CWE-312 · 750 записей
Cleartext Storage of Sensitive Information
CVE этого класса
750 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
55В плане | CVE-2022-26148Proof of concept | An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix.grafana · grafana · CWE-312 | Критическая9,8 | — | 53,4 % | 21 мар. 2022 г. |
53В плане | CVE-2011-4723Готовый эксплойт | The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information via unspecifidlink · dir-300 firmware · CWE-312 | Средняя5,7 | KEV | 3,1 % | 20 дек. 2011 г. |
41В плане | CVE-2019-0285Proof of concept | The .NET SDK WebForm Viewer in SAP Crystal Reports for Visual Studio (fixed in version 2010) discloses sensitive database information includsap · crystal reports · CWE-312 | Критическая9,8 | — | 6,6 % | 10 апр. 2019 г. |
41В плане | CVE-2020-5723Готовый эксплойт | The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database.grandstream · ucm6202 firmware · CWE-312 | Критическая9,8 | — | 5,9 % | 30 мар. 2020 г. |
40В плане | CVE-2021-36782Готовый эксплойт | Rancher: Plaintext storage and exposure of credentials in Rancher API and cluster.management.cattle.io objectsuse · rancher · CWE-312 | Критическая9,9 | — | 4,2 % | 7 сент. 2022 г. |
40В плане | CVE-2023-31069Proof of concept | An issue was discovered in TSplus Remote Access through 16.0.2.14.tsplus · tsplus remote work · CWE-312 | Критическая9,8 | — | 3,7 % | 11 сент. 2023 г. |
40В плане | CVE-2001-1481Эксплойта нет | Xitami 2.4 through 2.5 b4 stores the Administrator password in plaintext in the default.aut file, whose default permissions are world-readabxitami · xitami · CWE-312 | Критическая9,8 | — | 2,9 % | 31 дек. 2001 г. |
40В плане | CVE-2014-5433Эксплойта нет | An unauthenticated remote attacker may be able to execute commands to view wireless account credentials that are stored in cleartext on Baxtbaxter · sigma spectrum infusion system firmware · CWE-312 | Критическая9,8 | — | 2,1 % | 26 мар. 2019 г. |
40В плане | CVE-2008-0174Эксплойта нет | GE Fanuc Proficy Real-Time Information Portal 2.6 and earlier uses HTTP Basic Authentication, which transmits usernames and passwords in basge · proficy real-time information portal · CWE-312 | Критическая9,8 | — | 2,0 % | 28 янв. 2008 г. |
40В плане | CVE-2019-19228Эксплойта нет | Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allow attackers to bypass authentication because the password for the today accountfronius · datamanager box 2.0 firmware · CWE-312 | Критическая9,8 | — | 1,9 % | 4 дек. 2019 г. |
39Наблюдать | CVE-2019-9823Эксплойта нет | In several JetBrains IntelliJ IDEA versions, creating remote run configurations of JavaEE application servers leads to saving a cleartext rejetbrains · intellij idea · CWE-312 | Критическая9,8 | — | 1,6 % | 3 июл. 2019 г. |
39Наблюдать | CVE-2019-9873Эксплойта нет | In several versions of JetBrains IntelliJ IDEA Ultimate, creating Task Servers configurations leads to saving a cleartext unencrypted recordjetbrains · intellij idea · CWE-312 | Критическая9,8 | — | 1,6 % | 3 июл. 2019 г. |
39Наблюдать | CVE-2019-13096Эксплойта нет | TronLink Wallet 2.2.0 stores user wallet keystore in plaintext and places them in insecure storage.tronlink · wallet · CWE-312 | Критическая9,8 | — | 1,1 % | 22 июл. 2019 г. |
39Наблюдать | CVE-2019-11384Эксплойта нет | The Zalora application 6.15.1 for Android stores confidential information insecurely on the system (i.e.zalora · zalora · CWE-312 | Критическая9,8 | — | 1,0 % | 22 апр. 2019 г. |
