CWE-312: CWE-312

140
Total CVEs
7
Critical
73
High
6.8
Avg CVSS

Yearly Trend

2026
12
2025
53
2024
37
2023
16
2022
5

Top Affected Vendors

1 Broadcom 5
2 Jenkins 5
3 Tp Link 3
4 Microsoft 3
5 Ibm 3
6 Redhat 3
7 Couchbase 2
8 Dell 2
9 Samsung 2
10 Mailenable 2

All CWE-312 CVEs (140)

CVE-2023-44037
7.5

This vulnerability in ZPE Systems Nodegrid OS allows remote attackers to obtain sensitive information through the TACACS+ server component. Attackers ...

Oct 14, 2023
CVE-2023-39379
7.5

Fujitsu Software Infrastructure Manager (ISM) versions V2.8.0.060 store proxy server passwords in cleartext within maintenance data files (ismsnap). T...

Aug 4, 2023
CVE-2023-30146
7.5

This vulnerability in Assmann Digitus Plug&View IP Camera HT-IP211HDP allows unauthenticated attackers to download the camera's configuration file con...

Aug 4, 2023
CVE-2023-39144
7.5

Element55 KnowMore appliances version 21 and older store passwords in plaintext, allowing attackers with access to the system to read sensitive creden...

Aug 3, 2023
CVE-2023-30367
7.5

mRemoteNG versions up to 1.76.20 and 1.77.3-dev load encrypted configuration files into memory in plain text at startup, even when not actively connec...

Jul 26, 2023
CVE-2023-31821
7.5

This vulnerability in ALBIS v.13.6.1 allows remote attackers to access sensitive information through improper handling of channel access tokens in the...

Jul 13, 2023
CVE-2023-22584
7.5

The Danfoss AK-EM100 energy meter stores login credentials in cleartext, allowing attackers with physical or logical access to read sensitive authenti...

Jun 11, 2023
CVE-2023-29480
7.5

Ribose RNP versions before 0.16.3 fail to properly lock secret keys after use, potentially leaving them accessible in memory. This affects users of RN...

Apr 24, 2023
CVE-2023-31043
7.5

EnterpriseDB EDB Postgres Advanced Server (EPAS) versions before the fixed releases log unredacted passwords in CREATE/ALTER USER/GROUP/ROLE commands ...

Apr 23, 2023
CVE-2022-24660
7.5

The debug interface in Goldshell ASIC Miners firmware versions 2.2.1 and below is publicly accessible through the web interface, allowing unauthentica...

Jul 20, 2022
CVE-2021-42642
7.5

CVE-2021-42642 is an Insecure Direct Object Reference vulnerability in PrinterLogic Web Stack that allows unauthenticated attackers to retrieve plaint...

Feb 2, 2022
CVE-2021-43388
7.5

The Unisys Cargo Mobile Application before version 1.2.29 stores sensitive information in cleartext, making it visible in device backups. This vulnera...

Dec 14, 2021
CVE-2021-42370
7.5

This vulnerability in XoruX LPAR2RRD and STOR2RRD exposes cleartext passwords in HTML password input fields when viewing device properties. Attackers ...

Nov 8, 2021
CVE-2021-37842
7.5

CVE-2021-37842 is a cleartext storage vulnerability in Couchbase Server 7.0.0 where sensitive XDCR (Cross Data Center Replication) credentials can be ...

Nov 2, 2021
CVE-2020-19137
7.5

CVE-2020-19137 is an information disclosure vulnerability in Autumn CMS that allows unauthenticated attackers to retrieve all user credentials in clea...

Sep 8, 2021
CVE-2021-30997
7.5

This vulnerability in Apple's S/MIME email encryption handling allows attackers to potentially recover plaintext contents from encrypted emails. It af...

Aug 24, 2021
CVE-2021-37548
7.5

JetBrains TeamCity versions before 2021.1 could store passwords in cleartext within version control systems (VCS). This vulnerability allows attackers...

Aug 6, 2021
CVE-2021-33323
7.5

This vulnerability in Liferay Portal's Dynamic Data Mapping module allows unauthenticated remote attackers to view form values that were autosaved by ...

Aug 3, 2021
CVE-2020-22741
7.5

This vulnerability in Xuperchain 3.6.0 allows attackers to recover any user's private key after obtaining a partial signature in multisignature transa...

Jul 19, 2021
CVE-2020-12731
7.5

The MagicMotion Flamingo 2 Android application stores sensitive data on the device's external storage (sdcard) without proper access controls, allowin...

Jul 15, 2021
CVE-2021-31816
7.5

CVE-2021-31816 is a cleartext storage vulnerability in Octopus Server where database passwords are written to log files in plaintext during initial co...

Jul 8, 2021
CVE-2020-29324
7.5

CVE-2020-29324 is a credentials disclosure vulnerability in D-Link DIR-895L MFC routers where hardcoded telnet credentials can be extracted through fi...

Jun 4, 2021
CVE-2021-25644
7.5

CVE-2021-25644 is an information disclosure vulnerability in Couchbase Server where incorrect REST API commands cause authentication credentials to be...

May 19, 2021
CVE-2019-18630
7.5

This vulnerability affects Xerox multifunction printers where portions of the drive containing executable code were not encrypted, potentially allowin...

