CWE-312: CWE-312

144
Total CVEs
7
Critical
77
High
6.8
Avg CVSS

Yearly Trend

2026
12
2025
53
2024
37
2023
16
2022
5

Top Affected Vendors

1 Broadcom 5
2 Jenkins 5
3 Ibm 4
4 Tp Link 3
5 Microsoft 3
6 Dell 3
7 Redhat 3
8 Couchbase 2
9 Samsung 2
10 Mailenable 2

All CWE-312 CVEs (144)

CVE-2025-53103
5.8

JUnit versions 5.12.0 to 5.13.1 can leak Git credentials through Open Test Reporting XML files. If these test reports are published or stored publicly...

Jul 1, 2025
CVE-2025-47147
5.7

This vulnerability allows attackers with physical access to a logged-in operator's mobile device to extract session tokens stored in cleartext. Attack...

Mar 3, 2026
CVE-2025-32752
5.7

Dell ThinOS 2502 and earlier versions store sensitive information in cleartext, allowing high-privileged attackers with physical access to read this d...

May 29, 2025
CVE-2024-55582
5.7

CVE-2024-55582 is a vulnerability in Oxide versions before 6 where Control Plane datastores are stored unencrypted. This allows attackers with access ...

Dec 9, 2024
CVE-2023-27370
5.7

This vulnerability allows network-adjacent attackers to bypass authentication and access plaintext configuration secrets stored on NETGEAR RAX30 route...

May 3, 2024
CVE-2026-22276
5.5

Dell ECS and ObjectScale store sensitive information in cleartext, allowing local low-privileged attackers to read confidential data. This affects Del...

Jan 23, 2026
CVE-2025-21060
5.5

Samsung Smart Switch versions before 3.7.67.2 store sensitive application backup data in cleartext, allowing local attackers with physical or remote a...

Oct 10, 2025
CVE-2025-54422
5.5

This vulnerability in Sandboxie exposes user passwords during encrypted sandbox creation and modification. Passwords are transmitted via shared memory...

Jul 29, 2025
CVE-2025-54538
5.5

This vulnerability in JetBrains TeamCity allows passwords to be exposed via command line arguments when using the 'hg pull' command. Attackers with ac...

Jul 28, 2025
CVE-2025-41458
5.5

This vulnerability allows local attackers to extract sensitive data from the Two App Studio Journey iOS app by accessing unencrypted database files in...

Jul 21, 2025
CVE-2025-41647
5.5

A local attacker with low privileges can view the connected controller's password in plain text in PLC Designer V4 under specific conditions. This aff...

Jun 25, 2025
CVE-2024-56428
5.5

CVE-2024-56428 allows local attackers to read cleartext credentials from the iLabClient database. This affects users of iTech iLabClient 3.7.1 who hav...

May 21, 2025
CVE-2024-10404
5.5

Brocade SANnav versions before 2.3.1b log sensitive information like passwords and SNMP secrets in clear text. This allows authenticated local attacke...

Feb 14, 2025
CVE-2024-41629
5.5

Texas Instruments Fusion Digital Power Designer v7.10.1 stores credentials in plaintext, allowing local attackers to read sensitive authentication inf...

Sep 12, 2024
CVE-2024-4840
5.5

This vulnerability in OpenStack Platform (RHOSP) director exposes plaintext passwords in log files, potentially allowing unauthorized access to sensit...

May 14, 2024
CVE-2025-59792
5.3

The CVE-2025-59792 vulnerability in Apache Kvrocks allows attackers to obtain plaintext credentials through the MONITOR command. This affects all Apac...

Nov 28, 2025
CVE-2024-43429
5.3

This vulnerability in Moodle allows unauthorized users to view hidden user profile fields through gradebook reports. Users without the 'view hidden us...

Nov 11, 2024
CVE-2024-9802
5.3

CVE-2024-9802 exposes sensitive information through a publicly accessible conformance validation endpoint in Zowe API Layer. This allows unauthenticat...

Oct 10, 2024
CVE-2024-40750
5.3

Linksys Velop Pro 6E and 7 routers transmit Wi-Fi passwords in unencrypted plaintext over the internet during initial setup via the mobile app. This e...

Jul 9, 2024
CVE-2025-11009
5.1

A vulnerability in Mitsubishi Electric GT Designer3 allows local unauthenticated attackers to extract plaintext credentials from project files. This e...

Dec 17, 2025
CVE-2024-47056
5.1

This vulnerability allows unauthenticated attackers to directly access Mautic's .env configuration files via web browser, exposing sensitive informati...

May 28, 2025
CVE-2024-50570
5.0

This vulnerability allows local authenticated users on Windows or Linux systems running affected FortiClient versions to retrieve VPN passwords via me...