39Наблюдать | CVE-2018-18641Эксплойта нет | An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3.gitlab · gitlab · CWE-312 | Критическая9,8 | — | 0,9 % | 4 дек. 2018 г. |
39Наблюдать | CVE-2020-15332Эксплойта нет | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/etc/default/axess permissions.zyxel · cloudcnm secumanager · CWE-312 | Критическая9,8 | — | 0,9 % | 28 сент. 2022 г. |
39Наблюдать | CVE-2019-18868Эксплойта нет | Blaauw Remote Kiln Control through v3.00r4 allows an unauthenticated attacker to access MySQL credentials in cleartext in /engine/db.inc, /lblaauwproducts · remote kiln control · CWE-312 | Критическая9,8 | — | 0,8 % | 7 мая 2020 г. |
39Наблюдать | CVE-2018-18394Эксплойта нет | Sensitive Information Stored in Clear Text in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.moxa · thingspro · CWE-312 | Критическая9,8 | — | 0,7 % | 19 окт. 2018 г. |
39Наблюдать | CVE-2021-29954Эксплойта нет | Proxy functionality built into Hubs Cloud’s Reticulum software allowed access to internal URLs, including the metadata service.mozilla · hubs cloud reticulum · CWE-312 | Критическая9,8 | — | 0,6 % | 24 июн. 2021 г. |
39Наблюдать | CVE-2023-33373Эксплойта нет | Connected IO v2.1.0 and prior keeps passwords and credentials in clear-text format, allowing attackers to exfiltrate the credentials and useconnectedio · connected io · CWE-312 | Критическая9,8 | — | 0,4 % | 4 авг. 2023 г. |
39Наблюдать | CVE-2023-2809Эксплойта нет | Use of Cleartext credentials in Sage 200 Spainsage · sage 200 spain · CWE-312 | Критическая9,8 | — | 0,4 % | 4 окт. 2023 г. |
39Наблюдать | CVE-2024-46340Эксплойта нет | TL-WR845N(UN)_V4_201214, TP-Link TL-WR845N(UN)_V4_200909, and TL-WR845N(UN)_V4_190219 was discovered to transmit user credentials in plaintetp-link · tl-wr845n firmware · CWE-312 | Критическая9,8 | — | 0,3 % | 10 дек. 2024 г. |
39Наблюдать | CVE-2025-30124Эксплойта нет | An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices.CWE-312 | Критическая9,8 | — | 0,3 % | 28 июл. 2025 г. |
39Наблюдать | CVE-2025-65826Эксплойта нет | The mobile application was found to contain stored credentials for the network it was developed on.meatmeet · meatmeet · CWE-312 | Критическая9,8 | — | 0,3 % | 10 дек. 2025 г. |
39Наблюдать | CVE-2026-15721Эксплойта нет | Query Console SQL Injection Leading to Sensitive Data Disclosure in Bilin Software's HUMANIST Digital Human Resourcesbilin software and informatics consultancy inc. · humanist digital human resources · CWE-312 | Критическая9,8 | — | 0,3 % | 4 авг. 2026 г. |
- CVE-2022-2614855В плане
An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix.
КритическаяCVSS 9,8Proof of conceptEPSS 53 %grafana · grafana21 мар. 2022 г.
- CVE-2011-472353В плане
The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information via unspecifi
СредняяCVSS 5,7KEVГотовый эксплойтEPSS 3 %dlink · dir-300 firmware20 дек. 2011 г.
- CVE-2019-028541В плане
The .NET SDK WebForm Viewer in SAP Crystal Reports for Visual Studio (fixed in version 2010) discloses sensitive database information includ
КритическаяCVSS 9,8Proof of conceptEPSS 7 %sap · crystal reports10 апр. 2019 г.
- CVE-2020-572341В плане
The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database.
КритическаяCVSS 9,8Готовый эксплойтEPSS 6 %grandstream · ucm6202 firmware30 мар. 2020 г.
- CVE-2021-3678240В плане
Rancher: Plaintext storage and exposure of credentials in Rancher API and cluster.management.cattle.io object
КритическаяCVSS 9,9Готовый эксплойтEPSS 4 %suse · rancher7 сент. 2022 г.
