Skip to main content

CWE archive

CWE-312 CVEs

Programmatic archive

829 CVEs tagged with CWE-31250 Critical, 277 High, 455 Medium, 47 Low, 0 Unrated.

CVE-2025-54464

Published Aug 13, 2025

This vulnerability exists in ZKTeco WL20 due to storage of admin and user credentials without encryption in the device firmware. An attacker with physical access could exploit thi…

CVSS 7.0 · High
evidence mentions
2
Buzz score
21.0

CVE-2025-40753

Published Aug 12, 2025

A vulnerability has been identified in POWER METER SICAM Q100 (7KG9501-0AA01-0AA1) (All versions >= V2.60 < V2.62), POWER METER SICAM Q100 (7KG9501-0AA01-2AA1) (All versions >= V2…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-40752

Published Aug 12, 2025

A vulnerability has been identified in POWER METER SICAM Q100 (7KG9501-0AA01-0AA1) (All versions >= V2.60 < V2.62), POWER METER SICAM Q100 (7KG9501-0AA01-2AA1) (All versions >= V2…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-51055

Published Aug 6, 2025

Insecure Data Storage of credentials has been found in /api_vedo/configuration/config.yml file in Vedo Suite version 2024.17. This file contains clear-text credentials, secret key…

CVSS 8.6 · High
evidence mentions
1
Buzz score
16.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-8528

Published Aug 4, 2025

A vulnerability classified as problematic has been found in Exrick xboot up to 3.3.4. Affected is an unknown function of the file /xboot/permission/getMenuList. The manipulation l…

CVSS 2.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-7738

Published Jul 31, 2025

A flaw was found in Ansible Automation Platform (AAP) where the Gateway API returns the client secret for certain GitHub Enterprise authenticators in clear text. This vulnerabilit…

CVSS 4.4 · Medium

CVE-2025-54422

Published Jul 29, 2025

Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. In versions 1.16.1 and below, a critical security vulnerability exists in…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2025-54538

Published Jul 28, 2025

In JetBrains TeamCity before 2025.07 password exposure was possible via command line in the "hg pull" command

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-54537

Published Jul 28, 2025

In JetBrains TeamCity before 2025.07 user credentials were stored in plain text in memory snapshots

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-30124

Published Jul 28, 2025

An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. When a new SD card is inserted into the dashcam, the existing password is written onto the SD card in cleartext…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
27.6

CVE-2025-4394

Published Jul 24, 2025

Medtronic MyCareLink Patient Monitor uses an unencrypted filesystem on internal storage, which allows an attacker with physical access to read and modify files. This issue affec…

CVSS 6.8 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2025-41458

Published Jul 21, 2025

Unencrypted storage in the database in Two App Studio Journey v5.5.9 for iOS allows local attackers to extract sensitive data via direct access to the app’s filesystem.

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-7397

Published Jul 17, 2025

A vulnerability in the ascgshell, of Brocade ASCG before 3.3.0 stores any command executed in the Command Line Interface (CLI) in plain text within the command history. A local…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-32353

Published Jul 16, 2025

Kaseya Rapid Fire Tools Network Detective 2.0.16.0 has Unencrypted Credentials (for privileged access) stored in the collector.txt configuration file.

CVSS 8.2 · High
evidence mentions
4
Buzz score
24.1

CVE-2025-53758

Published Jul 16, 2025

This vulnerability exists in Digisol DG-GR6821AC Router due to use of default admin credentials at its web management interface. An attacker with physical access could exploit thi…

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-53755

Published Jul 16, 2025

This vulnerability exists in Digisol DG-GR6821AC Router due to storage of credentials and PINS without encryption in the device firmware. An attacker with physical access could ex…

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-53742

Published Jul 9, 2025

Jenkins Applitools Eyes Plugin 1.16.5 and earlier stores Applitools API keys unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-53672

Published Jul 9, 2025

Jenkins Kryptowire Plugin 0.2 and earlier stores the Kryptowire API key unencrypted in its global configuration file on the Jenkins controller, where it can be viewed by users wit…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-53670

Published Jul 9, 2025

Jenkins Nouvola DiveCloud Plugin 1.08 and earlier stores DiveCloud API Keys and Credentials Encryption Keys unencrypted in job config.xml files on the Jenkins controller, where th…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-7215

Published Jul 9, 2025

A vulnerability, which was classified as problematic, has been found in FNKvision FNK-GU2 up to 40.1.7. Affected by this issue is some unknown functionality of the file /rom/wpa_s…

CVSS 0.3 · Low

CVE-2025-53103

Published Jul 1, 2025

JUnit is a testing framework for Java and the JVM. From version 5.12.0 to 5.13.1, JUnit's support for writing Open Test Reporting XML files can leak Git credentials. The impact de…

CVSS 5.8 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2025-6224

Published Jul 1, 2025

Certificate generation in juju/utils using the cert.NewLeaf function could include private information. If this certificate were then transferred over the network in plaintext, an…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 126-150 of 829 CVEsPage 6 of 34