CWE-312

Cleartext Storage of Sensitive Information

Parent: CWE-311 - Missing Encryption of Sensitive Data

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

817 vulnerabilities with CWE-312
CVE-2026-59327 MEDIUM
Cleartext Storage of Spring Boot DevTools Remote Secret in Eclipse Launch Configurations
CVSS 4.4
CVE-2026-55985 MEDIUM
Tycon Systems TPDIN-Monitor-WEB2 Cleartext Storage of Sensitive Information
CVSS 4.3
CVE-2026-16802 MEDIUM
Devolutions PowerShell Universal < 2026.2.3 - Cleartext Storage of Sensitive Information
CVSS 6.5
CVE-2026-65599 MEDIUM
n8n before 1.123.64 Credential Exposure via JWT Header
CVSS 6.5
CVE-2026-13380 CRITICAL
VSee Clinic and API Exposes Cleartext SFTP Credentials in Unauthenticated HTTP Responses
CVE-2026-16213 LOW
Fantomas42 django-blog-zinnia Protected Entry Password entry_protection.py cleartext storage
CVSS 3.3
CVE-2026-55885 MEDIUM
Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets
CVSS 6.8
CVE-2026-8804 MEDIUM
Cleartext Storage of Sensitive Information for Puppet Resource API
CVE-2026-38571 MEDIUM
Tenda N300 F3 V603 - Unauthenticated WPA2 Credential Exposure and Memory R/W via UART
CVSS 4.6
CVE-2026-57287 MEDIUM
Jenkins Job Configuration History Plugin - Cleartext Storage of Sensitive Information
CVSS 4.3
CVE-2026-50267 MEDIUM
Steeltoe: TLS private keys written to /tmp with default permissions, never deleted
CVSS 4.7
CVE-2026-46622 HIGH
SolidInvoice: API tokens stored as plaintext in the database allowing full credential compromise on database breach
CVSS 8.1
CVE-2026-10786 MEDIUM
Devolutions Server - Cleartext Storage of Sensitive Information
CVSS 6.5
CVE-2026-36176 HIGH
GNCC GP5 7.1.76 - Unauthorized Operations via Plaintext Backblaze B2 Upload URL Exposure
CVSS 7.1
CVE-2026-4387 LOW
Unencrypted storage of authentication state in StrongDM Desktop Application state.kv file
CVE-2026-45040 MEDIUM
RustFS: Sensitive Information Leakage (SessionToken and SecretAccessKey) in RustFS Logs [Debug Mode]
CVE-2026-9274 MEDIUM
Information Exposure Vulnerability in CP-Plus Wi-Fi Camera
CVE-2026-8596 HIGH
Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK ModelBuilder/Serve path
CVSS 7.2
CVE-2026-6332 HIGH
Clear Text Storage of Sensitive Information on EcoStruxure™ Machine Expert HVAC
CVSS 7.5
CVE-2026-42408 MEDIUM
F5 BIG-IP DNS tmsh - Sensitive Information Disclosure
CVSS 4.4
CVE-2026-28758 MEDIUM
BIG-IP - Cleartext Storage of Sensitive Information in iControl REST Response and Audit Log
CVSS 4.4
CVE-2026-43992 CRITICAL
JunoClaw: MCP write tools exposed raw BIP-39 mnemonic as a tool-call parameter
CVSS 9.8
CVE-2026-45362 LOW
Sangoma Switchvox < 8.4 - Cleartext Storage of Sensitive Information in Backup File
CVSS 3.2
CVE-2026-41520 HIGH
Cillium exposes sensitive information included in the cilium-bugtool debug archive
CVSS 7.9
CVE-2026-43942 MEDIUM
electerm: Full process.env exposed to renderer via window.pre.env in electerm
CVSS 5.5
Details
Vulnerabilities 817