CWE-312

Cleartext Storage of Sensitive Information

Parent: CWE-311 - Missing Encryption of Sensitive Data

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

818 vulnerabilities with CWE-312
CVE-2023-46388 HIGH
LOYTEC electronics GmbH LINX-212/LINX-151 - Info Disclosure
CVSS 7.5
CVE-2023-46386 HIGH
LOYTEC electronics GmbH LINX-212/LINX-151 - Info Disclosure
CVSS 7.5
CVE-2023-46384 HIGH
LOYTEC electronics GmbH LINX Configurator - Info Disclosure
CVSS 7.5
CVE-2023-48707 MEDIUM
CodeIgniter Shield <1.0.0-beta.8 - Info Disclosure
CVSS 5.0
CVE-2023-47312 MEDIUM
Headwind MDM 5.22.1 - Cleartext Storage of Sensitive Information in Audit Logs
CVSS 6.5
CVE-2023-48700 MEDIUM
nautobot-plugin-device-onboarding 2.0.0-3.0.0 - Cleartext Storage of Sensitive Information in Job Results
CVSS 5.7
CVE-2023-48305 MEDIUM
Nextcloud Server 25.0.0-25.0.10 - Cleartext Storage of Sensitive Information in Debug Log
CVSS 4.2
CVE-2023-46376 HIGH
Zentao Biz < 8.7 - Cleartext Storage of Sensitive Information
CVSS 7.5
CVE-2023-41096 MEDIUM
Silicon Labs Ember ZNet SDK <7.3.1 - Info Disclosure
CVSS 6.8
CVE-2023-41095 MEDIUM
Silicon Labs OpenThread SDK <2.3.1 - Info Disclosure
CVSS 6.8
CVE-2023-46653 MEDIUM
Jenkins lambdatest-automation <1.20.10 - Info Disclosure
CVSS 6.5
CVE-2023-46128 MEDIUM
Nautobot 2.0.0-2.0.2 - Authenticated Exposure of Hashed User Passwords via REST API Depth Parameter
CVSS 6.5
CVE-2023-45151 MEDIUM
Nextcloud Server < 25.0.8 - Cleartext Storage of OAuth2 Tokens
CVSS 6.5
CVE-2023-44037 HIGH
ZPE Systems, Inc Nodegrid OS <5.8.14 & <5.10.6 - Info Disclosure
CVSS 7.5
CVE-2023-41964 MEDIUM
F5 BIG-IP 13.1.0-13.1.5 - Cleartext Storage of Sensitive Information in Database Variables
CVSS 4.3
CVE-2023-2809 HIGH
Sage 200 Spain <2023.38.001 - SQL Injection
CVSS 7.8
CVE-2023-4066 MEDIUM
Red Hat AMQ Broker - Info Disclosure
CVSS 5.5
CVE-2023-44159 HIGH
Acronis Cyber Protect 15 < 35979 - Cleartext Storage of Sensitive Information
CVSS 7.5
CVE-2023-44153 HIGH
Acronis Cyber Protect <35979 - Info Disclosure
CVSS 7.5
CVE-2023-41335 LOW
Synapse 1.66.0-1.93.0 - Cleartext Storage of Sensitive Information in Database
CVSS 3.7
CVE-2023-2358 MEDIUM
Hitachi Vantara Pentaho <9.5.0.0-9.3.0.4 - Info Disclosure
CVSS 4.3
CVE-2023-40715 MEDIUM
FortiTester <7.2.3 - Info Disclosure
CVSS 5.5
CVE-2023-4400 MEDIUM
Skyhigh Secure Web Gateway <11.2.14,10.2.25,12.2.1 - Info Disclosure
CVSS 6.2
CVE-2023-31069 CRITICAL
TSplus Remote Access <16.0.2.14 - Info Disclosure
CVSS 9.8
CVE-2023-3950 MEDIUM
GitLab 16.2-16.2.5, 16.3-16.3.1 - Unauthenticated Cleartext Storage of Sensitive Information in Google Cloud Logging
CVSS 5.5
Details
Vulnerabilities 818