CWE-312 · 750 kayıt
Cleartext Storage of Sensitive Information
Bu sınıftaki CVE’ler
750 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
55Planlayın | CVE-2022-26148Kavram kanıtı | An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix.grafana · grafana · CWE-312 | Kritik9,8 | — | %53,4 | 21 Mar 2022 |
53Planlayın | CVE-2011-4723Silahlaştırılmış | The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information via unspecifidlink · dir-300 firmware · CWE-312 | Orta5,7 | KEV | %3,1 | 20 Ara 2011 |
41Planlayın | CVE-2019-0285Kavram kanıtı | The .NET SDK WebForm Viewer in SAP Crystal Reports for Visual Studio (fixed in version 2010) discloses sensitive database information includsap · crystal reports · CWE-312 | Kritik9,8 | — | %6,6 | 10 Nis 2019 |
41Planlayın | CVE-2020-5723Silahlaştırılmış | The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database.grandstream · ucm6202 firmware · CWE-312 | Kritik9,8 | — | %5,9 | 30 Mar 2020 |
40Planlayın | CVE-2021-36782Silahlaştırılmış | Rancher: Plaintext storage and exposure of credentials in Rancher API and cluster.management.cattle.io objectsuse · rancher · CWE-312 | Kritik9,9 | — | %4,2 | 7 Eyl 2022 |
40Planlayın | CVE-2023-31069Kavram kanıtı | An issue was discovered in TSplus Remote Access through 16.0.2.14.tsplus · tsplus remote work · CWE-312 | Kritik9,8 | — | %3,7 | 11 Eyl 2023 |
40Planlayın | CVE-2001-1481İstismar yok | Xitami 2.4 through 2.5 b4 stores the Administrator password in plaintext in the default.aut file, whose default permissions are world-readabxitami · xitami · CWE-312 | Kritik9,8 | — | %2,9 | 31 Ara 2001 |
40Planlayın | CVE-2014-5433İstismar yok | An unauthenticated remote attacker may be able to execute commands to view wireless account credentials that are stored in cleartext on Baxtbaxter · sigma spectrum infusion system firmware · CWE-312 | Kritik9,8 | — | %2,1 | 26 Mar 2019 |
40Planlayın | CVE-2008-0174İstismar yok | GE Fanuc Proficy Real-Time Information Portal 2.6 and earlier uses HTTP Basic Authentication, which transmits usernames and passwords in basge · proficy real-time information portal · CWE-312 | Kritik9,8 | — | %2,0 | 28 Oca 2008 |
40Planlayın | CVE-2019-19228İstismar yok | Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allow attackers to bypass authentication because the password for the today accountfronius · datamanager box 2.0 firmware · CWE-312 | Kritik9,8 | — | %1,9 | 4 Ara 2019 |
39İzleyin | CVE-2019-9823İstismar yok | In several JetBrains IntelliJ IDEA versions, creating remote run configurations of JavaEE application servers leads to saving a cleartext rejetbrains · intellij idea · CWE-312 | Kritik9,8 | — | %1,6 | 3 Tem 2019 |
39İzleyin | CVE-2019-9873İstismar yok | In several versions of JetBrains IntelliJ IDEA Ultimate, creating Task Servers configurations leads to saving a cleartext unencrypted recordjetbrains · intellij idea · CWE-312 | Kritik9,8 | — | %1,6 | 3 Tem 2019 |
39İzleyin | CVE-2019-13096İstismar yok | TronLink Wallet 2.2.0 stores user wallet keystore in plaintext and places them in insecure storage.tronlink · wallet · CWE-312 | Kritik9,8 | — | %1,1 | 22 Tem 2019 |
39İzleyin | CVE-2019-11384İstismar yok | The Zalora application 6.15.1 for Android stores confidential information insecurely on the system (i.e.zalora · zalora · CWE-312 | Kritik9,8 | — | %1,0 | 22 Nis 2019 |
