İçeriğe atla
Noroxi

CWE-312 · 750 kayıt

Cleartext Storage of Sensitive Information

Bu sınıftaki CVE’ler

750 kayıt

  • CVE-2022-26148
    55Planlayın

    An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix.

    KritikCVSS 9,8Kavram kanıtıEPSS %53

    grafana · grafana21 Mar 2022

  • CVE-2011-4723
    53Planlayın

    The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information via unspecifi

    OrtaCVSS 5,7KEVSilahlaştırılmışEPSS %3

    dlink · dir-300 firmware20 Ara 2011

  • CVE-2019-0285
    41Planlayın

    The .NET SDK WebForm Viewer in SAP Crystal Reports for Visual Studio (fixed in version 2010) discloses sensitive database information includ

    KritikCVSS 9,8Kavram kanıtıEPSS %7

    sap · crystal reports10 Nis 2019

  • CVE-2020-5723
    41Planlayın

    The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database.

    KritikCVSS 9,8SilahlaştırılmışEPSS %6

    grandstream · ucm6202 firmware30 Mar 2020

  • CVE-2021-36782
    40Planlayın

    Rancher: Plaintext storage and exposure of credentials in Rancher API and cluster.management.cattle.io object

    KritikCVSS 9,9SilahlaştırılmışEPSS %4

    suse · rancher7 Eyl 2022

  • CVE-2023-31069
    40Planlayın

    An issue was discovered in TSplus Remote Access through 16.0.2.14.

    KritikCVSS 9,8Kavram kanıtıEPSS %4

    tsplus · tsplus remote work11 Eyl 2023

  • CVE-2001-1481
    40Planlayın

    Xitami 2.4 through 2.5 b4 stores the Administrator password in plaintext in the default.aut file, whose default permissions are world-readab

    KritikCVSS 9,8İstismar yokEPSS %3

    xitami · xitami31 Ara 2001

  • CVE-2014-5433
    40Planlayın

    An unauthenticated remote attacker may be able to execute commands to view wireless account credentials that are stored in cleartext on Baxt

    KritikCVSS 9,8İstismar yokEPSS %2

    baxter · sigma spectrum infusion system firmware26 Mar 2019

  • CVE-2008-0174
    40Planlayın

    GE Fanuc Proficy Real-Time Information Portal 2.6 and earlier uses HTTP Basic Authentication, which transmits usernames and passwords in bas

    KritikCVSS 9,8İstismar yokEPSS %2

    ge · proficy real-time information portal28 Oca 2008

  • CVE-2019-19228
    40Planlayın

    Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allow attackers to bypass authentication because the password for the today account

    KritikCVSS 9,8İstismar yokEPSS %2

    fronius · datamanager box 2.0 firmware4 Ara 2019

  • CVE-2019-9823
    39İzleyin

    In several JetBrains IntelliJ IDEA versions, creating remote run configurations of JavaEE application servers leads to saving a cleartext re

    KritikCVSS 9,8İstismar yokEPSS %2

    jetbrains · intellij idea3 Tem 2019

  • CVE-2019-9873
    39İzleyin

    In several versions of JetBrains IntelliJ IDEA Ultimate, creating Task Servers configurations leads to saving a cleartext unencrypted record

    KritikCVSS 9,8İstismar yokEPSS %2

    jetbrains · intellij idea3 Tem 2019

  • CVE-2019-13096
    39İzleyin

    TronLink Wallet 2.2.0 stores user wallet keystore in plaintext and places them in insecure storage.

    KritikCVSS 9,8İstismar yokEPSS %1

    tronlink · wallet22 Tem 2019

  • CVE-2019-11384
    39İzleyin

    The Zalora application 6.15.1 for Android stores confidential information insecurely on the system (i.e.

    KritikCVSS 9,8İstismar yokEPSS %1

    zalora · zalora22 Nis 2019

  • CVE-2018-18641
    39İzleyin

    An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3.

    KritikCVSS 9,8İstismar yokEPSS %1

    gitlab · gitlab4 Ara 2018

  • CVE-2020-15332
    39İzleyin

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/etc/default/axess permissions.

    KritikCVSS 9,8İstismar yokEPSS %1

    zyxel · cloudcnm secumanager28 Eyl 2022

  • CVE-2019-18868
    39İzleyin

    Blaauw Remote Kiln Control through v3.00r4 allows an unauthenticated attacker to access MySQL credentials in cleartext in /engine/db.inc, /l

    KritikCVSS 9,8İstismar yokEPSS %1

    blaauwproducts · remote kiln control7 May 2020

  • CVE-2018-18394
    39İzleyin

    Sensitive Information Stored in Clear Text in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.

    KritikCVSS 9,8İstismar yokEPSS %1

    moxa · thingspro19 Eki 2018

  • CVE-2021-29954
    39İzleyin

    Proxy functionality built into Hubs Cloud’s Reticulum software allowed access to internal URLs, including the metadata service.

    KritikCVSS 9,8İstismar yokEPSS %1

    mozilla · hubs cloud reticulum24 Haz 2021

  • CVE-2023-33373
    39İzleyin

    Connected IO v2.1.0 and prior keeps passwords and credentials in clear-text format, allowing attackers to exfiltrate the credentials and use

    KritikCVSS 9,8İstismar yokEPSS %0

    connectedio · connected io4 Ağu 2023

  • CVE-2023-2809
    39İzleyin

    Use of Cleartext credentials in Sage 200 Spain

    KritikCVSS 9,8İstismar yokEPSS %0

    sage · sage 200 spain4 Eki 2023

  • CVE-2024-46340
    39İzleyin

    TL-WR845N(UN)_V4_201214, TP-Link TL-WR845N(UN)_V4_200909, and TL-WR845N(UN)_V4_190219 was discovered to transmit user credentials in plainte

    KritikCVSS 9,8İstismar yokEPSS %0

    tp-link · tl-wr845n firmware10 Ara 2024

  • CVE-2025-30124
    39İzleyin

    An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices.

    KritikCVSS 9,8İstismar yokEPSS %0

    28 Tem 2025

  • CVE-2025-65826
    39İzleyin

    The mobile application was found to contain stored credentials for the network it was developed on.

    KritikCVSS 9,8İstismar yokEPSS %0

    meatmeet · meatmeet10 Ara 2025

  • CVE-2026-15721
    39İzleyin

    Query Console SQL Injection Leading to Sensitive Data Disclosure in Bilin Software's HUMANIST Digital Human Resources

    KritikCVSS 9,8İstismar yokEPSS %0

    bilin software and informatics consultancy inc. · humanist digital human resources4 Ağu 2026

Tüm zafiyet sınıfları