CWE-256
Plaintext Storage of a Password
Description
The product stores a password in plaintext within resources such as memory or files.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (286)
page 15 of 15| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-14867 | Med | 0.00 | 5.5 | 0.00 | Jul 7, 2026 | Credentials of built-in users are insecurely stored in the User directory of PcVue projects, all versions prior to 17.0.0. A local attacker could retrieve users’ credentials. Active Directory accounts are not affected by this vulnerability. | ||
| CVE-2025-56527 | Hig | 0.00 | 7.5 | 0.00 | Nov 18, 2025 | Plaintext password storage in Kotaemon 0.11.0 in the client's localStorage. | ||
| CVE-2022-0555 | Hig | 0.00 | 8.4 | 0.00 | Jun 3, 2024 | Subiquity Shows Guided Storage Passphrase in Plaintext with Read-all Permissions | ||
| CVE-2024-26133 | Med | 0.00 | 5.5 | 0.01 | Feb 21, 2024 | EventStoreDB (ESDB) is an operational database built to store events. A vulnerability has been identified in the projections subsystem in versions 20 prior to 20.10.6, 21 prior to 21.10.11, 22 prior to 22.10.5, and 23 prior to 23.10.1. Only database instances that use custom… | ||
| CVE-2022-45392 | Med | 0.00 | 6.5 | 0.01 | Nov 15, 2022 | Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by attackers with Extended Read permission, or access to the Jenkins controller file system. | ||
| CVE-2022-3287 | Med | 0.00 | 6.5 | 0.01 | Sep 28, 2022 | When creating an OPERATOR user account on the BMC, the redfish plugin saved the auto-generated password to /etc/fwupd/redfish.conf without proper restriction, allowing any user on the system to read the same configuration file. |
- risk 0.00cvss 5.5epss 0.00
Credentials of built-in users are insecurely stored in the User directory of PcVue projects, all versions prior to 17.0.0. A local attacker could retrieve users’ credentials. Active Directory accounts are not affected by this vulnerability.
- risk 0.00cvss 7.5epss 0.00
Plaintext password storage in Kotaemon 0.11.0 in the client's localStorage.
- risk 0.00cvss 8.4epss 0.00
Subiquity Shows Guided Storage Passphrase in Plaintext with Read-all Permissions
- risk 0.00cvss 5.5epss 0.01
EventStoreDB (ESDB) is an operational database built to store events. A vulnerability has been identified in the projections subsystem in versions 20 prior to 20.10.6, 21 prior to 21.10.11, 22 prior to 22.10.5, and 23 prior to 23.10.1. Only database instances that use custom…
- risk 0.00cvss 6.5epss 0.01
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by attackers with Extended Read permission, or access to the Jenkins controller file system.
- risk 0.00cvss 6.5epss 0.01
When creating an OPERATOR user account on the BMC, the redfish plugin saved the auto-generated password to /etc/fwupd/redfish.conf without proper restriction, allowing any user on the system to read the same configuration file.