CWE-256: CWE-256

58
Total CVEs
5
Critical
23
High
6.8
Avg CVSS

Yearly Trend

2026
3
2025
30
2024
18
2023
2
2022
4

Top Affected Vendors

1 Dell 9
2 Ibm 6
3 Jenkins 6
4 Opensolution 2
5 Schneider Electric 1
6 Mitsubishielectric 1
7 Elizsoftware 1
8 Hamastar 1
9 Proges 1
10 Redhat 1

All CWE-256 CVEs (58)

CVE-2025-6561
9.8

Hunt Electronic HBF-09KD and HBF-16NK hybrid DVR models expose a system configuration file containing plaintext administrator credentials to unauthent...

Jun 26, 2025
CVE-2025-5893
9.8

Smart Parking Management System from Honding Technology exposes plaintext administrator credentials through an unauthenticated web page. This allows r...

Jun 9, 2025
CVE-2024-5960
9.8

CVE-2024-5960 is a plaintext password storage vulnerability in Eliz Software Panel that allows attackers to access stored credentials. This affects al...

Sep 18, 2024
CVE-2024-23486
9.8

This vulnerability allows unauthenticated attackers on the same network to obtain router credentials stored in plaintext. It affects BUFFALO wireless ...

Apr 15, 2024
CVE-2024-6118
9.1

This vulnerability allows remote attackers to obtain user credentials stored in plaintext within XML files in Hamastar MeetingHub Paperless Meetings 2...

Aug 5, 2024
CVE-2023-41610
8.8

The Victure PC420 camera firmware version 1.1.39 contains a hardcoded root password stored in plaintext, allowing attackers to gain administrative acc...

Sep 18, 2024
CVE-2024-3622
8.8

CVE-2024-3622 is a vulnerability in mirror-registry for Quay installations where a default secret is stored in plain text in configuration files. This...

Apr 25, 2024
CVE-2020-5315
8.8

Dell EMC Repository Manager (DRM) version 3.2 stores proxy server passwords in plain text in a local database. This allows any authenticated local use...

Jul 19, 2021
CVE-2022-22554
8.2

Dell EMC System Update versions 1.9.2 and earlier store user credentials insecurely, allowing local attackers with user privileges to read passwords. ...

Jan 24, 2022
CVE-2024-36460
8.1

This vulnerability in Zabbix's front-end audit log allows unauthorized viewing of plaintext passwords. Attackers with access to the audit log interfac...

Aug 12, 2024
CVE-2024-43378
7.8

This vulnerability exposes LUKS disk encryption keys in plain text on legacy BIOS installations with specific manual partitioning configurations. It a...

Aug 16, 2024
CVE-2020-25184
7.8

Rockwell Automation ISaGRAF Runtime versions 4.x and 5.x store passwords in plaintext files in the same directory as the executable. This allows local...

Mar 18, 2022
CVE-2025-56527
7.5

CVE-2025-56527 allows attackers to steal plaintext passwords stored in the client's localStorage in Kotaemon 0.11.0. This affects all users of the vul...

Nov 18, 2025
CVE-2025-9982
7.5

QuickCMS version 6.8 contains hardcoded admin credentials stored in plaintext within a configuration file. Attackers with access to the source code or...

Nov 14, 2025
CVE-2024-41336
7.5

Draytek routers store passwords in plaintext instead of using secure hashing, allowing attackers with access to the device's storage to read sensitive...

Feb 27, 2025
CVE-2025-21111
7.5

Dell VxRail versions 8.0.000 through 8.0.311 store passwords in plaintext, allowing high-privileged attackers with local access to read sensitive cred...

Jan 8, 2025
CVE-2025-21102
7.5

Dell VxRail versions 7.0.000 through 7.0.532 store passwords in plaintext, allowing a high-privileged attacker with local access to read sensitive cre...

Jan 8, 2025
CVE-2023-0457
7.5

This vulnerability allows remote unauthenticated attackers to extract plaintext passwords from project files in Mitsubishi Electric PLC systems. Attac...

Mar 3, 2023
CVE-2022-31044
7.5

Rundeck 4.2.0 and 4.2.1 have a vulnerability where the Key Storage encryption mechanism fails to work properly, causing credentials to be stored in pl...

Jun 15, 2022
CVE-2022-22557
7.5

Dell PowerStore storage systems store certain user credentials in plain text, allowing locally authenticated attackers to read sensitive passwords. Th...

Jun 2, 2022
CVE-2025-2500
7.4

A vulnerability in Hitachi Energy Asset Suite's SOAP Web services allows attackers to bypass authentication mechanisms and expand password attack wind...

May 30, 2025
CVE-2024-27166
7.4

Toshiba printers have coredump binaries with incorrect permissions, allowing local attackers to read sensitive information. This affects specific Tosh...

Jun 14, 2024
CVE-2024-10334
7.3

A vulnerability in ABB's VideONet component within System 800xA versions allows attackers to disrupt or manipulate video feeds. This affects industria...

Feb 10, 2025
CVE-2024-3624
7.3

This vulnerability in Quay's mirror-registry exposes database credentials stored in plain-text within the jinja config.yaml file. An attacker with acc...

Apr 25, 2024
CVE-2022-47561
7.3

This vulnerability allows unauthenticated attackers to access the admin.xml file containing plaintext credentials for all users, including administrat...

