CWE-312

Cleartext Storage of Sensitive Information

Parent: CWE-311 - Missing Encryption of Sensitive Data

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

818 vulnerabilities with CWE-312
CVE-2024-23942 HIGH
Client Workstation - Info Disclosure
CVSS 7.1
CVE-2024-12604 MEDIUM
Tap&Sign App <V.1.025 - Info Disclosure
CVSS 6.5
CVE-2024-10404 MEDIUM
Brocade SANnav < 2.3.1b - Authenticated Cleartext Storage of Sensitive Information in CalInvocationHandler
CVSS 5.5
CVE-2024-13843 MEDIUM
Ivanti Connect Secure < 22.7R2.6 & Policy Secure < 22.7R1.3 - Sensitive Data Exposure via Cleartext Storage
CVSS 6.0
CVE-2024-53651 MEDIUM
SIPROTEC 5 - Cleartext Storage of Sensitive Information in On-Board Flash Storage
CVSS 4.6
CVE-2024-45718 MEDIUM
Configuration File - Info Disclosure
CVSS 4.6
CVE-2024-49800 MEDIUM
IBM ApplinX 11.1 - Authenticated Cleartext Storage of Sensitive Information in Memory
CVSS 4.3
CVE-2024-55928 MEDIUM
Xerox Workplace Suite - Info Disclosure
CVSS 6.5
CVE-2024-12079 LOW
ECOVACS Robot Lawnmowers - Cleartext Storage of Anti-Theft PIN
CVSS 3.3
CVE-2024-46505 CRITICAL
Infoblox BloxOne v2.4 - Info Disclosure
CVSS 9.1
CVE-2024-56362 HIGH
navidrome < 0.54.1 - Cleartext Storage of JWT Secret in Database
CVSS 7.1
CVE-2024-55196 HIGH
gophish v0.12.1 - Cleartext Storage of Sensitive Information in Mail Server Configuration
CVSS 7.5
CVE-2024-50570 MEDIUM
FortiClient 7.0.0-7.0.13, 7.2.0-7.2.6, 7.4.0-7.4.1 - Cleartext Storage of VPN Password
CVSS 5.0
CVE-2024-51175 HIGH
H3C switch h3c-S1526 - Info Disclosure
CVSS 7.5
CVE-2024-35117 MEDIUM
IBM OpenPages with Watson 9.0 - Cleartext Storage of Sensitive Information in System Tracing Log Files
CVSS 4.4
CVE-2024-46340 CRITICAL
TP-Link TL-WR845N(UN)_V4 - Cleartext Storage of Sensitive Information
CVSS 9.8
CVE-2024-40582 HIGH
Pentaminds CuroVMS v2.0.1 - Info Disclosure
CVSS 7.5
CVE-2024-55582 MEDIUM
Oxide < 6 - Cleartext Storage of Sensitive Information in Control Plane Datastores
CVSS 5.7
CVE-2024-54127 MEDIUM
TP-Link Archer C50 - Info Disclosure
CVE-2024-12094 MEDIUM
Tinxy Android app < 663000 and iOS app < 6.7.0 - Cleartext Storage of Sensitive Information in Device Database
CVE-2024-42451 MEDIUM
Veeam Backup & Replication - Info Disclosure
CVSS 6.5
CVE-2024-53979 HIGH
zhmc-ansible-modules < 1.9.3 - Cleartext Storage of Sensitive Information in Log Files
CVSS 8.2
CVE-2024-53865 HIGH
zhmcclient < 1.18.1 - Cleartext Storage of Sensitive Information in Logs
CVSS 8.2
CVE-2024-29146 MEDIUM
Product with vulnerability - Info Disclosure
CVSS 5.9
CVE-2024-46383 LOW
Hathway Skyworth Router CM5100-511 v4.1.1.24 - Info Disclosure
CVSS 2.4
Details
Vulnerabilities 818