A vulnerability classified as problematic was found in Netis WF-2404 1.1.124EN. Affected by this vulnerability is an unk
Flock Safety Gunshot Detection devices before 1.3 have cleartext storage of code.
Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have cleartext storage of code.
A vulnerability, which was classified as problematic, has been found in FNKvision FNK-GU2 up to 40.1.7. Affected by this
next-forge is a Next.js project boilerplate for modern web application. The BASEHUB_TOKEN commited in apps/web/.env.exam
PMD is an extensible multilanguage static code analyzer. The passphrase for the PMD and PMD Designer release signing key
This vulnerability exists in the Tinxy smart devices due to storage of credentials in plaintext within the device firmwa
The lack of encryption in the DuoxMe (formerly Blue) application binary in versions prior to 3.3.1 for iOS devices allow
Valmet DNA user passwords in plain text. This practice poses a security risk as attackers who gain access to local proje
This vulnerability exists in TP-Link Tapo H200 V1 IoT Smart Hub due to storage of Wi-Fi credentials in plain text withi
A vulnerability in the Palo Alto Networks PAN-OS® software enables unlicensed administrators to view clear-text data cap
The data stored in Be-Tech Mifare Classic card is stored in cleartext. An attacker having access to a Be-Tech hotel gues
This vulnerability exists in Digisol DG-GR6821AC Router due to storage of credentials and PINS without encryption in the
This vulnerability exists in Digisol DG-GR6821AC Router due to use of default admin credentials at its web management in
This vulnerability exists in ZKTeco WL20 due to storage of admin and user credentials without encryption in the device f
This vulnerability exists in ZKTeco WL20 due to storage of Wi-Fi credentials, configuration data and system data in plai
A sensitive information disclosure vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can result in the cleart
A problem with the implementation of the MACsec protocol in Palo Alto Networks PAN-OS® results in the cleartext exposure
Information disclosure and exposure of authentication FTP credentials over the debug port 1604 in the MINOVA TTA service
Local Deep Research is an AI-powered research assistant for deep, iterative research. Versions 0.2.0 through 0.6.7 store
R Radio Network FM Transmitter 1.07 allows unauthenticated attackers to access the admin user's password through the sys
TL-WR845N(UN)_V4_201214, TP-Link TL-WR845N(UN)_V4_200909, and TL-WR845N(UN)_V4_190219 was discovered to transmit user cr
The decrypted configuration file contains the password in cleartext which is used to configure WINSelect. It can be use
No-IP Dynamic Update Client (DUC) v3.x uses cleartext credentials that may occur on a command line or in a file. NOTE: t
The health endpoint is public so everybody can see a list of all services. It is potentially valuable information for at
Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 was discovered to store credentials in plaintext.
An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Sensitive information is stored in cleartext. It
An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive password in firmware update package
CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that exposes test credentials in the firmware b
Asus RT-N12+ B1 router stores user passwords in plaintext, which could allow local attackers to obtain unauthorized acce
A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 Domain Cont
zhmcclient is a pure Python client library for the IBM Z HMC Web Services API. In affected versions the Python package "
ibm.ibm_zhmc is an Ansible collection for the IBM Z HMC. The Ansible collection "ibm.ibm_zhmc" writes password-like prop
A vulnerability identified in storing and reusing information in Advance Authentication. This issue can lead to leakage
Cleartext storage of sensitive information vulnerability exists in WindLDR and WindO/I-NV4. If this vulnerability is exp
IBM Storage Defender - Resiliency Service 2.0 could allow a privileged user to perform unauthorized actions after obtain
The Kiuwan Local Analyzer (KLA) Java scanning application contains several hard-coded secrets in plain text format. In
In Infinera TNMS (Transcend Network Management System) 19.10.3, cleartext storage of sensitive information in memory of
TP-Link Tapo APK up to v2.12.703 uses hardcoded credentials for access to the login panel.
Prior to v7.4.0, Ember ZNet is vulnerable to a denial of service attack through manipulation of the NWK sequence number
SQL injection vulnerability in Jfinalcms v.5.0.0 allows a remote attacker to obtain sensitive information via /admin/adm
An issue was discovered in Newland Nquire 1000 Interactive Kiosk version NQ1000-II_G_V1.00.011, allows remote attackers
An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Cleartext passwords and hashes
An issue in axonaut v.3.1.23 and before allows a remote attacker to obtain sensitive information via the log.txt compone
Electrolink transmitters store credentials in clear-text. Use of these credentials could allow an attacker to access the
A flaw was found in Keycloak in OAuth 2.0 Pushed Authorization Requests (PAR). Client-provided parameters were found to
An issue was found on the Ruijie EG-2000 series gateway. An attacker can easily dump cleartext stored passwords in /data
Insecure Permissions vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s
Cleartext Storage of Sensitive Information vulnerability in NAC Telecommunication Systems Inc. NACPremium allows Retriev
Tina is an open-source content management system (CMS). Sites building with Tina CMS's command line interface (CLI) prio
Frequently Asked Questions
What is CWE-312?
CWE-312 (CWE-312) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-312?
There are 978 CVE records associated with CWE-312 in our database. Of these, 40 are critical severity, 260 are high severity, and 445 are medium severity.
How can I protect against CWE-312 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-312 using AI-powered security agents.
Detect CWE-312 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-312 vulnerabilities across your infrastructure.
Get Started