CWE-256 · 212 записей
Plaintext Storage of a Password
CVE этого класса
212 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2017-16714Эксплойта нет | In Ice Qube Thermal Management Center versions prior to version 4.13, passwords are stored in plaintext in a file that is accessible withouticeqube · thermal management center firmware · CWE-256 | Критическая9,8 | — | 2,4 % | 6 сент. 2018 г. |
40В плане | CVE-2020-6961Эксплойта нет | In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.Xgehealthcare · apexpro telemetry server firmware · CWE-256 | Критическая10,0 | — | 1,6 % | 24 янв. 2020 г. |
39Наблюдать | CVE-2018-7510Эксплойта нет | In the web application in BeaconMedaes TotalAlert Scroll Medical Air Systems running software versions prior to 4107600010.23, passwords arebeaconmedaes · scroll medical air systems firmware · CWE-256 | Критическая9,8 | — | 1,4 % | 6 июн. 2018 г. |
39Наблюдать | CVE-2018-8851Эксплойта нет | Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versionsechelon · smartserver 1 firmware · CWE-256 | Критическая9,8 | — | 1,3 % | 24 июл. 2018 г. |
39Наблюдать | CVE-2017-7913Эксплойта нет | A Plaintext Storage of a Password issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3moxa · oncell g3110-hspa firmware · CWE-256 | Критическая9,8 | — | 1,2 % | 29 мая 2017 г. |
39Наблюдать | CVE-2025-27656Эксплойта нет | Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Password Stored in Process List V-2printerlogic · vasion print · CWE-256 | Критическая9,8 | — | 0,9 % | 5 мар. 2025 г. |
39Наблюдать | CVE-2024-33375Эксплойта нет | LB-LINK BL-W1210M v2.0 was discovered to store user credentials in plaintext within the router's firmware.lb-link · bl-w1210m firmware · CWE-256 | Критическая9,8 | — | 0,6 % | 14 июн. 2024 г. |
39Наблюдать | CVE-2025-27662Эксплойта нет | Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Password in URL OVE-20230524-0005.printerlogic · vasion print · CWE-256 | Критическая9,8 | — | 0,6 % | 5 мар. 2025 г. |
39Наблюдать | CVE-2024-36081Эксплойта нет | Westermo EDW-100 devices through 2024-05-03 allow an unauthenticated user to download a configuration file containing a cleartext password.CWE-256 | Критическая9,8 | — | 0,6 % | 19 мая 2024 г. |
39Наблюдать | CVE-2024-23486Эксплойта нет | Plaintext storage of a password issue exists in BUFFALO wireless LAN routers, which may allow a network-adjacent unauthenticated attacker wibuffalo · wsr-2533dhp firmware · CWE-256 | Критическая9,8 | — | 0,6 % | 15 апр. 2024 г. |
39Наблюдать | CVE-2025-6561Эксплойта нет | Hunt Electronic Hybrid DVR - Exposure of Sensitive System Informationhunt electronic · hbf-09kd · CWE-256 | Критическая9,8 | — | 0,5 % | 26 июн. 2025 г. |
39Наблюдать | CVE-2024-5960Эксплойта нет | Plaintext Storage of a Password in Eliz Software's Panelelizsoftware · panel · CWE-256 | Критическая9,8 | — | 0,4 % | 18 сент. 2024 г. |
39Наблюдать | CVE-2023-26204Эксплойта нет | A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versionfortinet · fortisiem · CWE-256 | Критическая9,8 | — | 0,4 % | 13 июн. 2023 г. |
39Наблюдать | CVE-2023-42493Эксплойта нет | EisBaer Scada - CWE-256: Plaintext Storage of a Passwordbusbaer · eisbaer scada · CWE-256 | Критическая9,8 | — | 0,4 % | 25 окт. 2023 г. |
39Наблюдать | CVE-2024-55026Эксплойта нет | An issue in the reset_pj.cgi endpoint of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to execute arbitrarweintek · easyweb · CWE-256 | Критическая9,8 | — | 0,3 % | 3 мар. 2026 г. |
37Наблюдать | CVE-2025-6560Эксплойта нет | Sapido Wireless Router - Exposure of Sensitive Informationsapido · br071n · CWE-256 | Критическая9,3 | — | 0,6 % | 23 июн. 2025 г. |
37Наблюдать | CVE-2024-6118Эксплойта нет | Hamastar MeetingHub Paperless Meetings - Plaintext Storage of a Passwordhamastar · meetinghub paperless meetings · CWE-256 | Критическая9,3 | — | 0,5 % | 5 авг. 2024 г. |
37Наблюдать | CVE-2025-5893Эксплойта нет | Honding Technology Smart Parking Management System - Exposure of Sensitive Informationhonding technology · smart parking management system · CWE-256 | Критическая9,3 | — | 0,5 % | 9 июн. 2025 г. |
37Наблюдать | CVE-2025-15113Эксплойта нет | Ksenia Security lares Home Automation 1.6 Remote Code Execution via MPFS Uploadkseniasecurity · lares firmware · CWE-256 | Критическая9,3 | — | 0,5 % | 30 дек. 2025 г. |
37Наблюдать | CVE-2025-15624Эксплойта нет | Plaintext Storage of a Password in Sparx Pro Cloud Server.sparxsystems · pro cloud server · CWE-256 | Критическая9,3 | — | 0,4 % | 17 апр. 2026 г. |
37Наблюдать | CVE-2025-34210Эксплойта нет | Vasion Print (formerly PrinterLogic) Readable Cleartext Passwordsvasion · virtual appliance application · CWE-256 | Критическая9,4 | — | 0,2 % | 2 окт. 2025 г. |
36Наблюдать | CVE-2024-26165Эксплойта нет | Visual Studio Code Elevation of Privilege Vulnerabilitymicrosoft · visual studio code · CWE-256 | Высокая8,8 | — | 1,9 % | 12 мар. 2024 г. |
36Наблюдать | CVE-2022-36308Эксплойта нет | Airspan AirVelocity 1500 web management UI displays SNMP credentials in plaintext on software versions older than 15.18.00.2511, and stores airspan · airvelocity 1500 firmware · CWE-256 | Критическая9,1 | — | 0,7 % | 15 авг. 2022 г. |
36Наблюдать | CVE-2026-46488Эксплойта нет | motionEye: Authentication possible via password hashmotioneye-project · motioneye · CWE-256 | Критическая9,1 | — | 0,5 % | 15 сент. 2026 г. |
36Наблюдать | CVE-2026-35556Эксплойта нет | Plaintext storage of a password in OpenPLC_V3openplcproject · openplc v3 firmware · CWE-256 | Критическая9,2 | — | 0,4 % | 9 апр. 2026 г. |
- CVE-2017-1671440В плане
In Ice Qube Thermal Management Center versions prior to version 4.13, passwords are stored in plaintext in a file that is accessible without
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %iceqube · thermal management center firmware6 сент. 2018 г.
