CWE-256 · 212 records
Plaintext Storage of a Password
CVEs in this class
212 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2017-16714No exploit | In Ice Qube Thermal Management Center versions prior to version 4.13, passwords are stored in plaintext in a file that is accessible withouticeqube · thermal management center firmware · CWE-256 | Critical9.8 | — | 2.4% | Sep 6, 2018 |
40Plan | CVE-2020-6961No exploit | In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.Xgehealthcare · apexpro telemetry server firmware · CWE-256 | Critical10.0 | — | 1.6% | Jan 24, 2020 |
39Monitor | CVE-2018-7510No exploit | In the web application in BeaconMedaes TotalAlert Scroll Medical Air Systems running software versions prior to 4107600010.23, passwords arebeaconmedaes · scroll medical air systems firmware · CWE-256 | Critical9.8 | — | 1.4% | Jun 6, 2018 |
39Monitor | CVE-2018-8851No exploit | Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versionsechelon · smartserver 1 firmware · CWE-256 | Critical9.8 | — | 1.3% | Jul 24, 2018 |
39Monitor | CVE-2017-7913No exploit | A Plaintext Storage of a Password issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3moxa · oncell g3110-hspa firmware · CWE-256 | Critical9.8 | — | 1.2% | May 29, 2017 |
39Monitor | CVE-2025-27656No exploit | Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Password Stored in Process List V-2printerlogic · vasion print · CWE-256 | Critical9.8 | — | 0.9% | Mar 5, 2025 |
39Monitor | CVE-2024-33375No exploit | LB-LINK BL-W1210M v2.0 was discovered to store user credentials in plaintext within the router's firmware.lb-link · bl-w1210m firmware · CWE-256 | Critical9.8 | — | 0.6% | Jun 14, 2024 |
39Monitor | CVE-2025-27662No exploit | Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Password in URL OVE-20230524-0005.printerlogic · vasion print · CWE-256 | Critical9.8 | — | 0.6% | Mar 5, 2025 |
39Monitor | CVE-2024-36081No exploit | Westermo EDW-100 devices through 2024-05-03 allow an unauthenticated user to download a configuration file containing a cleartext password.CWE-256 | Critical9.8 | — | 0.6% | May 19, 2024 |
39Monitor | CVE-2024-23486No exploit | Plaintext storage of a password issue exists in BUFFALO wireless LAN routers, which may allow a network-adjacent unauthenticated attacker wibuffalo · wsr-2533dhp firmware · CWE-256 | Critical9.8 | — | 0.6% | Apr 15, 2024 |
39Monitor | CVE-2025-6561No exploit | Hunt Electronic Hybrid DVR - Exposure of Sensitive System Informationhunt electronic · hbf-09kd · CWE-256 | Critical9.8 | — | 0.5% | Jun 26, 2025 |
39Monitor | CVE-2024-5960No exploit | Plaintext Storage of a Password in Eliz Software's Panelelizsoftware · panel · CWE-256 | Critical9.8 | — | 0.4% | Sep 18, 2024 |
39Monitor | CVE-2023-26204No exploit | A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versionfortinet · fortisiem · CWE-256 | Critical9.8 | — | 0.4% | Jun 13, 2023 |
39Monitor | CVE-2023-42493No exploit | EisBaer Scada - CWE-256: Plaintext Storage of a Passwordbusbaer · eisbaer scada · CWE-256 | Critical9.8 | — | 0.4% | Oct 25, 2023 |
39Monitor | CVE-2024-55026No exploit | An issue in the reset_pj.cgi endpoint of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to execute arbitrarweintek · easyweb · CWE-256 | Critical9.8 | — | 0.3% | Mar 3, 2026 |
37Monitor | CVE-2025-6560No exploit | Sapido Wireless Router - Exposure of Sensitive Informationsapido · br071n · CWE-256 | Critical9.3 | — | 0.6% | Jun 23, 2025 |
