CWE-312

Cleartext Storage of Sensitive Information

Parent: CWE-311 - Missing Encryption of Sensitive Data

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

786 vulnerabilities with CWE-312
CVE-2026-7163 MEDIUM
Assisted-service: assisted-service: authenticated users can gain administrative access to openshift clusters via credential disclosure
CVSS 6.1
CVE-2026-41385 MEDIUM
OpenClaw < 2026.3.31 - Nostr Private Key Exposure via config.get Redaction Bypass
CVSS 6.5
CVE-2026-6796 MEDIUM
Sanluan PublicCMS Failed Login LoginAdminController.java log_login cleartext storage in file
CVSS 4.3
CVE-2026-6553 HIGH
TYPO3 CMS Stores Cleartext Password in User Settings Module
CVE-2026-6598 MEDIUM
langflow-ai langflow Project Creation Endpoint projects.py encrypt_auth_settings cleartext storage in file
CVSS 4.3
CVE-2026-35644 MEDIUM
OpenClaw < 2026.3.22 - Credential Exposure via baseUrl Fields in Gateway Snapshots
CVSS 6.5
CVE-2026-39943 MEDIUM
Directus exposes sensitive fields in revision history
CVSS 6.5
CVE-2026-5531 MEDIUM
SourceCodester Student Result Management System HTTP GET Request login_credentials.txt cleartext storage in file
CVSS 5.3
CVE-2026-34833 HIGH
Bulwark Webmail: Information Exposure: password returned in /api/auth/session
CVSS 7.5
CVE-2026-34214 HIGH
Trino: Iceberg REST catalog static and vended credentials are accessible via query JSON
CVSS 7.7
CVE-2026-33026 CRITICAL
nginx-ui Backup Restore Allows Tampering with Encrypted Backups
CVSS 9.1
CVE-2026-33867 HIGH
AVideo has Plaintext Video Password Storage
CVSS 7.5
CVE-2026-4346 MEDIUM
Cleartext Storage of Administrative and Wi-Fi Credentials via Accessible Serial Interface in TP Link's TL-WR850N
CVSS 6.8
CVE-2026-33512 HIGH
WWBN AVideo <=26.0 - Info Disclosure
CVSS 7.5
CVE-2026-31848 CRITICAL
Reversible ecos_pw cookie allows administrative authentication in Nexxt Nebula 300+
CVSS 9.8
CVE-2026-33003 MEDIUM
Jenkins LoadNinja Plugin <=2.1 - Info Disclosure
CVSS 4.3
CVE-2026-32842 MEDIUM
Edimax GS-5008PL <= 1.00.54 Admin Credentials Stored in Cleartext
CVSS 6.5
CVE-2026-24311 MEDIUM
SAP Customer Checkout - Memory Corruption
CVSS 5.6
CVE-2026-3277 MEDIUM
PowerShell Universal <2026.1.3 - Info Disclosure
CVSS 6.5
CVE-2026-3221 MEDIUM
Devolutions Server <2025.3.14 - Info Disclosure
CVSS 4.9
CVE-2026-27520 HIGH
Binardat 10G08-0800GSM <V300SP10260209 - Info Disclosure
CVSS 7.5
CVE-2026-23655 MEDIUM
Azure Compute Gallery - Info Disclosure
CVSS 6.5
CVE-2026-24319 MEDIUM
SAP Business One - Info Disclosure
CVSS 5.8
CVE-2026-25751 HIGH
Frangoteam Fuxa < 1.2.10 - Missing Authentication
CVSS 7.5
CVE-2026-22276 MEDIUM
Dell ECS <3.8.1.7 & Dell ObjectScale <4.2.0.0 - Info Disclosure
CVSS 5.5
Details
Vulnerabilities 786