- CVE-2020-696140В плане
In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %gehealthcare · apexpro telemetry server firmware24 янв. 2020 г.
- CVE-2018-751039Наблюдать
In the web application in BeaconMedaes TotalAlert Scroll Medical Air Systems running software versions prior to 4107600010.23, passwords are
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %beaconmedaes · scroll medical air systems firmware6 июн. 2018 г.
- CVE-2018-885139Наблюдать
Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %echelon · smartserver 1 firmware24 июл. 2018 г.
- CVE-2017-791339Наблюдать
A Plaintext Storage of a Password issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %moxa · oncell g3110-hspa firmware29 мая 2017 г.
- CVE-2025-2765639Наблюдать
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Password Stored in Process List V-2
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %printerlogic · vasion print5 мар. 2025 г.
- CVE-2024-3337539Наблюдать
LB-LINK BL-W1210M v2.0 was discovered to store user credentials in plaintext within the router's firmware.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %lb-link · bl-w1210m firmware14 июн. 2024 г.
- CVE-2025-2766239Наблюдать
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Password in URL OVE-20230524-0005.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %printerlogic · vasion print5 мар. 2025 г.
- CVE-2024-3608139Наблюдать
Westermo EDW-100 devices through 2024-05-03 allow an unauthenticated user to download a configuration file containing a cleartext password.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %19 мая 2024 г.
- CVE-2024-2348639Наблюдать
Plaintext storage of a password issue exists in BUFFALO wireless LAN routers, which may allow a network-adjacent unauthenticated attacker wi
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %buffalo · wsr-2533dhp firmware15 апр. 2024 г.
- CVE-2025-656139Наблюдать
Hunt Electronic Hybrid DVR - Exposure of Sensitive System Information
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %hunt electronic · hbf-09kd26 июн. 2025 г.
- CVE-2024-596039Наблюдать
Plaintext Storage of a Password in Eliz Software's Panel
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %elizsoftware · panel18 сент. 2024 г.
- CVE-2023-2620439Наблюдать
A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all version
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %fortinet · fortisiem13 июн. 2023 г.
- CVE-2023-4249339Наблюдать
EisBaer Scada - CWE-256: Plaintext Storage of a Password
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %busbaer · eisbaer scada25 окт. 2023 г.
- CVE-2024-5502639Наблюдать
An issue in the reset_pj.cgi endpoint of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to execute arbitrar
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %weintek · easyweb3 мар. 2026 г.
- CVE-2025-656037Наблюдать
Sapido Wireless Router - Exposure of Sensitive Information
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %sapido · br071n23 июн. 2025 г.
- CVE-2024-611837Наблюдать
Hamastar MeetingHub Paperless Meetings - Plaintext Storage of a Password
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %hamastar · meetinghub paperless meetings5 авг. 2024 г.
- CVE-2025-589337Наблюдать
Honding Technology Smart Parking Management System - Exposure of Sensitive Information
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %honding technology · smart parking management system9 июн. 2025 г.
- CVE-2025-1511337Наблюдать
Ksenia Security lares Home Automation 1.6 Remote Code Execution via MPFS Upload
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %kseniasecurity · lares firmware30 дек. 2025 г.
- CVE-2025-1562437Наблюдать
Plaintext Storage of a Password in Sparx Pro Cloud Server.
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %sparxsystems · pro cloud server17 апр. 2026 г.
- CVE-2025-3421037Наблюдать
Vasion Print (formerly PrinterLogic) Readable Cleartext Passwords
КритическаяCVSS 9,4Эксплойта нетEPSS 0 %vasion · virtual appliance application2 окт. 2025 г.
- CVE-2024-2616536Наблюдать
Visual Studio Code Elevation of Privilege Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %microsoft · visual studio code12 мар. 2024 г.
- CVE-2022-3630836Наблюдать
Airspan AirVelocity 1500 web management UI displays SNMP credentials in plaintext on software versions older than 15.18.00.2511, and stores
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %airspan · airvelocity 1500 firmware15 авг. 2022 г.
- CVE-2026-4648836Наблюдать
motionEye: Authentication possible via password hash
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %motioneye-project · motioneye15 сент. 2026 г.
- CVE-2026-3555636Наблюдать
Plaintext storage of a password in OpenPLC_V3
КритическаяCVSS 9,2Эксплойта нетEPSS 0 %openplcproject · openplc v3 firmware9 апр. 2026 г.