VYPR

CWE-256

Plaintext Storage of a Password

BaseIncompleteLikelihood: High

Description

The product stores a password in plaintext within resources such as memory or files.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (286)

page 13 of 15
  • CVE-2026-28360MedMar 2, 2026
    risk 0.27cvss 5.3epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, shared view passwords were stored in plaintext in the database and compared using direct string equality. This issue has been patched in version 0.301.3.

  • CVE-2024-45638MedMar 14, 2025
    risk 0.27cvss 4.1epss 0.00

    IBM Security QRadar 3.12 EDR stores user credentials in plain text which can be read by a local privileged user.

  • CVE-2024-3082MedJul 31, 2024
    risk 0.27cvss 4.2epss 0.00

    A “CWE-256: Plaintext Storage of a Password” affecting the administrative account allows an attacker with physical access to the machine to retrieve the password in cleartext unless specific security measures at other layers (e.g., full-disk encryption) have been enabled.

  • CVE-2024-4232MedMay 14, 2024
    risk 0.27cvss 4.1epss 0.00

    This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to lack of encryption or hashing in storing of passwords within the router's firmware/ database. An attacker with physical access could exploit this by extracting the…

  • CVE-2025-24375MedApr 9, 2025
    risk 0.26cvss 5.0epss 0.00

    Charmed MySQL K8s operator is a Charmed Operator for running MySQL on Kubernetes. Before revision 221, the method for calling a SQL DDL or python based mysql-shell scripts can leak database users credentials. The method mysql-operator calls mysql-shell application rely on…

  • CVE-2021-25358MedApr 9, 2021
    risk 0.26cvss 4.0epss 0.00

    A vulnerability that stores IMSI values in an improper path prior to SMR APR-2021 Release 1 allows local attackers to access IMSI values without any permission via untrusted applications.

  • CVE-2026-55164MedAug 18, 2026
    risk 0.25cvss 4.9epss 0.00

    Lemur manages TLS certificate creation. Prior to 1.9.2, lemur.users.service.update assigned a replacement password directly to users.password, while lemur/users/models.py registered User.hash_password only for the before_insert event. Because no before_update listener ran,…

  • CVE-2025-5760MedJun 6, 2025
    risk 0.25cvss 4.9epss 0.00

    The Simple History plugin for WordPress is vulnerable to sensitive data exposure via Detective Mode due to improper sanitization within the append_debug_info_to_context() function in versions prior to 5.8.1. When Detective Mode is enabled, the plugin’s logger captures the…

  • CVE-2023-26204LowJun 13, 2023
    risk 0.24cvss 3.7epss 0.00

    A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions, 6.1 all versions, 5.4 all versions, 5.3 all versions may allow an attacker able to access user DB…

  • CVE-2024-28971LowMay 8, 2024
    risk 0.23cvss 3.5epss 0.00

    Dell Update Manager Plugin, versions 1.4.0 through 1.5.0, contains a Plain-text Password Storage Vulnerability in Log file. A remote high privileged attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be…

  • CVE-2017-9856LowAug 5, 2017
    risk 0.22cvss 3.4epss 0.01

    An issue was discovered in SMA Solar Technology products. Sniffed passwords from SMAdata2+ communication can be decrypted very easily. The passwords are "encrypted" using a very simple encryption algorithm. This enables an attacker to find the plaintext passwords and…

  • CVE-2026-44187LowJul 22, 2026
    risk 0.21cvss 3.3epss 0.00

    A flaw was found in the Ansible Lightspeed extension for Visual Studio Code. This vulnerability allows an attacker with local access to the workstation, or malware running with the user's privileges, to read the Google Gemini API key. The extension insecurely stores the API key…

  • CVE-2025-31724MedApr 2, 2025
    risk 0.21cvss 4.3epss 0.00

    Jenkins Cadence vManager Plugin 4.0.0-282.v5096a_c2db_275 and earlier stores Verisium Manager vAPI keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.

  • CVE-2025-2355LowMar 17, 2025
    risk 0.21cvss 3.3epss 0.00

    A vulnerability was found in BlackVue App 3.65 on Android and classified as problematic. Affected by this issue is some unknown functionality of the component API Endpoint Handler. The manipulation of the argument BCS_TOKEN/SECRET_KEY leads to unprotected storage of credentials.…

  • CVE-2024-37135LowJul 31, 2024
    risk 0.21cvss 3.3epss 0.00

    DM5500 5.16.0.0, contains an information disclosure vulnerability. A local attacker with high privileges could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the…

  • CVE-2023-2633MedMay 16, 2023
    risk 0.21cvss 4.3epss 0.00

    Jenkins Code Dx Plugin 3.1.0 and earlier does not mask Code Dx server API keys displayed on the configuration form, increasing the potential for attackers to observe and capture them.

  • CVE-2023-2632MedMay 16, 2023
    risk 0.21cvss 4.3epss 0.01

    Jenkins Code Dx Plugin 3.1.0 and earlier stores Code Dx server API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.

  • CVE-2020-2249LowSep 1, 2020
    risk 0.21cvss 3.3epss 0.00

    Jenkins Team Foundation Server Plugin 5.157.1 and earlier stores a webhook secret unencrypted in its global configuration file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system.

  • CVE-2020-2239MedSep 1, 2020
    risk 0.21cvss 4.3epss 0.01

    Jenkins Parameterized Remote Trigger Plugin 3.1.3 and earlier stores a secret unencrypted in its global configuration file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system.

  • CVE-2020-2218LowJul 2, 2020
    risk 0.21cvss 3.3epss 0.00

    Jenkins HP ALM Quality Center Plugin 1.6 and earlier stores a password unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to the master file system.