CWE-256

High likelihood

Plaintext Storage of a Password

Parent: CWE-522 - Insufficiently Protected Credentials

The product stores a password in plaintext within resources such as memory or files.

215 vulnerabilities with CWE-256
CVE-2024-49370 MEDIUM
Pimcore <4.1.7, <3.1.16 - Info Disclosure
CVSS 4.9
CVE-2024-42496 LOW
Smart-tab Android <April 2023 - Info Disclosure
CVSS 2.4
CVE-2024-31899 MEDIUM
IBM Cognos Command Center <10.2.5 - Info Disclosure
CVSS 4.3
CVE-2024-5960 CRITICAL
Eliz Software Panel <2.3.24 - Info Disclosure
CVSS 9.8
CVE-2024-20489 HIGH
Cisco IOS XR - Authenticated MongoDB Credential Exposure via PON Controller Configuration File
CVSS 8.4
CVE-2024-44815 MEDIUM
Hathway Skyworth Router CM5100 <4.1.1.24 - Info Disclosure
CVSS 4.6
CVE-2024-45283 MEDIUM
SAP NetWeaver AS for Java - Info Disclosure
CVSS 6.0
CVE-2024-43378 HIGH
calamares-nixos-extensions - Info Disclosure
CVSS 7.8
CVE-2024-25024 MEDIUM
IBM QRadar Suite Software <1.10.23.0 & Cloud Pak for Security <1.10...
CVSS 5.5
CVE-2024-39922 MEDIUM
Siemens LOGO! and SIPLUS LOGO! - Plaintext Password Storage
CVSS 4.6
CVE-2024-36460 HIGH
Zabbix - Plaintext Password Disclosure in Front-End Audit Log
CVSS 8.1
CVE-2024-6118 CRITICAL
Hamastar MeetingHub Paperless Meetings 2021 - Info Disclosure
CVSS 9.1
CVE-2024-3082 MEDIUM
Proges Sensor Net Connect Firmware - Plaintext Password Storage
CVSS 4.2
CVE-2024-37135 LOW
Dell DM5500 Firmware < 5.17.0.0 - Plaintext Password Storage
CVSS 3.3
CVE-2024-40116 HIGH
Solar-Log 1000 < 2.8.2 - Plaintext Storage of Passwords in Export and Notification Files
CVSS 8.1
CVE-2024-39733 MEDIUM
IBM Datacap Navigator <9.1.10 - Info Disclosure
CVSS 5.5
CVE-2024-39220 MEDIUM
BAS-IP AV and AA Series < v3.9.2 - Authenticated Plaintext Password Exposure via SIP Account Request
CVSS 6.5
CVE-2024-33375 CRITICAL
LB-LINK BL-W1210M v2.0 - Info Disclosure
CVSS 9.8
CVE-2024-27166 HIGH
Toshiba Tec e-Studio multi-function peripheral (MFP) - Plaintext Password Exposure via Coredump Permissions
CVSS 7.4
CVE-2024-25052 MEDIUM
IBM Jazz Reporting Service 7.0.3 - Info Disclosure
CVSS 4.4
CVE-2024-28736 HIGH
Debezium Community debezium-ui <2.5 - RCE
CVSS 7.1
CVE-2024-36081 CRITICAL
Westermo EDW-100 through 2024-05-03 - Unauthenticated Plaintext Password Exposure in Configuration File
CVSS 9.8
CVE-2024-4425 MEDIUM
CemiPark 4.5 4.7 5.03 - Plaintext Password Storage in Integration Credentials
CVSS 5.4
CVE-2024-4232 MEDIUM
Digisol Router <3.2.02 - Info Disclosure
CVSS 4.1
CVE-2024-28971 LOW
Dell Update Manager Plugin <1.5.0 - Info Disclosure
CVSS 3.5
Details
Vulnerabilities 215
Exploit Likelihood High