1.11 - Info Disclosure
CVSS 6.5
CVE-2025-53655 MEDIUM
Jenkins Statistics Gatherer Plugin <2.0.3 - Info Disclosure
CVSS 5.3
CVE-2025-1709 MEDIUM
endress meac300-fnade4_firmware < 0.16.0 - Plaintext Storage of PostgreSQL Credentials
CVSS 6.5
CVE-2025-6561 CRITICAL
Hunt Electronic Hybrid DVR - Info Disclosure
CVSS 9.8
CVE-2025-6560 CRITICAL
Sapido Wireless Router - Info Disclosure
CVSS 9.8
CVE-2025-5893 CRITICAL
Smart Parking Management System - Info Disclosure
CVSS 9.8
CVE-2025-5760 MEDIUM
Simple History <5.8.1 - Info Disclosure
CVSS 4.9
CVE-2025-2500 HIGH
Hitachi Energy Asset Suite 9.6.4.4-9.7 - Plaintext Password Storage in SOAP Web Services
CVSS 7.4
CVE-2025-48046 MEDIUM
NetFax Server < 3.0.1.0 - Authenticated Cleartext Password Exposure via SMTP Config Endpoint
CVE-2025-33079 MEDIUM
IBM Controller <11.1.0 - Info Disclosure
CVSS 6.5
CVE-2025-43005 MEDIUM
SAP GUI for Windows - Info Disclosure
CVSS 4.3
CVE-2025-3758 HIGH
Netis Systems WF2220 - Unauthenticated Plaintext Password Exposure via netcore_get.cgi Endpoint
CVE-2025-0936 MEDIUM
Arista EOS 4.30.1F-4.30.8M, 4.31.0-4.31.4M, 4.32.0-4.32.2M, 4.33.0 - Plaintext Password Exposure
CVSS 6.5
CVE-2025-4286 LOW
Intelbras InControl <2.21.59 - Info Disclosure
CVSS 2.7
CVE-2025-2770 MEDIUM
BEC Technologies Router Firmware - Authenticated Cleartext Storage of Sensitive Information in Web Interface
CVSS 6.5
Details
Vulnerabilities 215
Exploit Likelihood High