VYPR

CWE-256

Plaintext Storage of a Password

BaseIncompleteLikelihood: High

Description

The product stores a password in plaintext within resources such as memory or files.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (279)

page 10 of 14
  • CVE-2025-15128MedDec 28, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was detected in ZKTeco BioTime up to 9.0.3/9.0.4/9.5.2. This affects an unknown part of the file /base/safe_setting/ of the component Endpoint. Performing a manipulation of the argument backup_encryption_password_decrypt/export_encryption_password_decrypt results…

  • CVE-2025-13221MedNov 15, 2025
    risk 0.34cvss 5.3epss 0.00

    A weakness has been identified in Intelbras UnniTI 24.07.11. The affected element is an unknown function of the file /xml/sistema/usuarios.xml. Executing manipulation of the argument Usuario/Senha can lead to unprotected storage of credentials. The attack can be executed…

  • CVE-2025-13187MedNov 14, 2025
    risk 0.34cvss 5.3epss 0.01

    A security vulnerability has been detected in Intelbras ICIP 2.0.20. Affected is an unknown function of the file /xml/sistema/acessodeusuario.xml. Such manipulation of the argument NomeUsuario/SenhaAcess leads to unprotected storage of credentials. The attack may be launched…

  • CVE-2025-53677MedJul 9, 2025
    risk 0.34cvss 5.3epss 0.00

    Jenkins Xooa Plugin 0.0.7 and earlier does not mask the Xooa Deployment Token on the global configuration form, increasing the potential for attackers to observe and capture it.

  • CVE-2025-53674MedJul 9, 2025
    risk 0.34cvss 5.3epss 0.00

    Jenkins Sensedia Api Platform tools Plugin 1.0 does not mask the Sensedia API Manager integration token on the global configuration form, increasing the potential for attackers to observe and capture it.

  • CVE-2025-53655MedJul 9, 2025
    risk 0.34cvss 5.3epss 0.00

    Jenkins Statistics Gatherer Plugin 2.0.3 and earlier does not mask the AWS Secret Key on the global configuration form, increasing the potential for attackers to observe and capture it.

  • CVE-2025-48046MedMay 29, 2025
    risk 0.34cvss epss 0.00

    An authenticated user can disclose the cleartext password of a configured SMTP server via an HTTP GET request to the /config.php endpoint.

  • CVE-2024-43186MedMar 29, 2025
    risk 0.34cvss 5.3epss 0.00

    IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information that is stored locally under certain conditions.

  • CVE-2022-43426MedOct 19, 2022
    risk 0.34cvss 5.3epss 0.01

    Jenkins S3 Explorer Plugin 1.0.8 and earlier does not mask the AWS_SECRET_ACCESS_KEY form field, increasing the potential for attackers to observe and capture it.

  • CVE-2018-7515MedMar 21, 2018
    risk 0.34cvss 5.3epss 0.00

    In Omron CX-Supervisor Versions 3.30 and prior, access of uninitialized pointer vulnerabilities can be exploited when CX Supervisor indirectly calls an initialized pointer when parsing malformed packets.

  • CVE-2025-43938MedSep 10, 2025
    risk 0.33cvss 5.0epss 0.00

    Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) a Plaintext Storage of a Password vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The…

  • CVE-2023-31002MedFeb 7, 2024
    risk 0.33cvss 5.1epss 0.00

    IBM Security Access Manager Container 10.0.0.0 through 10.0.6.1 temporarily stores sensitive information in files that could be accessed by a local user. IBM X-Force ID: 254657.

  • CVE-2026-31850MedMar 23, 2026
    risk 0.32cvss 4.9epss 0.00

    Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 stores sensitive information, including administrative credentials and WiFi pre-shared keys, in plaintext within exported configuration backup files. These backup files can be obtained through legitimate…

  • CVE-2026-23797MedFeb 5, 2026
    risk 0.32cvss 4.9epss 0.00

    In Quick.Cart user passwords are stored in plaintext form. An attacker with high privileges can display users' password in user editing page. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version…

  • CVE-2025-12680MedFeb 2, 2026
    risk 0.32cvss 4.9epss 0.00

    Brocade SANnav before Brocade SANnav 2.4.0b logs database passwords in clear text in the standby SANnav server, after disaster recovery failover. The vulnerability could allow a remote authenticated attacker with admin privilege able to access the SANnav logs or the supportsave…

  • CVE-2024-49370MedOct 23, 2024
    risk 0.32cvss 4.9epss 0.01

    Pimcore is an open source data and experience management platform. When a PortalUserObject is connected to a PimcoreUser and "Use Pimcore Backend Password" is set to true, the change password function in Portal Profile sets the new password. Prior to Pimcore portal engine…

  • CVE-2022-27548MedJul 6, 2022
    risk 0.32cvss 4.9epss 0.00

    HCL Launch stores user credentials in plain clear text which can be read by a local user.

  • CVE-2020-26079MedNov 18, 2020
    risk 0.32cvss 4.9epss 0.01

    A vulnerability in the web UI of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to obtain hashes of user passwords on an affected device. The vulnerability is due to insufficient protection of user credentials. An attacker could exploit this…

  • CVE-2026-6500MedMay 4, 2026
    risk 0.31cvss epss 0.00

    Plaintext storage of a password vulnerability in ILM Informatique OpenConcerto allows Retrieve Embedded Sensitive Data. This issue affects OpenConcerto: 1.7.5.

  • CVE-2024-6833MedJul 17, 2024
    risk 0.31cvss 5.9epss 0.00

    A vulnerability in Zowe CLI allows local, privileged actors to store previously entered secure credentials in a plaintext file as part of an auto-init operation.