39İzleyin | CVE-2018-18641İstismar yok | An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3.gitlab · gitlab · CWE-312 | Kritik9,8 | — | %0,9 | 4 Ara 2018 |
39İzleyin | CVE-2020-15332İstismar yok | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/etc/default/axess permissions.zyxel · cloudcnm secumanager · CWE-312 | Kritik9,8 | — | %0,9 | 28 Eyl 2022 |
39İzleyin | CVE-2019-18868İstismar yok | Blaauw Remote Kiln Control through v3.00r4 allows an unauthenticated attacker to access MySQL credentials in cleartext in /engine/db.inc, /lblaauwproducts · remote kiln control · CWE-312 | Kritik9,8 | — | %0,8 | 7 May 2020 |
39İzleyin | CVE-2018-18394İstismar yok | Sensitive Information Stored in Clear Text in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.moxa · thingspro · CWE-312 | Kritik9,8 | — | %0,7 | 19 Eki 2018 |
39İzleyin | CVE-2021-29954İstismar yok | Proxy functionality built into Hubs Cloud’s Reticulum software allowed access to internal URLs, including the metadata service.mozilla · hubs cloud reticulum · CWE-312 | Kritik9,8 | — | %0,6 | 24 Haz 2021 |
39İzleyin | CVE-2023-33373İstismar yok | Connected IO v2.1.0 and prior keeps passwords and credentials in clear-text format, allowing attackers to exfiltrate the credentials and useconnectedio · connected io · CWE-312 | Kritik9,8 | — | %0,4 | 4 Ağu 2023 |
39İzleyin | CVE-2023-2809İstismar yok | Use of Cleartext credentials in Sage 200 Spainsage · sage 200 spain · CWE-312 | Kritik9,8 | — | %0,4 | 4 Eki 2023 |
39İzleyin | CVE-2024-46340İstismar yok | TL-WR845N(UN)_V4_201214, TP-Link TL-WR845N(UN)_V4_200909, and TL-WR845N(UN)_V4_190219 was discovered to transmit user credentials in plaintetp-link · tl-wr845n firmware · CWE-312 | Kritik9,8 | — | %0,3 | 10 Ara 2024 |
39İzleyin | CVE-2025-30124İstismar yok | An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices.CWE-312 | Kritik9,8 | — | %0,3 | 28 Tem 2025 |
39İzleyin | CVE-2025-65826İstismar yok | The mobile application was found to contain stored credentials for the network it was developed on.meatmeet · meatmeet · CWE-312 | Kritik9,8 | — | %0,3 | 10 Ara 2025 |
39İzleyin | CVE-2026-15721İstismar yok | Query Console SQL Injection Leading to Sensitive Data Disclosure in Bilin Software's HUMANIST Digital Human Resourcesbilin software and informatics consultancy inc. · humanist digital human resources · CWE-312 | Kritik9,8 | — | %0,3 | 4 Ağu 2026 |
- CVE-2022-2614855Planlayın
An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix.
KritikCVSS 9,8Kavram kanıtıEPSS %53grafana · grafana21 Mar 2022
- CVE-2011-472353Planlayın
The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information via unspecifi
OrtaCVSS 5,7KEVSilahlaştırılmışEPSS %3dlink · dir-300 firmware20 Ara 2011
- CVE-2019-028541Planlayın
The .NET SDK WebForm Viewer in SAP Crystal Reports for Visual Studio (fixed in version 2010) discloses sensitive database information includ
KritikCVSS 9,8Kavram kanıtıEPSS %7sap · crystal reports10 Nis 2019
- CVE-2020-572341Planlayın
The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database.
KritikCVSS 9,8SilahlaştırılmışEPSS %6grandstream · ucm6202 firmware30 Mar 2020
- CVE-2021-3678240Planlayın
Rancher: Plaintext storage and exposure of credentials in Rancher API and cluster.management.cattle.io object
KritikCVSS 9,9SilahlaştırılmışEPSS %4suse · rancher7 Eyl 2022
- CVE-2023-3106940Planlayın
An issue was discovered in TSplus Remote Access through 16.0.2.14.
