A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) (All versions < V19). An information disclosure vulne
IBM Security Verify Governance 10.0 stores user credentials in plain clear text which can be read by a local user. IBM
An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It uses a local database to store dat
A vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to expose the plaintext val
A vulnerability was found in Control iD Gerencia Web 1.30 and classified as problematic. Affected by this issue is some
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. When users update their
A vulnerability has been found in Simple Design Daily Journal 1.012.GP.B on Android and classified as problematic. Affec
Nextcloud mail is an email app for the nextcloud home server platform. In versions prior to 2.2.2 user's passwords were
A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster
An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the a
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/etc/default/axess permissions.
Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU all versi
IXPdata EasyInstall 6.6.14725 contains an access control issue.
Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.095Z
Dell Wyse Management Suite 3.6.1 and below contains a Sensitive Data Exposure vulnerability. A low privileged malicious
The web-based admin console in H2 Database Engine before 2.2.220 can be started via the CLI with the argument -webAdminP
AVEVA System Platform 2020 stores sensitive information in cleartext, which may allow access to an attacker or a low-pri
A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions), SIMATIC PCS
A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the
During an update of SAP BusinessObjects Enterprise, Central Management Server (CMS) - versions 420, 430, authentication
Windows Credential Guard Domain-joined Public Key Elevation of Privilege Vulnerability
Devices with keyprotect off may store unencrypted keybox in RPMB and cause cryptographic issue in Snapdragon Auto, Snapd
A vulnerability has been identified in QMS Automotive (All versions < V12.39), QMS Automotive (All versions < V12.39). U
Airtable.js is the JavaScript client for Airtable. Prior to version 0.11.6, Airtable.js had a misconfigured build script
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vul
" Insecure password storage issue.The application stores sensitive information in cleartext within a resource that might
CVEProject/cve-services is an open source project used to operate the CVE services API. A conditional in 'data.js' has p
ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to C
The debug interface of Goldshell ASIC Miners v2.2.1 and below was discovered to be exposed publicly on the web interface
The Motorola MOSCAD Toolbox software through 2022-05-02 relies on a cleartext password. It utilizes an MDLC driver to co
In Omron CS series, CJ series, and CP series PLCs through 2022-05-18, the password for access to the Web UI is stored in
Lanling OA Landray Office Automation (OA) internal patch number #133383/#137780 contains an arbitrary file read vulnerab
bilde2910 Hauk v1.6.1 requires a hardcoded password which by default is blank. This hardcoded password is hashed but sto
The PassWork extension 5.0.9 for Chrome and other browsers allows an attacker to obtain cleartext cached credentials.
The PassWork extension 5.0.9 for Chrome and other browsers allows an attacker to obtain the cleartext master password.
The /device/signin end-point for the Ourphoto App version 1.4.1 discloses clear-text password information for functional
A vulnerability exists in the Intelligent Electronic Device (IED) Connectivity Package (ConnPack) credential storage fun
Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.087R
A cleartext storage of information vulnerability in the Zyxel VMG3625-T50B firmware version V5.50(ABTL.0)b2k could allow
3CX System through 2022-03-17 stores cleartext passwords in a database.
FileZilla v3.59.0 allows attackers to obtain cleartext passwords of connected SSH or FTP servers via a memory dump.- NOT
An issue has been discovered in hunter2 affecting all versions before 2.1.0. Improper handling of auto-completion input
A flaw was found in ovirt-engine, which leads to the logging of plaintext passwords in the log file when using otapi-sty
"IBM Cognos Analytics 11.2.1, 11.2.0, 11.1.7 stores user credentials in plain clear text which can be read by an authent
Dell Wyse Management Suite 3.6.1 and below contains an Plain-text Password Storage Vulnerability in UI. An attacker with
Browsing the path: http://ip/wifi_ap_pata_get.cmd, will show in the name of the existing access point on the component,
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When the `reset
Charactell - FormStorm Enterprise Account takeover – An attacker can modify (add, remove and update) passwords file for
Dell EMC Enterprise Storage Analytics for vRealize Operations, versions 4.0.1 to 6.2.1, contain a Plain-text password st
Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU all versi
Frequently Asked Questions
What is CWE-312?
CWE-312 (CWE-312) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-312?
There are 978 CVE records associated with CWE-312 in our database. Of these, 40 are critical severity, 260 are high severity, and 445 are medium severity.
How can I protect against CWE-312 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-312 using AI-powered security agents.
Detect CWE-312 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-312 vulnerabilities across your infrastructure.
Get Started