Skip to main content

CWE archive

CWE-312 CVEs

Programmatic archive

813 CVEs tagged with CWE-31248 Critical, 274 High, 445 Medium, 46 Low, 0 Unrated.

CVE-2025-67638

Published Dec 10, 2025

Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not mask build authorization tokens displayed on the job configuration form, increasing the potential for attackers to obse…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-67637

Published Dec 10, 2025

Jenkins 2.540 and earlier, LTS 2.528.2 and earlier stores build authorization tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by user…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-58277

Published Dec 4, 2025

R Radio Network FM Transmitter 1.07 allows unauthenticated attackers to access the admin user's password through the system.cgi endpoint, enabling authentication bypass and FM sta…

CVSS 8.7 · High

CVE-2025-65320

Published Dec 3, 2025

Abacre Restaurant Point of Sale (POS) up to 15.0.0.1656 are vulnerable to Cleartext Storage of Sensitive Information in Memory. The application leaves valid device-bound license k…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-59701

Published Dec 2, 2025

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker (with elevated privileges) to read and modify the Applianc…

CVSS 4.1 · Medium

CVE-2025-59792

Published Nov 28, 2025

Reveals plaintext credentials in the MONITOR command vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 1.0.0 through 2.13.0. Users are recommended to upgr…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-3784

Published Nov 27, 2025

Cleartext Storage of Sensitive Information Vulnerability in GX Works2 all versions allows an attacker to disclose credential information stored in plaintext from project files. As…

CVSS 5.5 · Medium

CVE-2025-65278

Published Nov 26, 2025

An issue was discovered in file users.json in GroceryMart commit 21934e6 (2020-10-23) allowing unauthenticated attackers to gain sensitive information including plaintext username…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-25613

Published Nov 20, 2025

FS Inc S3150-8T2F 8-Port Gigabit Ethernet L2+ Switch, 8 x Gigabit RJ45, with 2 x 1Gb SFP, Fanless. All versions before 2.2.0D Build 135103 were discovered to transmit cookies for…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-54342

Published Nov 14, 2025

A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There is Exposure of Sensitive Information because of Incompatible Poli…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-34270

Published Oct 30, 2025

Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the AD/LDAP user import functionality as it fails to obfuscate the password field during import. As a res…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-48428

Published Oct 23, 2025

Cleartext Storage of Sensitive Information (CWE-312) in the Gallagher Morpho integration could allow an authenticated user with access to the Command Centre Server to export a spe…

CVSS 6.7 · Medium

CVE-2025-21061

Published Oct 10, 2025

Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access sensitive data. User interaction is required for triggering t…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-21060

Published Oct 10, 2025

Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access backup data from applications. User interaction is required f…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59450

Published Oct 6, 2025

The YoSmart YoLink Smart Hub firmware 0382 is unencrypted, and data extracted from it can be used to determine network access credentials.

CVSS 4.3 · Medium

CVE-2025-23291

Published Sep 30, 2025

NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an User/Attacker may cause an authorized action. A successful exploit of this vulnera…

CVSS 2.4 · Low

CVE-2025-54855

Published Sep 23, 2025

Cleartext storage of sensitive information was discovered in Click Programming Software version v3.60. The vulnerability can be exploited by a local user with access to the file s…

CVSS 4.1 · Medium
Showing 76-100 of 813 CVEsPage 4 of 33