- CVE-2023-3106940В плане
An issue was discovered in TSplus Remote Access through 16.0.2.14.
КритическаяCVSS 9,8Proof of conceptEPSS 4 %tsplus · tsplus remote work11 сент. 2023 г.
- CVE-2001-148140В плане
Xitami 2.4 through 2.5 b4 stores the Administrator password in plaintext in the default.aut file, whose default permissions are world-readab
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %xitami · xitami31 дек. 2001 г.
- CVE-2014-543340В плане
An unauthenticated remote attacker may be able to execute commands to view wireless account credentials that are stored in cleartext on Baxt
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %baxter · sigma spectrum infusion system firmware26 мар. 2019 г.
- CVE-2008-017440В плане
GE Fanuc Proficy Real-Time Information Portal 2.6 and earlier uses HTTP Basic Authentication, which transmits usernames and passwords in bas
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %ge · proficy real-time information portal28 янв. 2008 г.
- CVE-2019-1922840В плане
Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allow attackers to bypass authentication because the password for the today account
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %fronius · datamanager box 2.0 firmware4 дек. 2019 г.
- CVE-2019-982339Наблюдать
In several JetBrains IntelliJ IDEA versions, creating remote run configurations of JavaEE application servers leads to saving a cleartext re
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %jetbrains · intellij idea3 июл. 2019 г.
- CVE-2019-987339Наблюдать
In several versions of JetBrains IntelliJ IDEA Ultimate, creating Task Servers configurations leads to saving a cleartext unencrypted record
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %jetbrains · intellij idea3 июл. 2019 г.
- CVE-2019-1309639Наблюдать
TronLink Wallet 2.2.0 stores user wallet keystore in plaintext and places them in insecure storage.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %tronlink · wallet22 июл. 2019 г.
- CVE-2019-1138439Наблюдать
The Zalora application 6.15.1 for Android stores confidential information insecurely on the system (i.e.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %zalora · zalora22 апр. 2019 г.
- CVE-2018-1864139Наблюдать
An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %gitlab · gitlab4 дек. 2018 г.
- CVE-2020-1533239Наблюдать
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/etc/default/axess permissions.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %zyxel · cloudcnm secumanager28 сент. 2022 г.
- CVE-2019-1886839Наблюдать
Blaauw Remote Kiln Control through v3.00r4 allows an unauthenticated attacker to access MySQL credentials in cleartext in /engine/db.inc, /l
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %blaauwproducts · remote kiln control7 мая 2020 г.
- CVE-2018-1839439Наблюдать
Sensitive Information Stored in Clear Text in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %moxa · thingspro19 окт. 2018 г.
- CVE-2021-2995439Наблюдать
Proxy functionality built into Hubs Cloud’s Reticulum software allowed access to internal URLs, including the metadata service.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mozilla · hubs cloud reticulum24 июн. 2021 г.
- CVE-2023-3337339Наблюдать
Connected IO v2.1.0 and prior keeps passwords and credentials in clear-text format, allowing attackers to exfiltrate the credentials and use
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %connectedio · connected io4 авг. 2023 г.
- CVE-2023-280939Наблюдать
Use of Cleartext credentials in Sage 200 Spain
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %sage · sage 200 spain4 окт. 2023 г.
- CVE-2024-4634039Наблюдать
TL-WR845N(UN)_V4_201214, TP-Link TL-WR845N(UN)_V4_200909, and TL-WR845N(UN)_V4_190219 was discovered to transmit user credentials in plainte
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %tp-link · tl-wr845n firmware10 дек. 2024 г.
- CVE-2025-3012439Наблюдать
An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices.
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %28 июл. 2025 г.
- CVE-2025-6582639Наблюдать
The mobile application was found to contain stored credentials for the network it was developed on.
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %meatmeet · meatmeet10 дек. 2025 г.
- CVE-2026-1572139Наблюдать
Query Console SQL Injection Leading to Sensitive Data Disclosure in Bilin Software's HUMANIST Digital Human Resources
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %bilin software and informatics consultancy inc. · humanist digital human resources4 авг. 2026 г.