CWE-312

Cleartext Storage of Sensitive Information

Parent: CWE-311 - Missing Encryption of Sensitive Data

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

804 vulnerabilities with CWE-312
CVE-2026-34214 HIGH
Trino: Iceberg REST catalog static and vended credentials are accessible via query JSON
CVSS 7.7
CVE-2026-33026 CRITICAL
nginx-ui Backup Restore Allows Tampering with Encrypted Backups
CVSS 9.1
CVE-2026-33867 HIGH
AVideo has Plaintext Video Password Storage
CVSS 7.5
CVE-2026-27877 MEDIUM
Public dashboards discloses all direct mode datasources
CVSS 6.5
CVE-2026-4346 MEDIUM
Cleartext Storage of Administrative and Wi-Fi Credentials via Accessible Serial Interface in TP Link's TL-WR850N
CVSS 6.8
CVE-2026-33512 HIGH
WWBN AVideo <=26.0 - Info Disclosure
CVSS 7.5
CVE-2026-31848 CRITICAL
Reversible ecos_pw cookie allows administrative authentication in Nexxt Nebula 300+
CVSS 9.8
CVE-2026-33003 MEDIUM
Jenkins LoadNinja Plugin <=2.1 - Info Disclosure
CVSS 4.3
CVE-2026-32842 MEDIUM
Edimax GS-5008PL <= 1.00.54 Admin Credentials Stored in Cleartext
CVSS 6.5
CVE-2026-24311 MEDIUM
SAP Customer Checkout - Memory Corruption
CVSS 5.6
CVE-2026-3277 MEDIUM
PowerShell Universal <2026.1.3 - Info Disclosure
CVSS 6.5
CVE-2026-3221 MEDIUM
Devolutions Server <2025.3.14 - Info Disclosure
CVSS 4.9
CVE-2026-27520 HIGH
Binardat 10G08-0800GSM <V300SP10260209 - Info Disclosure
CVSS 7.5
CVE-2026-23655 MEDIUM
Azure Compute Gallery - Info Disclosure
CVSS 6.5
CVE-2026-24319 MEDIUM
SAP Business One - Cleartext Storage of Sensitive Information in Memory
CVSS 5.8
CVE-2026-25751 HIGH
FUXA < 1.2.10 - Unauthenticated Information Disclosure of Database Credentials
CVSS 7.5
CVE-2026-22276 MEDIUM
Dell ECS <3.8.1.7 & Dell ObjectScale <4.2.0.0 - Info Disclosure
CVSS 5.5
CVE-2026-22240 HIGH
BLUVOYIX - Unauthenticated Exposure of Sensitive Information via Users API
CVSS 7.5
CVE-2025-14815 CRITICAL
Information Disclosure, Tampering, and Denial-of-Service Vulnerabilities in GENESIS64, ICONICS Suite, MobileHMI, Hyper Historian, AnalytiX, GENESIS, and MC Works64
CVE-2025-55717 MEDIUM
Fortinet FortiMail/FortiRecorder/FortiVoice - Info Disclosure
CVSS 4.0
CVE-2025-36105 MEDIUM
IBM Planning Analytics Advanced 3.1.0-3.1.4 - Info Disclosure
CVSS 4.4
CVE-2025-70050 MEDIUM
lesspass v9.6.9 - Cleartext Storage of Sensitive Information
CVSS 6.5
CVE-2025-47147 MEDIUM
Command Centre Mobile Client <9.40.123 - Info Disclosure
CVSS 5.7
CVE-2025-10464 MEDIUM
Birtech Senseway <09022026 - Info Disclosure
CVSS 6.5
CVE-2025-33081 LOW
IBM Concert <2.1.0 - Info Disclosure
CVSS 3.3
Details
Vulnerabilities 804