Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 uses the ecos_pw cookie for authentication, which conta
JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, every MCP write tool (send_tokens,
Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Dig
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui backup restore mechanism
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to bypass security restrictions due to t
Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These token
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering t
Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive inform
openssl_encrypt (pip package openssl-encrypt) versions 1.4.8 and earlier store an mTLS client private key in cleartext w
SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, API tokens used to authenticate all REST API
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.17.15, 1.
A flaw was found in the Submariner operator. This vulnerability allows for the exposure of a long-lived broker service a
Trino is a distributed SQL query engine for big data analytics. From version 439 to before version 480, Iceberg connecto
In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data.
FaceSentry Access Control System 6.4.8 contains a cleartext password storage vulnerability that allows attackers to acce
The vulnerability exists in BLUVOYIX due to an improper password storage implementation and subsequent exposure via unau
A vulnerability in the migration script for Brocade SANnav before 3.0 could allow the collection of database sql queries
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An information disclosure vulnerability in FUX
Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209 store a user password in a client-side c
Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to stroe credentials in plaintext in the component uac_
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the API plugin exposes a `decryptStr
WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo allows content owners to pass
Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to version 1.4.10, the GET /api/auth/ses
Changing backend users' passwords via the user settings module results in storing the cleartext password in the uc and u
Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_
CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that could cause the disclosure of a sensitive
VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthent
Cleartext Storage of Sensitive Information vulnerability in Apache CloudStack with AsyncJob storage in the database. Th
Cleartext storage of sensitive information in the ModelBuilder/Serve component in Amazon SageMaker Python SDK before v2.
GNCC GP5 v7.1.76 was discovered to store pre-signed Backblaze B2 upload URLs (PUT requests) in plaintext to the serial c
The vulnerability affecting TL-WR850N v3 allows cleartext storage of administrative and Wi-Fi credentials in a region of
Grav is a file-based Web platform. Prior to 1.7.53, an authenticated administrator with backup permissions can download
Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessi
A vulnerability in Brocade SANnav before 2.4.0b prints the Password-Based Encryption (PBE) key in plaintext in the syst
Insecure Storage of Sensitive Information vulnerability in Birtech Information Technologies Industry and Trade Ltd. Co.
Cleartext storage of sensitive information in Azure Compute Gallery allows an authorized attacker to disclose informatio
The OpenID Connect (OIDC) authentication configuration in PowerShell Universal before 2026.1.3 stores the OIDC client s
An issue pertaining to CWE-312: Cleartext Storage of Sensitive Information was discovered in lesspass lesspass v9.6.9 wh
Edimax GS-5008PL firmware version 1.00.54 and prior contain an insecure credential storage vulnerability that allows att
When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being u
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus stores revis
OpenClaw before 2026.3.22 contains an information disclosure vulnerability that allows attackers with operator.read scop
OpenClaw before 2026.3.31 stores Nostr privateKey as plaintext in configuration, allowing exposure through config.get me
Improper access control in the ticketing integration settings in Devolutions Server allows an authenticated low-privileg
n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a credential exposure vulnerability: when configured with a Goo
Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and ear
Cleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access
A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the
Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates
Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that
Frequently Asked Questions
What is CWE-312?
CWE-312 (CWE-312) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-312?
There are 230 CVE records associated with CWE-312 in our database. Of these, 16 are critical severity, 61 are high severity, and 95 are medium severity.
How can I protect against CWE-312 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-312 using AI-powered security agents.
Detect CWE-312 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-312 vulnerabilities across your infrastructure.
Get Started