The product stores a password in plaintext within resources such as memory or files.
Volume of CVEs assigned to CWE-256 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
213 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-42151HIGH Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuratio | May 4, 2026 | 7.5 | 36 | NO | NO |
CVE-2026-33216HIGH NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, for MQTT deployments using usercodes/passwords | Mar 25, 2026 | 7.5 | 34 | NO | NO |
CVE-2026-40430HIGH Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a plaintext storage of a password vulnerability that could expose cleartext credentials through the API. | Jul 23, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-46513HIGH Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, Frogman stored API tokens generated by Tools/CreateApiToken.php:33-36 as raw bin2hex(random_bytes(32 | Jul 16, 2026 | 7.4 | 33 | NO | NO |
CVE-2026-21660CRITICAL Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to una | Feb 27, 2026 | 9.8 | 32 | NO | NO |
CVE-2024-55026CRITICAL An issue in the reset_pj.cgi endpoint of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to execute arbitrary commands via supplying a crafted GET r | Mar 3, 2026 | 9.8 | 31 | NO | NO |
CVE-2018-7510CRITICAL In the web application in BeaconMedaes TotalAlert Scroll Medical Air Systems running software versions prior to 4107600010.23, passwords are presented in plaintext in a file that i | Jun 6, 2018 | 9.8 | 31 | NO | NO |
CVE-2026-61886MEDIUM Weintek cMT3092X HMI stores user account passwords in plaintext. | Jul 24, 2026 | 6.5 | 30 | NO | NO |
CVE-2025-15113CRITICAL Ksenia Security lares (legacy model) Home Automation version 1.6 contains an unprotected endpoint vulnerability that allows authenticated attackers to upload MPFS File System binar | Dec 30, 2025 | 9.3 | 30 | NO | NO |
CVE-2023-26204CRITICAL A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions, 6 | Jun 13, 2023 | 9.8 | 30 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.