Dec 18, 2024
CVE-2026-3221
4.9

Devolutions Server versions 2025.3.14 and earlier store sensitive user account information unencrypted in the database. This allows attackers with dat...

Feb 25, 2026
CVE-2025-12772
4.9

Brocade SANnav versions before 2.4.0b log the Fabric OS Switch admin password in clear text within support save logs and heap dump files during out-of...

Feb 2, 2026
CVE-2025-34270
4.9

Nagios Log Server versions before 2024R2.0.2 expose plaintext AD/LDAP passwords during user import operations. This allows administrators or users wit...

Oct 30, 2025
CVE-2024-7259
4.9

This vulnerability in oVirt allows administrators, including those with ReadOnlyAdmin permissions, to view Provider passwords in cleartext using brows...

Sep 26, 2024
CVE-2024-10523
4.6

This vulnerability allows attackers with physical access to extract Wi-Fi credentials stored in plain text within TP-Link IoT Smart Hub firmware. Affe...

Nov 4, 2024
CVE-2024-41691
4.6

This vulnerability allows attackers with physical access to extract plaintext FTP credentials from SyroTech SY-GPON-1110-WDONT router firmware. Affect...

Jul 26, 2024
CVE-2025-7738
4.4

CVE-2025-7738 exposes GitHub Enterprise client secrets in clear text through Ansible Automation Platform's Gateway API. This affects administrators an...

Jul 31, 2025
CVE-2024-35117
4.4

IBM OpenPages with Watson 9.0 may write sensitive information in clear text to system tracing log files under specific configurations. This could allo...

Dec 11, 2024
CVE-2025-67637
4.3

Jenkins versions 2.540 and earlier (including LTS 2.528.2 and earlier) store build authorization tokens unencrypted in job configuration files. This a...

Dec 10, 2025
CVE-2025-67638
4.3

Jenkins versions 2.540 and earlier (including LTS 2.528.2 and earlier) expose build authorization tokens in plain text on job configuration forms. Thi...

Dec 10, 2025
CVE-2025-27622
4.3

This vulnerability in Jenkins allows attackers with Agent/Extended Read permission to view encrypted secrets stored in agent configuration files via R...

Mar 5, 2025
CVE-2025-54855
4.2

Click Programming Software v3.60 stores credentials in cleartext, allowing local users with file system access to steal them during active administrat...

Sep 23, 2025
CVE-2025-59701
4.1

This vulnerability allows physically proximate attackers with elevated privileges to read and modify the unencrypted SSD contents of affected Entrust ...

Dec 2, 2025
CVE-2024-28024
4.1

This vulnerability in FOXMAN-UN/UNEM systems involves sensitive information being stored in cleartext within accessible resources. Attackers with acce...

Jun 11, 2024
CVE-2025-49728
4.0

Microsoft PC Manager stores sensitive information in cleartext, allowing local attackers to bypass security features. This affects users running vulne...

Sep 16, 2025
CVE-2025-33081
3.3

IBM Concert versions 1.0.0 through 2.1.0 store sensitive information in log files that local users can read. This information disclosure vulnerability...

Feb 3, 2026
CVE-2025-54342
3.3

This vulnerability in Desktop Alert PingAlert's Application Server exposes sensitive information due to incompatible security policies. It affects org...

Nov 14, 2025
CVE-2025-14836
2.7

This vulnerability in ZZCMS 2025 allows attackers to store user data in cleartext on disk through the /reg/user_save.php file. Remote exploitation is ...

Dec 17, 2025
CVE-2024-9432
N/A

This vulnerability allows attackers to retrieve plaintext API keys from OpenText Vertica agents, potentially enabling unauthorized access to Vertica s...

Jan 30, 2026
CVE-2025-59105
N/A

This CVE describes a physical access vulnerability where attackers can desolder flash memory chips from Dormakaba K7 (Linux) and K5 (Windows CE) acces...

Jan 26, 2026
CVE-2025-59102
N/A

This vulnerability allows attackers to download the complete device database backup containing sensitive unencrypted PINs and encrypted MIFARE keys by...

Jan 26, 2026
CVE-2024-58277
N/A

This vulnerability in R Radio Network FM Transmitter 1.07 allows unauthenticated attackers to retrieve the admin password via the system.cgi endpoint....

Dec 4, 2025

About CWE-312 (CWE-312)

Our database tracks 144 CVEs classified as CWE-312, with 7 rated critical and 77 rated high severity. The average CVSS score for CWE-312 vulnerabilities is 6.8.

External reference: View CWE-312 on MITRE CWE →

Monitor CWE-312 Vulnerabilities

Get alerted when new CWE-312 CVEs affect your infrastructure.

Start Monitoring Free