Mar 4, 2021
CVE-2023-5384
7.2

This vulnerability in Infinispan exposes credentials in clear text when cache configurations containing sensitive data (like JDBC or remote store cred...

Dec 18, 2023
CVE-2025-21061
7.1

Smart Switch versions before 3.7.67.2 store sensitive information in cleartext, allowing local attackers with physical or remote access to read this d...

Oct 10, 2025
CVE-2025-3395
7.1

This vulnerability in ABB Automation Builder allows attackers to access sensitive information stored in cleartext and potentially modify critical reso...

Apr 30, 2025
CVE-2024-23942
7.1

CVE-2024-23942 allows local attackers to access unencrypted sensitive data in configuration files on client workstations. This vulnerability enables d...

Mar 18, 2025
CVE-2024-56362
7.1

Navidrome versions before 0.54.1 store JWT secrets in plaintext in the database file, allowing anyone with database access to steal authentication tok...

Dec 23, 2024
CVE-2023-27706
7.1

The Bitwarden Windows desktop application versions before 2023.4.0 store biometric authentication keys in Windows Credential Manager without proper is...

Jun 9, 2023
CVE-2025-4394
6.8

Medtronic MyCareLink Patient Monitor models 24950 and 24952 use an unencrypted filesystem on internal storage, allowing attackers with physical access...

Jul 24, 2025
CVE-2024-34891
6.8

This vulnerability allows remote administrators to read Exchange account passwords stored in DAV server settings via HTTP GET requests. It affects Bit...

Nov 4, 2024
CVE-2026-23655
6.5

This vulnerability in Azure Compute Gallery allows cleartext storage of sensitive information, enabling authorized attackers to access and disclose th...

Feb 10, 2026
CVE-2025-10464
6.5

This vulnerability allows attackers to retrieve embedded sensitive data from Birtech Senseway software due to insecure storage practices. All users of...

Feb 9, 2026
CVE-2025-12679
6.5

This vulnerability exposes the Password-Based Encryption (PBE) key in plaintext within system audit logs during migration operations in Brocade SANnav...

Feb 2, 2026
CVE-2025-53670
6.5

The Jenkins Nouvola DiveCloud Plugin 1.08 and earlier stores sensitive API keys and encryption keys unencrypted in job configuration files. This allow...

Jul 9, 2025
CVE-2025-53672
6.5

The Jenkins Kryptowire Plugin stores API keys unencrypted in configuration files, allowing attackers with file system access to steal sensitive creden...

Jul 9, 2025
CVE-2024-55928
6.5

Xerox Workplace Suite stores sensitive secrets like passwords and API keys in unencrypted plain text, making them accessible to attackers who can read...

Jan 23, 2025
CVE-2024-42451
6.5

This vulnerability in Veeam Backup & Replication allows authenticated low-privileged users to retrieve all stored credentials in plaintext through ext...

Dec 4, 2024
CVE-2024-31415
6.3

CVE-2024-31415 is a vulnerability in Eaton Foreseer software where encryption keys for server configurations are insecurely stored. This allows attack...

Sep 13, 2024
CVE-2025-55334
6.2

This vulnerability involves cleartext storage of sensitive information in the Windows Kernel, allowing local attackers to bypass security features. It...

Oct 14, 2025
CVE-2025-40752
6.2

This vulnerability allows authenticated local attackers to extract plain-text SMTP passwords from Siemens SICAM Q100/Q200 power meters. Attackers coul...

Aug 12, 2025
CVE-2025-40753
6.2

This vulnerability exposes SMTP account passwords in plain text within configuration files on Siemens SICAM Q100 and Q200 power meters. An authenticat...

Aug 12, 2025
CVE-2025-4737
6.2

This vulnerability in the Transsion AIVoiceAssistant mobile app allows attackers to access sensitive information due to insufficient encryption. It af...

May 15, 2025
CVE-2024-13843
6.0

This vulnerability allows local authenticated administrators on Ivanti Connect Secure and Policy Secure systems to read sensitive data stored in clear...

Feb 11, 2025
CVE-2024-29146
5.9

This vulnerability in Sharp and Toshiba multifunction printers exposes decrypted user passwords in memory before login, allowing attackers to retrieve...

Nov 26, 2024
CVE-2025-53103
5.8

JUnit versions 5.12.0 to 5.13.1 can leak Git credentials through Open Test Reporting XML files. If these test reports are published or stored publicly...

Jul 1, 2025
CVE-2025-47147
5.7

This vulnerability allows attackers with physical access to a logged-in operator's mobile device to extract session tokens stored in cleartext. Attack...

Mar 3, 2026
CVE-2025-32752
5.7

Dell ThinOS 2502 and earlier versions store sensitive information in cleartext, allowing high-privileged attackers with physical access to read this d...

May 29, 2025
CVE-2024-55582
5.7

CVE-2024-55582 is a vulnerability in Oxide versions before 6 where Control Plane datastores are stored unencrypted. This allows attackers with access ...

Dec 9, 2024

About CWE-312 (CWE-312)

Our database tracks 140 CVEs classified as CWE-312, with 7 rated critical and 73 rated high severity. The average CVSS score for CWE-312 vulnerabilities is 6.8.

External reference: View CWE-312 on MITRE CWE →

Monitor CWE-312 Vulnerabilities

Get alerted when new CWE-312 CVEs affect your infrastructure.

Start Monitoring Free