CWE-312

Cleartext Storage of Sensitive Information

Parent: CWE-311 - Missing Encryption of Sensitive Data

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

818 vulnerabilities with CWE-312
CVE-2024-9040 LOW
Blood Bank Management System 1.0 - Info Disclosure
CVSS 2.3
CVE-2024-45862 HIGH
Kastle Access Control System Firmware < 2024-05-01 - Cleartext Storage of Sensitive Information
CVSS 7.5
CVE-2024-31415 MEDIUM
Eaton Foreseer Electrical Power Monitoring System < 7.8.600 - Insufficiently Protected Credentials
CVSS 6.3
CVE-2024-41629 MEDIUM
Texas Instruments Fusion Digital Power Designer 7.10.1 - Sensitive Information Exposure via Plaintext Credential Storage
CVSS 5.5
CVE-2024-40457 CRITICAL
No-IP Dynamic Update Client 3.x - Cleartext Storage of Sensitive Information
CVSS 9.1
CVE-2024-8689 MEDIUM
Cortex XSOAR/XSIAM - Info Disclosure
CVE-2024-35282 MEDIUM
FortiClient VPN iOS <7.2, <7.0, <6.4, <6.2, <6.0 - Info Disclosure
CVSS 4.2
CVE-2024-45175 HIGH
za-internet C-MOR Video Surveillance 5.2401 - Info Disclosure
CVSS 8.8
CVE-2024-45004 MEDIUM
Linux Kernel 6.10-6.10.7 - Cleartext Storage of Sensitive Information in Trusted Key Blob Export
CVSS 5.5
CVE-2024-41716 HIGH
WindLDR < 9.2.0 and WindO/I-NV4 < 3.1.0 - Cleartext Storage of Sensitive Information
CVSS 8.1
CVE-2024-45391 HIGH
Tina CMS < 1.6.2 - Search Token Exposure via Lock File
CVSS 7.5
CVE-2024-6921 HIGH
NACPremium < 2024-08-01 - Cleartext Storage of Sensitive Information
CVSS 7.5
CVE-2024-32939 MEDIUM
Mattermost 9.5.0-9.5.7 9.8.0-9.8.2 9.9.0-9.9.1 9.10.0 - Improper Access Control in Shared Channels
CVSS 4.3
CVE-2024-25024 MEDIUM
IBM QRadar Suite Software <1.10.23.0 & Cloud Pak for Security <1.10...
CVSS 5.5
CVE-2024-5916 MEDIUM
Palo Alto Networks PAN-OS - Info Disclosure
CVSS 4.4
CVE-2024-33892 HIGH
Cosy+ <21.2s10, <22.1s3 - Info Disclosure
CVSS 7.5
CVE-2024-38877 HIGH
Omnivise T3000 - Cleartext Storage of Sensitive Initial System Credentials
CVSS 8.2
CVE-2024-41691 MEDIUM
SyroTech SY-GPON-1110-WDONT Firmware - Cleartext Storage of FTP Credentials in SquashFS-root Filesystem
CVSS 4.6
CVE-2024-41690 MEDIUM
SyroTech SY-GPON-1110-WDONT Router - Cleartext Storage of Sensitive Information in Firmware
CVSS 4.6
CVE-2024-41689 MEDIUM
SyroTech SY-GPON-1110-WDONT Router - Cleartext Storage of WPA/WPS Credentials
CVSS 4.6
CVE-2024-41688 MEDIUM
SyroTech SY-GPON-1110-WDONT Firmware - Cleartext Storage of Sensitive Information
CVSS 4.6
CVE-2024-39674 MEDIUM
HarmonyOS - Cleartext Storage of Sensitive Information in Gallery Search Module
CVSS 6.2
CVE-2024-39732 MEDIUM
IBM Datacap Navigator <9.1.10 - Info Disclosure
CVSS 4.1
CVE-2024-25023 MEDIUM
IBM Cloud Pak for Security 1.10.0.0-1.10.11.0 & QRadar Suite 1.10.12.0-1.10.22.0 Cleartext Sensitive Info in Logs
CVSS 5.5
CVE-2024-21993 MEDIUM
SnapCenter <5.0p1 - Info Disclosure
CVSS 5.7
Details
Vulnerabilities 818