37Monitor | CVE-2024-6118No exploit | Hamastar MeetingHub Paperless Meetings - Plaintext Storage of a Passwordhamastar · meetinghub paperless meetings · CWE-256 | Critical9.3 | — | 0.5% | Aug 5, 2024 |
37Monitor | CVE-2025-5893No exploit | Honding Technology Smart Parking Management System - Exposure of Sensitive Informationhonding technology · smart parking management system · CWE-256 | Critical9.3 | — | 0.5% | Jun 9, 2025 |
37Monitor | CVE-2025-15113No exploit | Ksenia Security lares Home Automation 1.6 Remote Code Execution via MPFS Uploadkseniasecurity · lares firmware · CWE-256 | Critical9.3 | — | 0.5% | Dec 30, 2025 |
37Monitor | CVE-2025-15624No exploit | Plaintext Storage of a Password in Sparx Pro Cloud Server.sparxsystems · pro cloud server · CWE-256 | Critical9.3 | — | 0.4% | Apr 17, 2026 |
37Monitor | CVE-2025-34210No exploit | Vasion Print (formerly PrinterLogic) Readable Cleartext Passwordsvasion · virtual appliance application · CWE-256 | Critical9.4 | — | 0.2% | Oct 2, 2025 |
36Monitor | CVE-2024-26165No exploit | Visual Studio Code Elevation of Privilege Vulnerabilitymicrosoft · visual studio code · CWE-256 | High8.8 | — | 1.9% | Mar 12, 2024 |
36Monitor | CVE-2022-36308No exploit | Airspan AirVelocity 1500 web management UI displays SNMP credentials in plaintext on software versions older than 15.18.00.2511, and stores airspan · airvelocity 1500 firmware · CWE-256 | Critical9.1 | — | 0.7% | Aug 15, 2022 |
36Monitor | CVE-2026-46488No exploit | motionEye: Authentication possible via password hashmotioneye-project · motioneye · CWE-256 | Critical9.1 | — | 0.5% | Sep 15, 2026 |
36Monitor | CVE-2026-35556No exploit | Plaintext storage of a password in OpenPLC_V3openplcproject · openplc v3 firmware · CWE-256 | Critical9.2 | — | 0.4% | Apr 9, 2026 |
- CVE-2017-1671440Plan
In Ice Qube Thermal Management Center versions prior to version 4.13, passwords are stored in plaintext in a file that is accessible without
CriticalCVSS 9.8No exploitEPSS 2%iceqube · thermal management center firmwareSep 6, 2018
- CVE-2020-696140Plan
In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X
CriticalCVSS 10.0No exploitEPSS 2%gehealthcare · apexpro telemetry server firmwareJan 24, 2020
- CVE-2018-751039Monitor
In the web application in BeaconMedaes TotalAlert Scroll Medical Air Systems running software versions prior to 4107600010.23, passwords are
CriticalCVSS 9.8No exploitEPSS 1%beaconmedaes · scroll medical air systems firmwareJun 6, 2018
- CVE-2018-885139Monitor
Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions
CriticalCVSS 9.8No exploitEPSS 1%echelon · smartserver 1 firmwareJul 24, 2018
- CVE-2017-791339Monitor
A Plaintext Storage of a Password issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3
CriticalCVSS 9.8No exploitEPSS 1%moxa · oncell g3110-hspa firmwareMay 29, 2017
- CVE-2025-2765639Monitor
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Password Stored in Process List V-2
CriticalCVSS 9.8No exploitEPSS 1%printerlogic · vasion printMar 5, 2025
- CVE-2024-3337539Monitor
LB-LINK BL-W1210M v2.0 was discovered to store user credentials in plaintext within the router's firmware.
CriticalCVSS 9.8No exploitEPSS 1%lb-link · bl-w1210m firmwareJun 14, 2024
- CVE-2025-2766239Monitor
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Password in URL OVE-20230524-0005.
