CWE-312

Cleartext Storage of Sensitive Information

Parent: CWE-311 - Missing Encryption of Sensitive Data

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

817 vulnerabilities with CWE-312
CVE-2026-8026 LOW
FlowiseAI Flowise API Response account.service.ts login information disclosure
CVSS 3.7
CVE-2026-42151 HIGH
Prometheus Azure AD remote write OAuth client secret exposed via config API
CVSS 7.5
CVE-2026-43824 HIGH
Argo CD 3.2.0-3.2.11 - Info Disclosure
CVSS 7.7
CVE-2026-7163 MEDIUM
Red Hat Multicluster Engine Assisted Installer - Administrative Credential Disclosure
CVSS 6.1
CVE-2026-41385 MEDIUM
OpenClaw < 2026.3.31 - Nostr Private Key Exposure via config.get Redaction Bypass
CVSS 6.5
CVE-2026-6796 MEDIUM
Sanluan PublicCMS Failed Login LoginAdminController.java log_login cleartext storage in file
CVSS 4.3
CVE-2026-6553 HIGH
TYPO3 CMS Stores Cleartext Password in User Settings Module
CVSS 7.5
CVE-2026-6598 MEDIUM
langflow-ai langflow Project Creation Endpoint projects.py encrypt_auth_settings cleartext storage in file
CVSS 4.3
CVE-2026-35644 MEDIUM
OpenClaw < 2026.3.22 - Credential Exposure via baseUrl Fields in Gateway Snapshots
CVSS 6.5
CVE-2026-39943 MEDIUM
Directus exposes sensitive fields in revision history
CVSS 6.5
CVE-2026-5531 MEDIUM
SourceCodester Student Result Management System HTTP GET Request login_credentials.txt cleartext storage in file
CVSS 5.3
CVE-2026-34833 HIGH
Bulwark Webmail: Information Exposure: password returned in /api/auth/session
CVSS 7.5
CVE-2026-34214 HIGH
Trino: Iceberg REST catalog static and vended credentials are accessible via query JSON
CVSS 7.7
CVE-2026-33026 CRITICAL
nginx-ui Backup Restore Allows Tampering with Encrypted Backups
CVSS 9.1
CVE-2026-33867 HIGH
AVideo has Plaintext Video Password Storage
CVSS 7.5
CVE-2026-27877 MEDIUM
Public dashboards discloses all direct mode datasources
CVSS 6.5
CVE-2026-4346 MEDIUM
Cleartext Storage of Administrative and Wi-Fi Credentials via Accessible Serial Interface in TP Link's TL-WR850N
CVSS 6.8
CVE-2026-33512 HIGH
WWBN AVideo <=26.0 - Info Disclosure
CVSS 7.5
CVE-2026-31848 CRITICAL
Reversible ecos_pw cookie allows administrative authentication in Nexxt Nebula 300+
CVSS 9.8
CVE-2026-33003 MEDIUM
Jenkins LoadNinja Plugin <=2.1 - Info Disclosure
CVSS 4.3
CVE-2026-32842 MEDIUM
Edimax GS-5008PL <= 1.00.54 Admin Credentials Stored in Cleartext
CVSS 6.5
CVE-2026-24311 MEDIUM
SAP Customer Checkout - Memory Corruption
CVSS 5.6
CVE-2026-3277 MEDIUM
PowerShell Universal <2026.1.3 - Info Disclosure
CVSS 6.5
CVE-2026-3221 MEDIUM
Devolutions Server <2025.3.14 - Info Disclosure
CVSS 4.9
CVE-2026-27520 HIGH
Binardat 10G08-0800GSM <V300SP10260209 - Info Disclosure
CVSS 7.5
Details
Vulnerabilities 817