CWE-312

Cleartext Storage of Sensitive Information

Parent: CWE-311 - Missing Encryption of Sensitive Data

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

818 vulnerabilities with CWE-312
CVE-2024-52525 LOW
Nextcloud Server 28.0.0-28.0.11 - Cleartext Storage of Sensitive Information in Session Data
CVSS 1.8
CVE-2024-11159 MEDIUM
Thunderbird < 128.4.3 - Cleartext Storage of Sensitive Information via OpenPGP Encrypted Messages
CVSS 4.3
CVE-2024-43429 MEDIUM
Moodle < 4.1.12 and 4.4.0-4.4.2 - Unprotected User Data Exposure via Gradebook Reports
CVSS 5.3
CVE-2024-51993 LOW
Combodo iTop <3.2.0 - Info Disclosure
CVSS 3.4
CVE-2024-34891 MEDIUM
Bitrix24 23.300.100 - Cleartext Storage of Sensitive Information in DAV Server Settings
CVSS 6.8
CVE-2024-10523 MEDIUM
TP-Link Tapo H100 Firmware < 1.5.22 - Cleartext Storage of Wi-Fi Credentials
CVSS 4.6
CVE-2024-7783 HIGH
AnythingLLM < 1.2.1 - Cleartext Storage of Sensitive Information in JWT Bearer Token
CVSS 7.5
CVE-2024-9991 HIGH
Philips lighting devices - Info Disclosure
CVE-2024-8070 HIGH
Firmware <version> - Info Disclosure
CVSS 8.5
CVE-2024-9802 MEDIUM
Zowe API Mediation Layer 2.11.0-2.16.9 - Information Exposure via Conformance Validation Endpoint
CVSS 5.3
CVE-2024-9798 CRITICAL
Zowe API Mediation Layer 1.0.0-1.28.7 - Unauthenticated Sensitive Information Exposure via Health Endpoint
CVSS 9.0
CVE-2024-9466 MEDIUM
Palo Alto Networks Expedition 1.2.0-1.2.95 - Authenticated Sensitive Information Disclosure in Log Files
CVSS 6.5
CVE-2024-6400 HIGH
Finrota Netahsilat <1.24.03 - Info Disclosure
CVSS 7.5
CVE-2024-47529 MEDIUM
OpenC3 COSMOS < 5.19.0 - Cleartext Storage of Sensitive Information in LocalStorage
CVSS 6.5
CVE-2024-20448 MEDIUM
Cisco Nexus Dashboard Fabric Controller - Info Disclosure
CVSS 6.3
CVE-2024-25661 HIGH
Nokia Transcend Network Management System - Cleartext Storage
CVSS 7.7
CVE-2024-25658 MEDIUM
Nokia Transcend Network Management System - Cleartext Storage
CVSS 6.5
CVE-2024-28807 MEDIUM
Nokia hiT 7300 Firmware 5.60.50 - Cleartext Storage of Sensitive Information in Memory
CVSS 6.5
CVE-2024-28810 MEDIUM
Infinera hiT 7300 5.60.50 - Cleartext Storage of Sensitive Information in Diagnostic Files
CVSS 6.6
CVE-2024-28809 HIGH
Infinera hiT 7300 5.60.50 - Cleartext Storage of Sensitive Password in Firmware Update Packages
CVSS 8.8
CVE-2024-8459 HIGH
PLANET Technology - Info Disclosure
CVSS 7.2
CVE-2024-45744 LOW
TopQuadrant TopBraid EDG <7.1.3 - Info Disclosure
CVSS 3.0
CVE-2024-8644 HIGH
Oceanic Software ValeApp <2.0.0 - JSON Hijacking
CVSS 7.5
CVE-2024-7259 MEDIUM
oVirt Engine < 4.5.7 - Authenticated Cleartext Storage of Sensitive Information in Provider Passwords
CVSS 4.9
CVE-2024-6785 MEDIUM
Configuration File - Info Disclosure
CVSS 5.5
Details
Vulnerabilities 818