Element55 KnowMore appliances version 21 and older was discovered to store passwords in plaintext.
Assmann Digitus Plug&View IP Camera HT-IP211HDP, version 2.000.022 allows unauthenticated attackers to download a copy o
Fujitsu Software Infrastructure Manager (ISM) stores sensitive information at the product's maintenance data (ismsnap) i
An issue was discovered in SysPasswordDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. System password information c
Sensitive information disclosure due to cleartext storage of sensitive information in memory. The following products are
Sensitive information disclosure due to cleartext storage of sensitive information. The following products are affected:
An issue in ZPE Systems, Inc Nodegrid OS v.5.8.10 thru v.5.8.13 and v.5.10.3 thru v.5.10.5 allows a remote attacker to o
Zentao Biz version 8.7 and before is vulnerable to Information Disclosure.
LOYTEC electronics GmbH LINX Configurator (all versions) is vulnerable to Insecure Permissions. Cleartext storage of cre
LOYTEC electronics GmbH LINX-212 and LINX-151 devices (all versions) are vulnerable to Insecure Permissions via registry
LOYTEC electronics GmbH LINX-212 and LINX-151 devices (all versions) are vulnerable to Insecure Permissions via dpal_con
The Devise gem before 3.5.4 for Ruby mishandles Remember Me cookies for sessions, which may allow an adversary to obtain
XWiki Platform is a generic wiki platform. Starting in 7.2-milestone-2 and prior to versions 14.10.15, 15.5.2, and 15.7-
The BestWebSoft's Like & Share WordPress plugin before 2.74 discloses the content of password protected posts to unauthe
A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credenti
Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior
Bitwarden Windows desktop application versions prior to v2023.4.0 store biometric keys in Windows Credential Manager, ac
Dell BIOS contains an information exposure vulnerability. An unauthenticated local attacker with physical access to the
Missing Encryption of Security Keys vulnerability in Silicon Labs OpenThread SDK on 32 bit, ARM (SecureVault High module
Missing Encryption of Security Keys vulnerability in Silicon Labs Ember ZNet SDK on 32 bit, ARM (SecureVault High module
A pair of spare WiFi credentials is stored in the configuration file of the Zyxel AX7501-B0 firmware prior to V5.17(ABPC
Jenkins view-cloner Plugin 1.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controlle
Information disclosure vulnerability exists in Pgpool-II 4.4.0 to 4.4.1 (4.4 series), 4.3.0 to 4.3.4 (4.3 series), 4.2.0
On Xerox WorkCentre 3550 25.003.03.000 devices, an authenticated attacker can view the SMB server settings and can obtai
MV iDigital Clinic Enterprise (iDCE) 1.0 stores passwords in cleartext.
The fix in 4.6.16, 4.7.9, 4.8.4 and 4.9.7 for CVE-2018-10919 Confidential attribute disclosure vi LDAP filters was insuf
Jenkins WSO2 Oauth Plugin 1.0 and earlier does not mask the WSO2 Oauth client secret on the global configuration form, i
Jenkins Consul KV Builder Plugin 2.0.13 and earlier does not mask the HashiCorp Consul ACL Token on the global configura
Plaintext Password in Registry vulnerability in 42gears surelock windows surelockwinsetupv2.40.0.Exe on Windows (Regi
Cleartext storage of sensitive information exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier, which may al
All versions of the TWinSoft Configuration Tool store encrypted passwords as plaintext in memory. An attacker with acc
PHPJabbers Class Scheduling System 1.0 lacks encryption on the password when editing a user account (update user page) a
An issue was discovered in MariaDB MaxScale before 23.02.3. A user enters an encrypted password on a "maxctrl create ser
Nextcloud server is an open source home cloud platform. Affected versions of Nextcloud stored OAuth2 tokens in plaintext
Nautobot is a Network Automation Platform built as a web application atop the Django Python framework with a PostgreSQL
Jenkins lambdatest-automation Plugin 1.20.10 and earlier logs LAMBDATEST Credentials access token at the INFO level, pot
Headwind MDM Web panel 5.22.1 is vulnerable to Incorrect Access Control due to Login Credential Leakage via Audit Entrie
The App Settings (/admin/app) page in GROWI versions prior to v6.0.6 stores sensitive information in cleartext form. As
Echelon SmartServer 2.2 with i.LON Vision 2.2 stores cleartext credentials in a file, which could allow an attacker
NVIDIA BMC stores user passwords in an obfuscated form in a database accessible by the host. This may lead to a credenti
IBM InfoSphere Information Server 11.7 could allow a local user to obtain sensitive information from a log files. IBM X
IBM InfoSphere Information Server 11.7 stores user credentials in plain clear text which can be read by a local user. I
A password management vulnerability in Skyhigh Secure Web Gateway (SWG) in main releases 11.x prior to 11.2.14, 10.x pr
Dell PowerScale OneFS, 9.0.0.x-9.4.0.x, contain a cleartext storage of sensitive information vulnerability in S3 compon
Feedbacksystem is a personalized feedback system for students using artificial intelligence. Passwords of users using LD
IBM QRadar SIEM 7.4 and 7.5 is vulnerable to information exposure allowing a non-tenant user with a specific domain secu
An issue was discovered in Fujitsu Software Infrastructure Manager (ISM) before 2.8.0.061. The ismsnap component (in thi
Possible information exposure through log file vulnerability where sensitive fields are recorded in the configuration
The Nautobot Device Onboarding plugin uses the netmiko and NAPALM libraries to simplify the onboarding process of a new
Unproper laxist permissions on the temporary files used by MIME4J TempFileStorageProvider may lead to information disclo
Frequently Asked Questions
What is CWE-312?
CWE-312 (CWE-312) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-312?
There are 978 CVE records associated with CWE-312 in our database. Of these, 40 are critical severity, 260 are high severity, and 445 are medium severity.
How can I protect against CWE-312 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-312 using AI-powered security agents.
Detect CWE-312 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-312 vulnerabilities across your infrastructure.
Get Started