Перейти к содержимому
Noroxi

CWE-312 · 750 записей

Cleartext Storage of Sensitive Information

CVE этого класса

750 записей

  • CVE-2022-26148
    55В плане

    An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix.

    КритическаяCVSS 9,8Proof of conceptEPSS 53 %

    grafana · grafana21 мар. 2022 г.

  • CVE-2011-4723
    53В плане

    The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information via unspecifi

    СредняяCVSS 5,7KEVГотовый эксплойтEPSS 3 %

    dlink · dir-300 firmware20 дек. 2011 г.

  • CVE-2019-0285
    41В плане

    The .NET SDK WebForm Viewer in SAP Crystal Reports for Visual Studio (fixed in version 2010) discloses sensitive database information includ

    КритическаяCVSS 9,8Proof of conceptEPSS 7 %

    sap · crystal reports10 апр. 2019 г.

  • CVE-2020-5723
    41В плане

    The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database.

    КритическаяCVSS 9,8Готовый эксплойтEPSS 6 %

    grandstream · ucm6202 firmware30 мар. 2020 г.

  • CVE-2021-36782
    40В плане

    Rancher: Plaintext storage and exposure of credentials in Rancher API and cluster.management.cattle.io object

    КритическаяCVSS 9,9Готовый эксплойтEPSS 4 %

    suse · rancher7 сент. 2022 г.

  • CVE-2023-31069
    40В плане

    An issue was discovered in TSplus Remote Access through 16.0.2.14.

    КритическаяCVSS 9,8Proof of conceptEPSS 4 %

    tsplus · tsplus remote work11 сент. 2023 г.

  • CVE-2001-1481
    40В плане

    Xitami 2.4 through 2.5 b4 stores the Administrator password in plaintext in the default.aut file, whose default permissions are world-readab

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    xitami · xitami31 дек. 2001 г.

  • CVE-2014-5433
    40В плане

    An unauthenticated remote attacker may be able to execute commands to view wireless account credentials that are stored in cleartext on Baxt

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    baxter · sigma spectrum infusion system firmware26 мар. 2019 г.

  • CVE-2008-0174
    40В плане

    GE Fanuc Proficy Real-Time Information Portal 2.6 and earlier uses HTTP Basic Authentication, which transmits usernames and passwords in bas

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    ge · proficy real-time information portal28 янв. 2008 г.

  • CVE-2019-19228
    40В плане

    Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allow attackers to bypass authentication because the password for the today account

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    fronius · datamanager box 2.0 firmware4 дек. 2019 г.

  • CVE-2019-9823
    39Наблюдать

    In several JetBrains IntelliJ IDEA versions, creating remote run configurations of JavaEE application servers leads to saving a cleartext re

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    jetbrains · intellij idea3 июл. 2019 г.

  • CVE-2019-9873
    39Наблюдать

    In several versions of JetBrains IntelliJ IDEA Ultimate, creating Task Servers configurations leads to saving a cleartext unencrypted record

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    jetbrains · intellij idea3 июл. 2019 г.

  • CVE-2019-13096
    39Наблюдать

    TronLink Wallet 2.2.0 stores user wallet keystore in plaintext and places them in insecure storage.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    tronlink · wallet22 июл. 2019 г.

  • CVE-2019-11384
    39Наблюдать

    The Zalora application 6.15.1 for Android stores confidential information insecurely on the system (i.e.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    zalora · zalora22 апр. 2019 г.

  • CVE-2018-18641
    39Наблюдать

    An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    gitlab · gitlab4 дек. 2018 г.

  • CVE-2020-15332
    39Наблюдать

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/etc/default/axess permissions.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    zyxel · cloudcnm secumanager28 сент. 2022 г.

  • CVE-2019-18868
    39Наблюдать

    Blaauw Remote Kiln Control through v3.00r4 allows an unauthenticated attacker to access MySQL credentials in cleartext in /engine/db.inc, /l

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    blaauwproducts · remote kiln control7 мая 2020 г.

  • CVE-2018-18394
    39Наблюдать

    Sensitive Information Stored in Clear Text in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    moxa · thingspro19 окт. 2018 г.

  • CVE-2021-29954
    39Наблюдать

    Proxy functionality built into Hubs Cloud’s Reticulum software allowed access to internal URLs, including the metadata service.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    mozilla · hubs cloud reticulum24 июн. 2021 г.

  • CVE-2023-33373
    39Наблюдать

    Connected IO v2.1.0 and prior keeps passwords and credentials in clear-text format, allowing attackers to exfiltrate the credentials and use

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    connectedio · connected io4 авг. 2023 г.

  • CVE-2023-2809
    39Наблюдать

    Use of Cleartext credentials in Sage 200 Spain

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    sage · sage 200 spain4 окт. 2023 г.

  • CVE-2024-46340
    39Наблюдать

    TL-WR845N(UN)_V4_201214, TP-Link TL-WR845N(UN)_V4_200909, and TL-WR845N(UN)_V4_190219 was discovered to transmit user credentials in plainte

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    tp-link · tl-wr845n firmware10 дек. 2024 г.

  • CVE-2025-30124
    39Наблюдать

    An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices.

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    28 июл. 2025 г.

  • CVE-2025-65826
    39Наблюдать

    The mobile application was found to contain stored credentials for the network it was developed on.

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    meatmeet · meatmeet10 дек. 2025 г.

  • CVE-2026-15721
    39Наблюдать

    Query Console SQL Injection Leading to Sensitive Data Disclosure in Bilin Software's HUMANIST Digital Human Resources

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    bilin software and informatics consultancy inc. · humanist digital human resources4 авг. 2026 г.

Все классы уязвимостей