Skip to main content

CWE archive

CWE-312 CVEs

Programmatic archive

829 CVEs tagged with CWE-31250 Critical, 277 High, 454 Medium, 47 Low, 1 Unrated.

CVE-2019-13100

Published Jul 22, 2019

The Send Anywhere application 9.4.18 for Android stores confidential information insecurely on the system (i.e., in cleartext), which allows a non-root user to find out the userna…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-13099

Published Jul 22, 2019

The Momo application 2.1.9 for Android stores confidential information insecurely on the system (i.e., in cleartext), which allows a non-root user to find out the username/passwor…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10351

Published Jul 11, 2019

Jenkins Caliper CI Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access t…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10350

Published Jul 11, 2019

Jenkins Port Allocator Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or acce…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10348

Published Jul 11, 2019

Jenkins Gogs Plugin stored credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-12171

Published Jul 8, 2019

Dropbox.exe (and QtWebEngineProcess.exe in the Web Helper) in the Dropbox desktop application 71.4.108.0 store cleartext credentials in memory upon successful login or new account…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-9873

Published Jul 3, 2019

In several versions of JetBrains IntelliJ IDEA Ultimate, creating Task Servers configurations leads to saving a cleartext unencrypted record of the server credentials in the IDE c…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-9872

Published Jul 3, 2019

In several versions of JetBrains IntelliJ IDEA Ultimate, creating run configurations for cloud application servers leads to saving a cleartext unencrypted record of the server cre…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-9823

Published Jul 3, 2019

In several JetBrains IntelliJ IDEA versions, creating remote run configurations of JavaEE application servers leads to saving a cleartext record of the server credentials in the I…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-2028

Published Jun 6, 2019

IBM Maximo Asset Management 7.6 could allow a an authenticated user to replace a target page with a phishing site which could allow the attacker to obtain highly sensitive informa…

CVSS 6.5 · Medium

CVE-2019-11384

Published Apr 22, 2019

The Zalora application 6.15.1 for Android stores confidential information insecurely on the system (i.e. plain text), which allows a non-root user to find out the username/passwor…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-0285

Published Apr 10, 2019

The .NET SDK WebForm Viewer in SAP Crystal Reports for Visual Studio (fixed in version 2010) discloses sensitive database information including credentials which can be misused by…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2018-19981

Published Apr 4, 2019

Amazon AWS SDK <=2.8.5 for Android uses Android SharedPreferences to store plain text AWS STS Temporary Credentials retrieved by AWS Cognito Identity Service. An attacker can use…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2019-3606

Published Mar 26, 2019

Data Leakage Attacks vulnerability in the web portal component when in an MDR pair in McAfee Network Security Management (NSM) 9.1 < 9.1.7.75 (Update 4) and 9.2 < 9.2.7.31 Update2…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2015-3952

Published Mar 25, 2019

Wireless keys are stored in plain text on Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, vers…

CVSS 7.5 · High

CVE-2018-17499

Published Mar 21, 2019

Envoy Passport for Android and Envoy Passport for iPhone could allow a local attacker to obtain sensitive information, caused by the storing of unencrypted data in logs. An attack…

CVSS 2.9 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 751-775 of 829 CVEsPage 31 of 34