The product stores sensitive information in cleartext within the GUI.
Volume of CVEs assigned to CWE-317 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-14816CRITICAL Cleartext Storage of Sensitive Information in GUI vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.3 and | Apr 8, 2026 | 9.3 | 31 | NO | NO |
CVE-2026-27516HIGH Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior expose user passwords in plaintext within the administrative interface and HTTP responses, allowing | Feb 24, 2026 | 7.5 | 26 | NO | NO |
CVE-2022-29090MEDIUM Dell Wyse Management Suite 3.6.1 and below contains a Sensitive Data Exposure vulnerability. A low privileged malicious user could potentially exploit this vulnerability in order t | Aug 10, 2022 | 6.5 | 22 | NO | NO |
CVE-2026-24431MEDIUM Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) display stored user account passwords in plaintext within the administrative web interface. Any user | Jan 26, 2026 | 6.5 | 20 | NO | NO |
CVE-2022-0354HIGH A vulnerability was reported in Lenovo System Update that could allow a local user with interactive system access the ability to execute code with elevated privileges only during t | Apr 22, 2022 | 7.8 | 19 | NO | NO |
CVE-2019-13947MEDIUM A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The user configuration menu in the web interface of the
Control Center Server (CCS) tran | Dec 12, 2019 | 4.9 | 17 | NO | NO |
CVE-2021-34751MEDIUM A vulnerability in the administrative web-based GUI configuration manager of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to acces | Nov 15, 2024 | 4.3 | 16 | NO | NO |
CVE-2021-34750MEDIUM A vulnerability in the administrative web-based GUI configuration manager of Cisco Firepower Management Center Software could allow an authenticated, remote attacker to access sens | Nov 15, 2024 | 4.3 | 16 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.