Skip to main content

CWE archive

CWE-312 CVEs

Programmatic archive

824 CVEs tagged with CWE-31249 Critical, 277 High, 451 Medium, 47 Low, 0 Unrated.

CVE-2025-48428

Published Oct 23, 2025

Cleartext Storage of Sensitive Information (CWE-312) in the Gallagher Morpho integration could allow an authenticated user with access to the Command Centre Server to export a spe…

CVSS 6.7 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-21061

Published Oct 10, 2025

Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access sensitive data. User interaction is required for triggering t…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-21060

Published Oct 10, 2025

Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access backup data from applications. User interaction is required f…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-59450

Published Oct 6, 2025

The YoSmart YoLink Smart Hub firmware 0382 is unencrypted, and data extracted from it can be used to determine network access credentials.

CVSS 4.3 · Medium

CVE-2025-23291

Published Sep 30, 2025

NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an User/Attacker may cause an authorized action. A successful exploit of this vulnera…

CVSS 2.4 · Low
evidence mentions
3
Buzz score
25.4

CVE-2025-54855

Published Sep 23, 2025

Cleartext storage of sensitive information was discovered in Click Programming Software version v3.60. The vulnerability can be exploited by a local user with access to the file s…

CVSS 4.1 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2025-49728

Published Sep 16, 2025

Cleartext storage of sensitive information in Microsoft PC Manager allows an unauthorized attacker to bypass a security feature locally.

CVSS 4.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-58401

Published Sep 5, 2025

Obsidian GitHub Copilot Plugin versions prior to 1.1.7 store Github API token in cleartext form. As a result, an attacker may perform unauthorized operations on the linked Github…

CVSS 5.1 · Medium

CVE-2025-57806

Published Sep 3, 2025

Local Deep Research is an AI-powered research assistant for deep, iterative research. Versions 0.2.0 through 0.6.7 stored confidential information, including API keys, in a local…

CVSS 6.9 · Medium

CVE-2024-52284

Published Sep 2, 2025

Unauthorized disclosure of sensitive data: Any user with `GET` or `LIST` permissions on `BundleDeployment` resources could retrieve Helm values containing credentials or other sec…

CVSS 7.7 · High

CVE-2025-55443

Published Aug 26, 2025

Telpo MDM 1.4.6 thru 1.4.9 for Android contains sensitive administrator credentials and MQTT server connection details (IP/port) that are stored in plaintext within log files on t…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-7426

Published Aug 25, 2025

Information disclosure and exposure of authentication FTP credentials over the debug port 1604 in the MINOVA TTA service. This allows unauthenticated remote access to an active FT…

CVSS 9.3 · Critical

CVE-2025-2182

Published Aug 13, 2025

A problem with the implementation of the MACsec protocol in Palo Alto Networks PAN-OS® results in the cleartext exposure of the connectivity association key (CAK). This issue is o…

CVSS 5.6 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-2181

Published Aug 13, 2025

A sensitive information disclosure vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can result in the cleartext exposure of Prisma Cloud access keys in Checkov's outpu…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-55280

Published Aug 13, 2025

This vulnerability exists in ZKTeco WL20 due to storage of Wi-Fi credentials, configuration data and system data in plaintext within the device firmware. An attacker with physical…

CVSS 5.2 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-54464

Published Aug 13, 2025

This vulnerability exists in ZKTeco WL20 due to storage of admin and user credentials without encryption in the device firmware. An attacker with physical access could exploit thi…

CVSS 7.0 · High
evidence mentions
2
Buzz score
21.0

CVE-2025-40753

Published Aug 12, 2025

A vulnerability has been identified in POWER METER SICAM Q100 (7KG9501-0AA01-0AA1) (All versions >= V2.60 < V2.62), POWER METER SICAM Q100 (7KG9501-0AA01-2AA1) (All versions >= V2…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-40752

Published Aug 12, 2025

A vulnerability has been identified in POWER METER SICAM Q100 (7KG9501-0AA01-0AA1) (All versions >= V2.60 < V2.62), POWER METER SICAM Q100 (7KG9501-0AA01-2AA1) (All versions >= V2…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-51055

Published Aug 6, 2025

Insecure Data Storage of credentials has been found in /api_vedo/configuration/config.yml file in Vedo Suite version 2024.17. This file contains clear-text credentials, secret key…

CVSS 8.6 · High
evidence mentions
1
Buzz score
16.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-8528

Published Aug 4, 2025

A vulnerability classified as problematic has been found in Exrick xboot up to 3.3.4. Affected is an unknown function of the file /xboot/permission/getMenuList. The manipulation l…

CVSS 2.9 · Low
Vendor/product tagsBeta · best-effort
Showing 101-125 of 824 CVEsPage 5 of 33