CWE-256: CWE-256
Yearly Trend
Top Affected Vendors
All CWE-256 CVEs (58)
Hunt Electronic HBF-09KD and HBF-16NK hybrid DVR models expose a system configuration file containing plaintext administrator credentials to unauthent...
Jun 26, 2025Smart Parking Management System from Honding Technology exposes plaintext administrator credentials through an unauthenticated web page. This allows r...
Jun 9, 2025CVE-2024-5960 is a plaintext password storage vulnerability in Eliz Software Panel that allows attackers to access stored credentials. This affects al...
Sep 18, 2024This vulnerability allows unauthenticated attackers on the same network to obtain router credentials stored in plaintext. It affects BUFFALO wireless ...
Apr 15, 2024This vulnerability allows remote attackers to obtain user credentials stored in plaintext within XML files in Hamastar MeetingHub Paperless Meetings 2...
Aug 5, 2024The Victure PC420 camera firmware version 1.1.39 contains a hardcoded root password stored in plaintext, allowing attackers to gain administrative acc...
Sep 18, 2024CVE-2024-3622 is a vulnerability in mirror-registry for Quay installations where a default secret is stored in plain text in configuration files. This...
Apr 25, 2024Dell EMC Repository Manager (DRM) version 3.2 stores proxy server passwords in plain text in a local database. This allows any authenticated local use...
Jul 19, 2021Dell EMC System Update versions 1.9.2 and earlier store user credentials insecurely, allowing local attackers with user privileges to read passwords. ...
Jan 24, 2022This vulnerability in Zabbix's front-end audit log allows unauthorized viewing of plaintext passwords. Attackers with access to the audit log interfac...
Aug 12, 2024This vulnerability exposes LUKS disk encryption keys in plain text on legacy BIOS installations with specific manual partitioning configurations. It a...
Aug 16, 2024Rockwell Automation ISaGRAF Runtime versions 4.x and 5.x store passwords in plaintext files in the same directory as the executable. This allows local...
Mar 18, 2022CVE-2025-56527 allows attackers to steal plaintext passwords stored in the client's localStorage in Kotaemon 0.11.0. This affects all users of the vul...
Nov 18, 2025QuickCMS version 6.8 contains hardcoded admin credentials stored in plaintext within a configuration file. Attackers with access to the source code or...
Nov 14, 2025Draytek routers store passwords in plaintext instead of using secure hashing, allowing attackers with access to the device's storage to read sensitive...
Feb 27, 2025Dell VxRail versions 8.0.000 through 8.0.311 store passwords in plaintext, allowing high-privileged attackers with local access to read sensitive cred...
Jan 8, 2025Dell VxRail versions 7.0.000 through 7.0.532 store passwords in plaintext, allowing a high-privileged attacker with local access to read sensitive cre...
Jan 8, 2025This vulnerability allows remote unauthenticated attackers to extract plaintext passwords from project files in Mitsubishi Electric PLC systems. Attac...
Mar 3, 2023Rundeck 4.2.0 and 4.2.1 have a vulnerability where the Key Storage encryption mechanism fails to work properly, causing credentials to be stored in pl...
Jun 15, 2022Dell PowerStore storage systems store certain user credentials in plain text, allowing locally authenticated attackers to read sensitive passwords. Th...
Jun 2, 2022A vulnerability in Hitachi Energy Asset Suite's SOAP Web services allows attackers to bypass authentication mechanisms and expand password attack wind...
May 30, 2025Toshiba printers have coredump binaries with incorrect permissions, allowing local attackers to read sensitive information. This affects specific Tosh...
Jun 14, 2024A vulnerability in ABB's VideONet component within System 800xA versions allows attackers to disrupt or manipulate video feeds. This affects industria...
Feb 10, 2025This vulnerability in Quay's mirror-registry exposes database credentials stored in plain-text within the jinja config.yaml file. An attacker with acc...
Apr 25, 2024This vulnerability allows unauthenticated attackers to access the admin.xml file containing plaintext credentials for all users, including administrat...
Sep 20, 2023Dell VxVerify versions before x.40.405 store passwords in plain text within shell wrapper files. A local high-privileged attacker can read these crede...
