Skip to content
Noroxi

CWE-256 · 212 records

Plaintext Storage of a Password

CVEs in this class

212 records

  • In Ice Qube Thermal Management Center versions prior to version 4.13, passwords are stored in plaintext in a file that is accessible without

    CriticalCVSS 9.8No exploitEPSS 2%

    iceqube · thermal management center firmwareSep 6, 2018

  • In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X

    CriticalCVSS 10.0No exploitEPSS 2%

    gehealthcare · apexpro telemetry server firmwareJan 24, 2020

  • CVE-2018-7510
    39Monitor

    In the web application in BeaconMedaes TotalAlert Scroll Medical Air Systems running software versions prior to 4107600010.23, passwords are

    CriticalCVSS 9.8No exploitEPSS 1%

    beaconmedaes · scroll medical air systems firmwareJun 6, 2018

  • CVE-2018-8851
    39Monitor

    Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions

    CriticalCVSS 9.8No exploitEPSS 1%

    echelon · smartserver 1 firmwareJul 24, 2018

  • CVE-2017-7913
    39Monitor

    A Plaintext Storage of a Password issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3

    CriticalCVSS 9.8No exploitEPSS 1%

    moxa · oncell g3110-hspa firmwareMay 29, 2017

  • Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Password Stored in Process List V-2

    CriticalCVSS 9.8No exploitEPSS 1%

    printerlogic · vasion printMar 5, 2025

  • LB-LINK BL-W1210M v2.0 was discovered to store user credentials in plaintext within the router's firmware.

    CriticalCVSS 9.8No exploitEPSS 1%

    lb-link · bl-w1210m firmwareJun 14, 2024

  • Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Password in URL OVE-20230524-0005.

    CriticalCVSS 9.8No exploitEPSS 1%

    printerlogic · vasion printMar 5, 2025

  • Westermo EDW-100 devices through 2024-05-03 allow an unauthenticated user to download a configuration file containing a cleartext password.

    CriticalCVSS 9.8No exploitEPSS 1%

    May 19, 2024

  • Plaintext storage of a password issue exists in BUFFALO wireless LAN routers, which may allow a network-adjacent unauthenticated attacker wi

    CriticalCVSS 9.8No exploitEPSS 1%

    buffalo · wsr-2533dhp firmwareApr 15, 2024

  • CVE-2025-6561
    39Monitor

    Hunt Electronic Hybrid DVR - Exposure of Sensitive System Information

    CriticalCVSS 9.8No exploitEPSS 1%

    hunt electronic · hbf-09kdJun 26, 2025

  • CVE-2024-5960
    39Monitor

    Plaintext Storage of a Password in Eliz Software's Panel

    CriticalCVSS 9.8No exploitEPSS 0%

    elizsoftware · panelSep 18, 2024

  • A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all version

    CriticalCVSS 9.8No exploitEPSS 0%

    fortinet · fortisiemJun 13, 2023

  • EisBaer Scada - CWE-256: Plaintext Storage of a Password

    CriticalCVSS 9.8No exploitEPSS 0%

    busbaer · eisbaer scadaOct 25, 2023

  • An issue in the reset_pj.cgi endpoint of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to execute arbitrar

    CriticalCVSS 9.8No exploitEPSS 0%

    weintek · easywebMar 3, 2026

  • CVE-2025-6560
    37Monitor

    Sapido Wireless Router - Exposure of Sensitive Information

    CriticalCVSS 9.3No exploitEPSS 1%

    sapido · br071nJun 23, 2025

  • CVE-2024-6118
    37Monitor

    Hamastar MeetingHub Paperless Meetings - Plaintext Storage of a Password

    CriticalCVSS 9.3No exploitEPSS 0%

    hamastar · meetinghub paperless meetingsAug 5, 2024

  • CVE-2025-5893
    37Monitor

    Honding Technology Smart Parking Management System - Exposure of Sensitive Information

    CriticalCVSS 9.3No exploitEPSS 0%

    honding technology · smart parking management systemJun 9, 2025

  • Ksenia Security lares Home Automation 1.6 Remote Code Execution via MPFS Upload

    CriticalCVSS 9.3No exploitEPSS 0%

    kseniasecurity · lares firmwareDec 30, 2025

  • Plaintext Storage of a Password in Sparx Pro Cloud Server.

    CriticalCVSS 9.3No exploitEPSS 0%

    sparxsystems · pro cloud serverApr 17, 2026

  • Vasion Print (formerly PrinterLogic) Readable Cleartext Passwords

    CriticalCVSS 9.4No exploitEPSS 0%

    vasion · virtual appliance applicationOct 2, 2025

  • Visual Studio Code Elevation of Privilege Vulnerability

    HighCVSS 8.8No exploitEPSS 2%

    microsoft · visual studio codeMar 12, 2024

  • Airspan AirVelocity 1500 web management UI displays SNMP credentials in plaintext on software versions older than 15.18.00.2511, and stores

    CriticalCVSS 9.1No exploitEPSS 1%

    airspan · airvelocity 1500 firmwareAug 15, 2022

  • motionEye: Authentication possible via password hash

    CriticalCVSS 9.1No exploitEPSS 0%

    motioneye-project · motioneyeSep 15, 2026

  • Plaintext storage of a password in OpenPLC_V3

    CriticalCVSS 9.2No exploitEPSS 0%

    openplcproject · openplc v3 firmwareApr 9, 2026

All vulnerability classes