KritikCVSS 9,8Kavram kanıtıEPSS %4tsplus · tsplus remote work11 Eyl 2023
- CVE-2001-148140Planlayın
Xitami 2.4 through 2.5 b4 stores the Administrator password in plaintext in the default.aut file, whose default permissions are world-readab
KritikCVSS 9,8İstismar yokEPSS %3xitami · xitami31 Ara 2001
- CVE-2014-543340Planlayın
An unauthenticated remote attacker may be able to execute commands to view wireless account credentials that are stored in cleartext on Baxt
KritikCVSS 9,8İstismar yokEPSS %2baxter · sigma spectrum infusion system firmware26 Mar 2019
- CVE-2008-017440Planlayın
GE Fanuc Proficy Real-Time Information Portal 2.6 and earlier uses HTTP Basic Authentication, which transmits usernames and passwords in bas
KritikCVSS 9,8İstismar yokEPSS %2ge · proficy real-time information portal28 Oca 2008
- CVE-2019-1922840Planlayın
Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allow attackers to bypass authentication because the password for the today account
KritikCVSS 9,8İstismar yokEPSS %2fronius · datamanager box 2.0 firmware4 Ara 2019
- CVE-2019-982339İzleyin
In several JetBrains IntelliJ IDEA versions, creating remote run configurations of JavaEE application servers leads to saving a cleartext re
KritikCVSS 9,8İstismar yokEPSS %2jetbrains · intellij idea3 Tem 2019
- CVE-2019-987339İzleyin
In several versions of JetBrains IntelliJ IDEA Ultimate, creating Task Servers configurations leads to saving a cleartext unencrypted record
KritikCVSS 9,8İstismar yokEPSS %2jetbrains · intellij idea3 Tem 2019
- CVE-2019-1309639İzleyin
TronLink Wallet 2.2.0 stores user wallet keystore in plaintext and places them in insecure storage.
KritikCVSS 9,8İstismar yokEPSS %1tronlink · wallet22 Tem 2019
- CVE-2019-1138439İzleyin
The Zalora application 6.15.1 for Android stores confidential information insecurely on the system (i.e.
KritikCVSS 9,8İstismar yokEPSS %1zalora · zalora22 Nis 2019
- CVE-2018-1864139İzleyin
An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3.
KritikCVSS 9,8İstismar yokEPSS %1gitlab · gitlab4 Ara 2018
- CVE-2020-1533239İzleyin
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/etc/default/axess permissions.
KritikCVSS 9,8İstismar yokEPSS %1zyxel · cloudcnm secumanager28 Eyl 2022
- CVE-2019-1886839İzleyin
Blaauw Remote Kiln Control through v3.00r4 allows an unauthenticated attacker to access MySQL credentials in cleartext in /engine/db.inc, /l
KritikCVSS 9,8İstismar yokEPSS %1blaauwproducts · remote kiln control7 May 2020
- CVE-2018-1839439İzleyin
Sensitive Information Stored in Clear Text in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.
KritikCVSS 9,8İstismar yokEPSS %1moxa · thingspro19 Eki 2018
- CVE-2021-2995439İzleyin
Proxy functionality built into Hubs Cloud’s Reticulum software allowed access to internal URLs, including the metadata service.
KritikCVSS 9,8İstismar yokEPSS %1mozilla · hubs cloud reticulum24 Haz 2021
- CVE-2023-3337339İzleyin
Connected IO v2.1.0 and prior keeps passwords and credentials in clear-text format, allowing attackers to exfiltrate the credentials and use
KritikCVSS 9,8İstismar yokEPSS %0connectedio · connected io4 Ağu 2023
- CVE-2023-280939İzleyin
Use of Cleartext credentials in Sage 200 Spain
KritikCVSS 9,8İstismar yokEPSS %0sage · sage 200 spain4 Eki 2023
- CVE-2024-4634039İzleyin
TL-WR845N(UN)_V4_201214, TP-Link TL-WR845N(UN)_V4_200909, and TL-WR845N(UN)_V4_190219 was discovered to transmit user credentials in plainte
KritikCVSS 9,8İstismar yokEPSS %0tp-link · tl-wr845n firmware10 Ara 2024
- CVE-2025-3012439İzleyin
An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices.
KritikCVSS 9,8İstismar yokEPSS %028 Tem 2025
- CVE-2025-6582639İzleyin
The mobile application was found to contain stored credentials for the network it was developed on.
KritikCVSS 9,8İstismar yokEPSS %0meatmeet · meatmeet10 Ara 2025
- CVE-2026-1572139İzleyin
Query Console SQL Injection Leading to Sensitive Data Disclosure in Bilin Software's HUMANIST Digital Human Resources
KritikCVSS 9,8İstismar yokEPSS %0bilin software and informatics consultancy inc. · humanist digital human resources4 Ağu 2026