Dec 11, 2024CVE-2024-28736 is a local privilege escalation vulnerability in Debezium Community UI version 2.5 that allows an attacker with local access to execute...
May 31, 2024Dell CloudBoost Virtual Appliance versions before 19.14.0.0 store passwords in plaintext, allowing attackers with remote access and high privileges to...
Jan 27, 2026This vulnerability in Dell CloudLink allows privileged users to escalate their privileges or access the database to obtain confidential information. I...
Nov 5, 2025SoftPerfect Connection Quality Monitor v1.1 stores all credentials in plaintext, allowing attackers with access to the system to read sensitive authen...
Jul 24, 2025The Jenkins ReadyAPI Functional Testing Plugin 1.11 and earlier stores sensitive credentials unencrypted in job configuration files on the Jenkins con...
Jul 9, 2025The Jenkins IFTTT Build Notifier Plugin stores sensitive IFTTT Maker Channel Keys unencrypted in configuration files, allowing users with Item/Extende...
Jul 9, 2025The Jenkins Apica Loadtest Plugin stores authentication tokens in plaintext within job configuration files, allowing users with Item/Extended Read per...
Jul 9, 2025This vulnerability exposes PostgreSQL database credentials stored in plain text (partially base64 encoded) in SICK industrial control systems. Attacke...
Jul 3, 2025Arista EOS devices with gNMI transport enabled may log or transmit remote server credentials when using the gNOI File TransferToRemote RPC. This affec...
May 7, 2025Bosscomm IF740 OBD2 tablets store passwords in cleartext, allowing attackers with physical or logical access to read sensitive credentials. This affec...
Feb 28, 2025IBM Common Licensing 9.0 stores user credentials in plain text, allowing local users to read sensitive authentication data. This affects systems runni...
Jan 26, 2025This vulnerability allows attackers to decrypt sensitive data and impersonate legitimate users or devices by exploiting a cryptographic weakness (CWE-...
Jan 22, 2026Turms Server versions v0.10.0-SNAPSHOT and earlier store administrator passwords in plaintext memory after successful login. Attackers with local syst...
Dec 19, 2025CVE-2024-45283 is an information disclosure vulnerability in SAP NetWeaver AS for Java that allows authorized attackers to obtain usernames and passwo...
Sep 10, 2024IBM Storage Defender - Resiliency Service versions 2.0.0 through 2.0.9 store user credentials in plain text within pod files. This allows authenticate...
Dec 18, 2024HCL Workload Scheduler stores user credentials in plain text files that can be read by local users on the system. This vulnerability allows unauthoriz...
Dec 11, 2025This vulnerability in some Lenovo Tablets allows a local authenticated user or application to access sensitive device-specific information. It affects...
Nov 3, 2025Vasion Print (formerly PrinterLogic) Virtual Appliance stores sensitive credentials in cleartext world-readable files, allowing any local user or proc...
Oct 2, 2025IBM Datacap Navigator versions 9.1.5 through 9.1.9 store user credentials in plain text, allowing local users to read sensitive authentication data. T...
Jul 14, 2024CVE-2024-4425 is a plain-text credential storage vulnerability in CemiPark software that allows attackers with unauthorized device access to retrieve ...
May 14, 2024The Jenkins Sensedia Api Platform tools Plugin 1.0 fails to mask the Sensedia API Manager integration token on the global configuration form, exposing...
Jul 9, 2025IBM InfoSphere Information Server 11.7 contains an information disclosure vulnerability where authenticated users can access sensitive local data unde...
Mar 29, 2025Dell PowerProtect Data Manager versions 19.19 and 19.20 for Hyper-V store passwords in plaintext, allowing high-privileged local attackers to steal cr...
Sep 10, 2025The Charmed MySQL K8s operator versions before revision 221 (Kubernetes) and revision 338 (machine operators) create temporary files containing databa...
Apr 9, 2025About CWE-256 (CWE-256)
Our database tracks 58 CVEs classified as CWE-256, with 5 rated critical and 23 rated high severity. The average CVSS score for CWE-256 vulnerabilities is 6.8.
External reference: View CWE-256 on MITRE CWE →
Monitor CWE-256 Vulnerabilities
Get alerted when new CWE-256 CVEs affect your infrastructure.
Start Monitoring Free