CWE-256

High likelihood

Plaintext Storage of a Password

Parent: CWE-522 - Insufficiently Protected Credentials

The product stores a password in plaintext within resources such as memory or files.

215 vulnerabilities with CWE-256
CVE-2023-39452 HIGH
Socomec Modulys GP Firmware - Unauthenticated Plaintext Password Exposure via Session Management Issue
CVSS 7.5
CVE-2023-4984 MEDIUM
didi KnowSearch <0.3.2/0.3.1.2 - Info Disclosure
CVSS 4.3
CVE-2023-4400 MEDIUM
Skyhigh Secure Web Gateway <11.2.14,10.2.25,12.2.1 - Info Disclosure
CVSS 6.2
CVE-2023-4918 HIGH
Keycloak 22.0.2 - Cleartext Transmission of Sensitive Information via User Registration Form
CVSS 8.8
CVE-2023-39227 MEDIUM
Softneta MedDream PACS - Info Disclosure
CVSS 6.1
CVE-2023-35067 HIGH
Infodrom Software E-Invoice Approval System <v.20230701 - Info Disc...
CVSS 7.5
CVE-2023-35765 MEDIUM
PiiGAB M-Bus 900s Firmware - Plaintext Password Storage
CVSS 6.5
CVE-2023-3395 MEDIUM
TWinSoft Configuration Tool - Info Disclosure
CVSS 6.5
CVE-2023-26204 LOW
FortiSIEM 5.3.0-6.7 - Plaintext Password Storage
CVSS 3.7
CVE-2023-2633 MEDIUM
Jenkins Code Dx Plugin <3.1.0 - Info Disclosure
CVSS 4.3
CVE-2023-2632 MEDIUM
Jenkins Code Dx Plugin <3.1.0 - Info Disclosure
CVSS 4.3
CVE-2023-0457 HIGH
Mitsubishi Electric Corporation MELSEC - Info Disclosure
CVSS 7.5
CVE-2023-22389 MEDIUM
Snap One Wattbox WB-300-IP-3 <WB10.9a17 - Info Disclosure
CVSS 5.7
CVE-2022-0555 HIGH
Subiquity < 22.02.1 - Plaintext Storage of a Password
CVSS 8.4
CVE-2022-47561 HIGH
Ormazabal ekorCCP and ekorrCI Firmware - Unauthenticated Credential Exposure via admin.xml
CVSS 7.3
CVE-2022-3261 MEDIUM
Red Hat OpenStack Platform - Cleartext Transmission of Sensitive Information in /var/log/messages
CVSS 4.4
CVE-2022-4308 MEDIUM
Secomea GateManager - Info Disclosure
CVSS 6.1
CVE-2022-22458 MEDIUM
IBM Security Verify Governance, Identity Manager 10.0.1 - Info Disc...
CVSS 6.3
CVE-2022-41732 MEDIUM
IBM Maximo Mobile <8.9 - Info Disclosure
CVSS 6.2
CVE-2022-43958 HIGH
QMS Automotive <V12.39 - Info Disclosure
CVSS 7.6
CVE-2022-3644 MEDIUM
pulp_ansible - Insufficiently Protected Credentials via Plaintext Token Storage
CVSS 5.5
CVE-2022-43426 MEDIUM
Jenkins S3 Explorer Plugin <1.0.8 - Info Disclosure
CVSS 5.3
CVE-2022-3287 MEDIUM
fwupd < 1.8.5 - Unauthenticated Sensitive Information Exposure via Redfish Plugin Configuration
CVSS 6.5
CVE-2022-36308 CRITICAL
Airspan AirVelocity <15.18.00.2511 - Info Disclosure
CVSS 9.1
CVE-2022-33928 MEDIUM
Dell Wyse Management Suite <3.6.1 - Info Disclosure
CVSS 6.4
Details
Vulnerabilities 215
Exploit Likelihood High