VYPR

CWE-256

Plaintext Storage of a Password

BaseIncompleteLikelihood: High

Description

The product stores a password in plaintext within resources such as memory or files.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (286)

page 10 of 15
  • CVE-2024-4425MedMay 14, 2024
    risk 0.35cvss 5.4epss 0.00

    The access control in CemiPark software stores integration (e.g. FTP or SIP) credentials in plain-text. An attacker who gained unauthorized access to the device can retrieve clear text passwords used by the system.This issue affects CemiPark software: 4.5, 4.7, 5.03 and…

  • CVE-2022-43419MedOct 19, 2022
    risk 0.35cvss 6.5epss 0.01

    Jenkins Katalon Plugin 1.0.32 and earlier stores API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.

  • CVE-2022-36901MedJul 27, 2022
    risk 0.35cvss 6.5epss 0.01

    Jenkins HTTP Request Plugin 1.15 and earlier stores HTTP Request passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

  • CVE-2020-2132MedFeb 12, 2020
    risk 0.35cvss 6.5epss 0.01

    Jenkins Parasoft Environment Manager Plugin 2.14 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.

  • CVE-2020-2119MedFeb 12, 2020
    risk 0.35cvss 5.3epss 0.01

    Jenkins Azure AD Plugin 1.1.2 and earlier transmits configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.

  • CVE-2025-36425MedFeb 17, 2026
    risk 0.34cvss 5.3epss 0.00

    IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 could allow an authenticated user to obtain sensitive information under specific HADR configuration.

  • CVE-2025-15128MedDec 28, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was detected in ZKTeco BioTime up to 9.0.3/9.0.4/9.5.2. This affects an unknown part of the file /base/safe_setting/ of the component Endpoint. Performing a manipulation of the argument backup_encryption_password_decrypt/export_encryption_password_decrypt results…

  • CVE-2025-13221MedNov 15, 2025
    risk 0.34cvss 5.3epss 0.00

    A weakness has been identified in Intelbras UnniTI 24.07.11. The affected element is an unknown function of the file /xml/sistema/usuarios.xml. Executing manipulation of the argument Usuario/Senha can lead to unprotected storage of credentials. The attack can be executed…

  • CVE-2025-13187MedNov 14, 2025
    risk 0.34cvss 5.3epss 0.01

    A security vulnerability has been detected in Intelbras ICIP 2.0.20. Affected is an unknown function of the file /xml/sistema/acessodeusuario.xml. Such manipulation of the argument NomeUsuario/SenhaAcess leads to unprotected storage of credentials. The attack may be launched…

  • CVE-2025-53677MedJul 9, 2025
    risk 0.34cvss 5.3epss 0.00

    Jenkins Xooa Plugin 0.0.7 and earlier does not mask the Xooa Deployment Token on the global configuration form, increasing the potential for attackers to observe and capture it.

  • CVE-2025-53674MedJul 9, 2025
    risk 0.34cvss 5.3epss 0.00

    Jenkins Sensedia Api Platform tools Plugin 1.0 does not mask the Sensedia API Manager integration token on the global configuration form, increasing the potential for attackers to observe and capture it.

  • CVE-2025-53655MedJul 9, 2025
    risk 0.34cvss 5.3epss 0.00

    Jenkins Statistics Gatherer Plugin 2.0.3 and earlier does not mask the AWS Secret Key on the global configuration form, increasing the potential for attackers to observe and capture it.

  • CVE-2025-48046MedMay 29, 2025
    risk 0.34cvss —epss 0.01

    An authenticated user can disclose the cleartext password of a configured SMTP server via an HTTP GET request to the /config.php endpoint.

  • CVE-2024-43186MedMar 29, 2025
    risk 0.34cvss 5.3epss 0.00

    IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information that is stored locally under certain conditions.

  • CVE-2022-43426MedOct 19, 2022
    risk 0.34cvss 5.3epss 0.01

    Jenkins S3 Explorer Plugin 1.0.8 and earlier does not mask the AWS_SECRET_ACCESS_KEY form field, increasing the potential for attackers to observe and capture it.

  • CVE-2018-7515MedMar 21, 2018
    risk 0.34cvss 5.3epss 0.00

    In Omron CX-Supervisor Versions 3.30 and prior, access of uninitialized pointer vulnerabilities can be exploited when CX Supervisor indirectly calls an initialized pointer when parsing malformed packets.

  • CVE-2025-43938MedSep 10, 2025
    risk 0.33cvss 5.0epss 0.00

    Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) a Plaintext Storage of a Password vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The…

  • CVE-2023-31002MedFeb 7, 2024
    risk 0.33cvss 5.1epss 0.00

    IBM Security Access Manager Container 10.0.0.0 through 10.0.6.1 temporarily stores sensitive information in files that could be accessed by a local user. IBM X-Force ID: 254657.

  • CVE-2026-31850MedMar 23, 2026
    risk 0.32cvss 4.9epss 0.00

    Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 stores sensitive information, including administrative credentials and WiFi pre-shared keys, in plaintext within exported configuration backup files. These backup files can be obtained through legitimate…

  • CVE-2026-23797MedFeb 5, 2026
    risk 0.32cvss 4.9epss 0.00

    In Quick.Cart user passwords are stored in plaintext form. An attacker with high privileges can display users' password in user editing page. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version…