A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in
An issue in the reset_pj.cgi endpoint of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.1
CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and
A plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to
OpenPLC_V3 is vulnerable to a Plaintext Storage of a Password vulnerability that could allow an attacker to retrieve cre
Plaintext Storage of a Password vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server. In a setup where OpenID
Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_
Heatmiser Wifi Thermostat 1.7 contains a credential disclosure vulnerability that allows unauthenticated attackers to re
Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a plaintext storage of a password vulnerability that could expose cl
rust-iot-platform through commit 5df942ab stores user passwords in cleartext without hashing in the user model. Attacker
update_disk_psu_baseline.sh requires password in plain text
Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, Frogman stored API tokens generated by T
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 product stores user credentials and other sensitive informat
Dell CloudBoost Virtual Appliance, versions prior to 19.14.0.0, contains a Plaintext Storage of Password vulnerability.
GUnet OpenEclass 1.7.3 stores user credentials in plaintext, allowing administrators to view all registered users' usern
Weintek cMT3092X HMI stores user account passwords in plaintext.
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.3.0, 5.3.1 stores user credentials in plain text which can be read by a lo
An attacker could decrypt sensitive data, impersonate legitimate users or devices, and potentially gain access to netwo
Credentials of built-in users are insecurely stored in the User directory of PcVue projects, all versions prior to 17.0.
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 could
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, shared view passwords were stored i
Brocade SANnav before Brocade SANnav 2.4.0b logs database passwords in clear text in the standby SANnav server, after di
In Quick.Cart user passwords are stored in plaintext form. An attacker with high privileges can display users' password
Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 stores sensitive information, including administrative
Lemur manages TLS certificate creation. Prior to 1.9.2, lemur.users.service.update assigned a replacement password direc
GNCC GP5 v7.1.76 was discovered to store sensitive wireless network information in plaintext during routine operations t
Dell Device Management Agent (DDMA), versions prior to 26.02, contain a Plaintext Storage of Password vulnerability. A h
Jenkins FitNesse Plugin 1.36 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller,
IBM Security QRadar EDR 3.12 through 3.12.24 stores user credentials in plain text which can be read by a local privileg
A flaw was found in the Ansible Lightspeed extension for Visual Studio Code. This vulnerability allows an attacker with
A weakness has been identified in langflow-ai langflow up to 1.8.3. Impacted is the function remove_api_keys/has_api_ter
A security vulnerability has been detected in XREAL Nebula App up to 3.2.1 on Android. This impacts an unknown function
A security flaw has been discovered in BabyChakra Pregnancy & Parenting App up to 5.4.3.0 on Android. This affects an un
A weakness has been identified in La Nacion App 10.2.25 on Android. This impacts an unknown function of the file source/
A vulnerability was found in Albert Sağlık Hizmetleri ve Ticaret Albert Health up to 1.7.3 on Android. Affected is an un
A vulnerability was determined in CityData CityChat up to 0.12.6 on Android. Affected by this vulnerability is an unknow
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati
Plaintext storage of a password vulnerability in ILM Informatique OpenConcerto allows Retrieve Embedded Sensitive Data.
Quick.Cart stores hard-coded, plaintext admin credentials in a configuration file. This flaw allows attackers with acces
Streamsoft Business Intelligence (BI) stores users' passwords in plaintext form in the database This issue was fixed in
Frequently Asked Questions
What is CWE-256?
CWE-256 (CWE-256) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-256?
There are 41 CVE records associated with CWE-256 in our database. Of these, 2 are critical severity, 13 are high severity, and 15 are medium severity.
How can I protect against CWE-256 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-256 using AI-powered security agents.
Detect CWE-256 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-256 vulnerabilities across your infrastructure.
Get Started