Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-312

Cleartext Storage of Sensitive Information

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

814
Assigned CVEs
52nd
Commonality Rank
6.4
Avg CVSS
0.1%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-312 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2001
24 years ago
Most Recent CVE
Jul 23, 2026
1 day ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

814 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-50719HIGH
XWiki Platform is a generic wiki platform. Starting in 7.2-milestone-2 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the Solr-based search in XWiki discloses the password
Dec 15, 20237.575NOYES
CVE-2022-26148CRITICAL
An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source code. When the user logs in and a
Mar 21, 20229.873NOYES
CVE-2011-4723MEDIUM
The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information via unspecified vectors.
Dec 20, 20115.758YESNO
CVE-2019-0285CRITICAL
The .NET SDK WebForm Viewer in SAP Crystal Reports for Visual Studio (fixed in version 2010) discloses sensitive database information including credentials which can be misused by
Apr 10, 20199.845NOYES
CVE-2021-36782CRITICAL
A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Members, Project Owners, Project Members and User Base to us
Sep 7, 20229.943NOYES
CVE-2026-43824CRITICAL
In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data.
May 2, 20269.642NONO
CVE-2020-27986HIGH
SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. NOTE: reportedly, the vendor's position for S
Oct 28, 20207.542NOYES
CVE-2018-8947HIGH
rap2hpoutre Laravel Log Viewer before v0.13.0 relies on Base64 encoding for l, dl, and del requests, which makes it easier for remote attackers to bypass intended access restrictio
Mar 25, 20187.540NOYES
CVE-2023-31069CRITICAL
An issue was discovered in TSplus Remote Access through 16.0.2.14. Credentials are stored as cleartext within the HTML source code of the login page.
Sep 11, 20239.838NOYES
CVE-2020-5723CRITICAL
The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. This could allow an attacker to retrieve all passwords and possibly gain elevated pr
Mar 30, 20209.838NOYES
View all 814 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
15%
10%
4.0-4.9
22%
19%
5.0-5.9
18%
16%
6.0-6.9
30%
26%
7.0-7.9
11%
8.0-8.9
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
1 CVE
0.1% of CVEs· 80th percentile
Metasploit
3 CVEs
0.4% of CVEs· 82nd percentile
Nuclei
7 CVEs
0.9% of CVEs· 84th percentile
ExploitDB
9 CVEs
1.1% of CVEs· 83rd percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products