CriticalCVSS 9.8No exploitEPSS 1%printerlogic · vasion printMar 5, 2025
- CVE-2024-3608139Monitor
Westermo EDW-100 devices through 2024-05-03 allow an unauthenticated user to download a configuration file containing a cleartext password.
CriticalCVSS 9.8No exploitEPSS 1%May 19, 2024
- CVE-2024-2348639Monitor
Plaintext storage of a password issue exists in BUFFALO wireless LAN routers, which may allow a network-adjacent unauthenticated attacker wi
CriticalCVSS 9.8No exploitEPSS 1%buffalo · wsr-2533dhp firmwareApr 15, 2024
- CVE-2025-656139Monitor
Hunt Electronic Hybrid DVR - Exposure of Sensitive System Information
CriticalCVSS 9.8No exploitEPSS 1%hunt electronic · hbf-09kdJun 26, 2025
- CVE-2024-596039Monitor
Plaintext Storage of a Password in Eliz Software's Panel
CriticalCVSS 9.8No exploitEPSS 0%elizsoftware · panelSep 18, 2024
- CVE-2023-2620439Monitor
A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all version
CriticalCVSS 9.8No exploitEPSS 0%fortinet · fortisiemJun 13, 2023
- CVE-2023-4249339Monitor
EisBaer Scada - CWE-256: Plaintext Storage of a Password
CriticalCVSS 9.8No exploitEPSS 0%busbaer · eisbaer scadaOct 25, 2023
- CVE-2024-5502639Monitor
An issue in the reset_pj.cgi endpoint of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to execute arbitrar
CriticalCVSS 9.8No exploitEPSS 0%weintek · easywebMar 3, 2026
- CVE-2025-656037Monitor
Sapido Wireless Router - Exposure of Sensitive Information
CriticalCVSS 9.3No exploitEPSS 1%sapido · br071nJun 23, 2025
- CVE-2024-611837Monitor
Hamastar MeetingHub Paperless Meetings - Plaintext Storage of a Password
CriticalCVSS 9.3No exploitEPSS 0%hamastar · meetinghub paperless meetingsAug 5, 2024
- CVE-2025-589337Monitor
Honding Technology Smart Parking Management System - Exposure of Sensitive Information
CriticalCVSS 9.3No exploitEPSS 0%honding technology · smart parking management systemJun 9, 2025
- CVE-2025-1511337Monitor
Ksenia Security lares Home Automation 1.6 Remote Code Execution via MPFS Upload
CriticalCVSS 9.3No exploitEPSS 0%kseniasecurity · lares firmwareDec 30, 2025
- CVE-2025-1562437Monitor
Plaintext Storage of a Password in Sparx Pro Cloud Server.
CriticalCVSS 9.3No exploitEPSS 0%sparxsystems · pro cloud serverApr 17, 2026
- CVE-2025-3421037Monitor
Vasion Print (formerly PrinterLogic) Readable Cleartext Passwords
CriticalCVSS 9.4No exploitEPSS 0%vasion · virtual appliance applicationOct 2, 2025
- CVE-2024-2616536Monitor
Visual Studio Code Elevation of Privilege Vulnerability
HighCVSS 8.8No exploitEPSS 2%microsoft · visual studio codeMar 12, 2024
- CVE-2022-3630836Monitor
Airspan AirVelocity 1500 web management UI displays SNMP credentials in plaintext on software versions older than 15.18.00.2511, and stores
CriticalCVSS 9.1No exploitEPSS 1%airspan · airvelocity 1500 firmwareAug 15, 2022
- CVE-2026-4648836Monitor
motionEye: Authentication possible via password hash
CriticalCVSS 9.1No exploitEPSS 0%motioneye-project · motioneyeSep 15, 2026
- CVE-2026-3555636Monitor
Plaintext storage of a password in OpenPLC_V3
CriticalCVSS 9.2No exploitEPSS 0%openplcproject · openplc v3 firmwareApr 9, 2026