VYPR

CWE-256

Plaintext Storage of a Password

BaseIncompleteLikelihood: High

Description

The product stores a password in plaintext within resources such as memory or files.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (286)

page 5 of 15
  • CVE-2025-65009HigDec 18, 2025
    risk 0.46cvss —epss 0.00

    In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) admin password is stored in configuration file as plaintext and can be obtained by unauthorized user by direct references to the resource in question. The vendor was notified early about this vulnerability, but…

  • CVE-2024-28736HigMay 31, 2024
    risk 0.46cvss 7.1epss 0.03

    An issue in Debezium Community debezium-ui v.2.5 allows a local attacker to execute arbitrary code via the refresh page function.

  • CVE-2023-42493HigOct 25, 2023
    risk 0.46cvss 7.1epss 0.00

    EisBaer Scada - CWE-256: Plaintext Storage of a Password

  • CVE-2021-36309HigOct 1, 2021
    risk 0.46cvss 7.1epss 0.01

    Dell Enterprise SONiC OS, versions 3.3.0 and earlier, contains a sensitive information disclosure vulnerability. An authenticated malicious user with access to the system may use the TACACS\Radius credentials stored to read sensitive information and use it in further attacks.

  • CVE-2020-3483HigOct 14, 2020
    risk 0.46cvss 7.1epss 0.00

    Duo has identified and fixed an issue with the Duo Network Gateway (DNG) product in which some customer-provided SSL certificates and private keys were not excluded from logging. This issue resulted in certificate and private key information being written out in plain-text to…

  • CVE-2026-15933MedSep 3, 2026
    risk 0.45cvss —epss 0.00

    OptimiDoc Server (On-Premise) stores credentials for external services in cleartext. An authenticated administrator can view previously configured service passwords, including SMTP, FTP (for scan delivery), Active Directory (for user list import), and SharePoint credentials, in…

  • CVE-2025-46366MedNov 5, 2025
    risk 0.44cvss 6.7epss 0.00

    Dell CloudLink, versions prior to 8.1.1, contain a vulnerability where a privileged user may exploit and gain parallel privilege escalation or access to the database to obtain confidential information.

  • CVE-2024-43378HigAug 16, 2024
    risk 0.44cvss 7.8epss 0.00

    calamares-nixos-extensions provides Calamares branding and modules for NixOS, a distribution of GNU/Linux. Users who installed NixOS through the graphical installer who used manual disk partitioning to create a setup where the system was booted via legacy BIOS rather than UEFI;…

  • CVE-2021-36317MedDec 21, 2021
    risk 0.44cvss 6.7epss 0.00

    Dell EMC Avamar Server version 19.4 contains a plain-text password storage vulnerability in AvInstaller. A local attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials…

  • CVE-2025-61680MedOct 3, 2025
    risk 0.43cvss —epss 0.00

    Minecraft RCON Terminal is a VS Code extension that streamlines Minecraft server management. Versions 0.1.0 through 2.0.6 stores passwords using VS Code's configuration API which writes to settings.json in plaintext. This issue is fixed in version 2.1.0.

  • CVE-2026-61886MedJul 24, 2026
    risk 0.42cvss 6.5epss 0.00

    Weintek cMT3092X HMI stores user account passwords in plaintext.

  • CVE-2026-42151HigMay 4, 2026
    risk 0.42cvss 7.5epss 0.00

    Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of Secret. Prometheus redacts fields of type…

  • CVE-2020-37115MedFeb 3, 2026
    risk 0.42cvss 6.5epss 0.00

    GUnet OpenEclass 1.7.3 stores user credentials in plaintext, allowing administrators to view all registered users' usernames and passwords without encryption. This vulnerability exposes sensitive information and increases the risk of credential theft and unauthorized access.

  • CVE-2025-45702MedJul 24, 2025
    risk 0.42cvss 6.5epss 0.00

    SoftPerfect Pty Ltd Connection Quality Monitor v1.1 was discovered to store all credentials in plaintext.

  • CVE-2025-53675MedJul 9, 2025
    risk 0.42cvss 6.5epss 0.00

    Jenkins Warrior Framework Plugin 1.2 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.

  • CVE-2025-53671MedJul 9, 2025
    risk 0.42cvss 6.5epss 0.00

    Jenkins Nouvola DiveCloud Plugin 1.08 and earlier does not mask DiveCloud API Keys and Credentials Encryption Keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

  • CVE-2025-53664MedJul 9, 2025
    risk 0.42cvss 6.5epss 0.00

    Jenkins Apica Loadtest Plugin 1.10 and earlier stores Apica Loadtest LTP authentication tokens unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.

  • CVE-2025-53662MedJul 9, 2025
    risk 0.42cvss 6.5epss 0.00

    Jenkins IFTTT Build Notifier Plugin 1.2 and earlier stores IFTTT Maker Channel Keys unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.

  • CVE-2025-53656MedJul 9, 2025
    risk 0.42cvss 6.5epss 0.00

    Jenkins ReadyAPI Functional Testing Plugin 1.11 and earlier stores SLM License Access Keys, client secrets, and passwords unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins…

  • CVE-2025-1709MedJul 3, 2025
    risk 0.42cvss 6.5epss 0.00

    Several credentials for the local PostgreSQL database are stored in plain text (partially base64 encoded).