Sensitive smart card data is logged in default INFO logs by Teradici's PCoIP Connection Manager and Security Gateway pri
An internal product security audit of Lenovo XClarity Controller (XCC) discovered that the XCC configuration backup/rest
A flaw was found in ceph in versions prior to 16.y.z where ceph stores mgr module passwords in clear text. This can be f
IBM Security Guardium Insights 2.0.2 stores user credentials in plain in clear text which can be read by a local privile
An issue was discovered in Couchbase Server before 6.0.5, 6.1.x through 6.5.x before 6.5.2, and 6.6.x before 6.6.1. An i
IBM Security Verify Access Docker 10.0.0 stores user credentials in plain clear text which can be read by a local user.
SAP Business One - version 10.0, allows an admin user to view DB password in plain text over the network, which should o
IBM Security Guardium 11.2 discloses sensitive information in the response headers that could be used in further attacks
OpenPGP secret keys that were imported using Thunderbird version 78.8.1 up to version 78.10.1 were stored unencrypted on
A cleartext storage of sensitive information in GUI in FortiADC versions 5.4.3 and below, 6.0.0 and below may allow a re
There is an information leak vulnerability in eCNS280_TD versions V100R005C00 and V100R005C10. A command does not have t
The ownCloud application before 2.15 for Android allows attackers to use adb to include a PIN preferences value in a bac
UCWeb UC 12.12.3.1219 through 12.12.3.1226 uses cleartext HTTP, and thus man-in-the-middle attackers can discover visite
NCH Reflect CRM 3.01 allows local users to discover cleartext user account information by reading the configuration file
An issue was discovered in PrimeKey EJBCA before 7.6.0. When audit logging changes to the alias configurations of variou
During installation or upgrade to Software House C•CURE 9000 v2.70 and American Dynamics victor Video Management System
The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. This could allow an atta
Blaauw Remote Kiln Control through v3.00r4 allows an unauthenticated attacker to access MySQL credentials in cleartext i
Baxter ExactaMix EM 2400 Versions 1.10, 1.11 and ExactaMix EM1200 Versions 1.1, 1.2 systems store device data with sensi
UltraLog Express device management software stores user’s information in cleartext. Any user can obtain accounts informa
The installation procedure in BigBlueButton before 2.2.28 (or earlier) uses ClueCon as the FreeSWITCH password, which al
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.23 and 10.4.10 user sessio
IBM Security Identity Manager Virtual Appliance 7.0.2 stores user credentials in plain in clear text which can be read b
In NGINX Controller 3.0.0-3.4.0, recovery code required to change a user's password is transmitted and stored in the dat
A CWE-316: Cleartext Storage of Sensitive Information in Memory vulnerability exists in Easergy Builder V1.4.7.2 and pri
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. It is an npm pac
GitLab EE 8.4 through 12.5, 12.4.3, and 12.3.6 stored several tokens in plaintext.
Snare for Linux before 1.7.0 has password disclosure because the rendered page contains the field RemotePassword.
Parallels 13 uses cleartext HTTP as part of the update process, allowing man-in-the-middle attacks. Users of out-of-date
Cisco Linksys E4200 1.0.05 Build 7 devices store passwords in cleartext allowing remote attackers to obtain sensitive in
TAIWAN SECOM CO., LTD., a Door Access Control and Personnel Attendance Management system, stores users’ information by c
In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower,
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660
The AD Helper component in WatchGuard Fireware before 5.8.5.10317 allows remote attackers to discover cleartext password
django-nopassword before 5.0.0 stores cleartext secrets in the database.
Universal Robots control box CB 3.1 across firmware versions (tested on 1.12.1, 1.12, 1.11 and 1.10) does not encrypt or
In JetBrains PyCharm 2019.2.5 and 2019.3 on Windows, Apple Notarization Service credentials were included. This is fixed
Users can lock their notes with a password in Memono version 3.8. Thus, users needs to know a password to read notes. Ho
D-Link DIR-865L Ax 1.20B01 Beta devices have Cleartext Storage of Sensitive Information.
A CWE-312: Cleartext Storage of Sensitive Information vulnerability exists in Easergy T300 (Firmware version 1.5.2 and o
An issue was discovered in the stashcat app through 3.9.2 for macOS, Windows, Android, iOS, and possibly other platforms
MiR controllers across firmware versions 2.8.1.1 and before do not encrypt or protect in any way the intellectual proper
An issue was discovered in Navigate CMS 2.9 r1433. Sessions, as well as associated information such as CSRF tokens, are
django-celery-results through 1.2.1 stores task results in the database. Among the data it stores are the variables pass
An issue was discovered on Nescomed Multipara Monitor M1000 devices. The internal storage of the underlying Linux system
A cleartext storage of sensitive information in Nextcloud Desktop Client 2.6.4 gave away information about used proxies
SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settin
An issue was discovered in Aviatrix Controller before R5.3.1151. Encrypted key values are stored in a readable file.
An issue was discovered in URVE Build 24.03.2020. The password of an integration user account (used for the connection o
A vulnerability has been reported to affect QNAP NAS. If exploited, this vulnerability allows an attacker to access sens
Frequently Asked Questions
What is CWE-312?
CWE-312 (CWE-312) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-312?
There are 978 CVE records associated with CWE-312 in our database. Of these, 40 are critical severity, 260 are high severity, and 445 are medium severity.
How can I protect against CWE-312 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-312 using AI-powered security agents.
Detect CWE-312 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-312 vulnerabilities across your infrastructure.
Get Started