Sep 20, 2023
CVE-2024-53292
7.2

Dell VxVerify versions before x.40.405 store passwords in plain text within shell wrapper files. A local high-privileged attacker can read these crede...

Dec 11, 2024
CVE-2024-28736
7.1

CVE-2024-28736 is a local privilege escalation vulnerability in Debezium Community UI version 2.5 that allows an attacker with local access to execute...

May 31, 2024
CVE-2026-21417
7.0

Dell CloudBoost Virtual Appliance versions before 19.14.0.0 store passwords in plaintext, allowing attackers with remote access and high privileges to...

Jan 27, 2026
CVE-2025-46366
6.7

This vulnerability in Dell CloudLink allows privileged users to escalate their privileges or access the database to obtain confidential information. I...

Nov 5, 2025
CVE-2025-45702
6.5

SoftPerfect Connection Quality Monitor v1.1 stores all credentials in plaintext, allowing attackers with access to the system to read sensitive authen...

Jul 24, 2025
CVE-2025-53656
6.5

The Jenkins ReadyAPI Functional Testing Plugin 1.11 and earlier stores sensitive credentials unencrypted in job configuration files on the Jenkins con...

Jul 9, 2025
CVE-2025-53662
6.5

The Jenkins IFTTT Build Notifier Plugin stores sensitive IFTTT Maker Channel Keys unencrypted in configuration files, allowing users with Item/Extende...

Jul 9, 2025
CVE-2025-53664
6.5

The Jenkins Apica Loadtest Plugin stores authentication tokens in plaintext within job configuration files, allowing users with Item/Extended Read per...

Jul 9, 2025
CVE-2025-1709
6.5

This vulnerability exposes PostgreSQL database credentials stored in plain text (partially base64 encoded) in SICK industrial control systems. Attacke...

Jul 3, 2025
CVE-2025-0936
6.5

Arista EOS devices with gNMI transport enabled may log or transmit remote server credentials when using the gNOI File TransferToRemote RPC. This affec...

May 7, 2025
CVE-2025-25727
6.2

Bosscomm IF740 OBD2 tablets store passwords in cleartext, allowing attackers with physical or logical access to read sensitive credentials. This affec...

Feb 28, 2025
CVE-2023-50945
6.2

IBM Common Licensing 9.0 stores user credentials in plain text, allowing local users to read sensitive authentication data. This affects systems runni...

Jan 26, 2025
CVE-2025-25051
6.1

This vulnerability allows attackers to decrypt sensitive data and impersonate legitimate users or devices by exploiting a cryptographic weakness (CWE-...

Jan 22, 2026
CVE-2025-66910
6.0

Turms Server versions v0.10.0-SNAPSHOT and earlier store administrator passwords in plaintext memory after successful login. Attackers with local syst...

Dec 19, 2025
CVE-2024-45283
6.0

CVE-2024-45283 is an information disclosure vulnerability in SAP NetWeaver AS for Java that allows authorized attackers to obtain usernames and passwo...

Sep 10, 2024
CVE-2024-52361
5.7

IBM Storage Defender - Resiliency Service versions 2.0.0 through 2.0.9 store user credentials in plain text within pod files. This allows authenticate...

Dec 18, 2024
CVE-2024-42197
5.5

HCL Workload Scheduler stores user credentials in plain text files that can be read by local users on the system. This vulnerability allows unauthoriz...

Dec 11, 2025
CVE-2025-11193
5.5

This vulnerability in some Lenovo Tablets allows a local authenticated user or application to access sensitive device-specific information. It affects...

Nov 3, 2025
CVE-2025-34210
5.5

Vasion Print (formerly PrinterLogic) Virtual Appliance stores sensitive credentials in cleartext world-readable files, allowing any local user or proc...

Oct 2, 2025
CVE-2024-39733
5.5

IBM Datacap Navigator versions 9.1.5 through 9.1.9 store user credentials in plain text, allowing local users to read sensitive authentication data. T...

Jul 14, 2024
CVE-2024-4425
5.4

CVE-2024-4425 is a plain-text credential storage vulnerability in CemiPark software that allows attackers with unauthorized device access to retrieve ...

May 14, 2024
CVE-2025-53674
5.3

The Jenkins Sensedia Api Platform tools Plugin 1.0 fails to mask the Sensedia API Manager integration token on the global configuration form, exposing...

Jul 9, 2025
CVE-2024-43186
5.3

IBM InfoSphere Information Server 11.7 contains an information disclosure vulnerability where authenticated users can access sensitive local data unde...

Mar 29, 2025
CVE-2025-43938
5.0

Dell PowerProtect Data Manager versions 19.19 and 19.20 for Hyper-V store passwords in plaintext, allowing high-privileged local attackers to steal cr...

Sep 10, 2025
CVE-2025-24375
5.0

The Charmed MySQL K8s operator versions before revision 221 (Kubernetes) and revision 338 (machine operators) create temporary files containing databa...

Apr 9, 2025

About CWE-256 (CWE-256)

Our database tracks 58 CVEs classified as CWE-256, with 5 rated critical and 23 rated high severity. The average CVSS score for CWE-256 vulnerabilities is 6.8.

External reference: View CWE-256 on MITRE CWE →

Monitor CWE-256 Vulnerabilities

Get alerted when new CWE-256 CVEs affect your infrastructure.

Start Monitoring Free