The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Volume of CVEs assigned to CWE-312 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
814 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-50719HIGH XWiki Platform is a generic wiki platform. Starting in 7.2-milestone-2 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the Solr-based search in XWiki discloses the password | Dec 15, 2023 | 7.5 | 75 | NO | YES |
CVE-2022-26148CRITICAL An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source code. When the user logs in and a | Mar 21, 2022 | 9.8 | 73 | NO | YES |
CVE-2011-4723MEDIUM The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information via unspecified vectors. | Dec 20, 2011 | 5.7 | 58 | YES | NO |
CVE-2019-0285CRITICAL The .NET SDK WebForm Viewer in SAP Crystal Reports for Visual Studio (fixed in version 2010) discloses sensitive database information including credentials which can be misused by | Apr 10, 2019 | 9.8 | 45 | NO | YES |
CVE-2021-36782CRITICAL A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Members, Project Owners, Project Members and User Base to us | Sep 7, 2022 | 9.9 | 43 | NO | YES |
CVE-2026-43824CRITICAL In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data. | May 2, 2026 | 9.6 | 42 | NO | NO |
CVE-2020-27986HIGH SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. NOTE: reportedly, the vendor's position for S | Oct 28, 2020 | 7.5 | 42 | NO | YES |
CVE-2018-8947HIGH rap2hpoutre Laravel Log Viewer before v0.13.0 relies on Base64 encoding for l, dl, and del requests, which makes it easier for remote attackers to bypass intended access restrictio | Mar 25, 2018 | 7.5 | 40 | NO | YES |
CVE-2023-31069CRITICAL An issue was discovered in TSplus Remote Access through 16.0.2.14. Credentials are stored as cleartext within the HTML source code of the login page. | Sep 11, 2023 | 9.8 | 38 | NO | YES |
CVE-2020-5723CRITICAL The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. This could allow an attacker to retrieve all passwords and possibly gain elevated pr | Mar 30, 2020 | 9.8 | 38 | NO | YES |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.