CWE-312

Cleartext Storage of Sensitive Information

Parent: CWE-311 - Missing Encryption of Sensitive Data

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

804 vulnerabilities with CWE-312
CVE-2024-5916 MEDIUM
Palo Alto Networks PAN-OS - Info Disclosure
CVSS 4.4
CVE-2024-33892 HIGH
Cosy+ <21.2s10, <22.1s3 - Info Disclosure
CVSS 7.5
CVE-2024-38877 HIGH
Omnivise T3000 - Cleartext Storage of Sensitive Initial System Credentials
CVSS 8.2
CVE-2024-41691 MEDIUM
SyroTech SY-GPON-1110-WDONT Firmware - Cleartext Storage of FTP Credentials in SquashFS-root Filesystem
CVSS 4.6
CVE-2024-41690 MEDIUM
SyroTech SY-GPON-1110-WDONT Router - Cleartext Storage of Sensitive Information in Firmware
CVSS 4.6
CVE-2024-41689 MEDIUM
SyroTech SY-GPON-1110-WDONT Router - Cleartext Storage of WPA/WPS Credentials
CVSS 4.6
CVE-2024-41688 MEDIUM
SyroTech SY-GPON-1110-WDONT Firmware - Cleartext Storage of Sensitive Information
CVSS 4.6
CVE-2024-39674 MEDIUM
HarmonyOS - Cleartext Storage of Sensitive Information in Gallery Search Module
CVSS 6.2
CVE-2024-39732 MEDIUM
IBM Datacap Navigator <9.1.10 - Info Disclosure
CVSS 4.1
CVE-2024-25023 MEDIUM
IBM Cloud Pak for Security 1.10.0.0-1.10.11.0 & QRadar Suite 1.10.12.0-1.10.22.0 Cleartext Sensitive Info in Logs
CVSS 5.5
CVE-2024-21993 MEDIUM
SnapCenter <5.0p1 - Info Disclosure
CVSS 5.7
CVE-2024-40750 MEDIUM
Linksys Velop Pro 6E - Info Disclosure
CVSS 5.3
CVE-2024-40594 LOW
OpenAI ChatGPT <2024-07-05 - Info Disclosure
CVSS 2.3
CVE-2024-39846 LOW
NewPass < 1.2.0 - Cleartext Storage of Sensitive Information
CVSS 3.5
CVE-2024-29954 MEDIUM
Brocade Fabric OS <9.2.1-8.2.3e - Info Disclosure
CVSS 5.9
CVE-2024-36497 CRITICAL
Faronics WINSelect 8.30.xx.903 - Cleartext Storage of Sensitive Information
CVSS 9.1
CVE-2024-36589 MEDIUM
Annonshop.app - Cleartext Storage of Sensitive Credentials
CVSS 4.3
CVE-2024-38280 MEDIUM
Motorola Vigilant Fixed LPR COMS Box Firmware <= 3.1.171.9 - Cleartext Credential Storage
CVSS 4.6
CVE-2024-28024 MEDIUM
HitachiEnergy FOXMAN-UN/UNEM - Cleartext Storage of Sensitive Information
CVSS 4.1
CVE-2024-36790 HIGH
Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 - Cleartext Storage of Sensitive Information
CVSS 8.8
CVE-2024-4540 HIGH
Keycloak < 24.0.5 - Cleartext Storage of Sensitive Information in OAuth 2.0 PAR KC_RESTART Cookie
CVSS 7.5
CVE-2024-36119 LOW
Statamic CMS 5.3.0-5.6.1 - Cleartext Storage of Sensitive Information in User Registration Form
CVSS 1.8
CVE-2024-33471 HIGH
AVTECH Room Alert 4E <4.4.0 - Info Disclosure
CVSS 7.2
CVE-2024-33470 MEDIUM
AVTECH Room Alert 4E <4.4.0 - Info Disclosure
CVSS 4.9
CVE-2024-31840 MEDIUM
Italtel Embrace 1.6.4 - Info Disclosure
CVSS 6.5
Details
Vulnerabilities 804