VYPR

CWE-312

Cleartext Storage of Sensitive Information

BaseDraft

Description

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (848)

page 41 of 43
  • CVE-2025-14836LowDec 17, 2025
    risk 0.18cvss 2.7epss 0.00

    A flaw has been found in ZZCMS 2025. Affected by this vulnerability is an unknown functionality of the file /reg/user_save.php of the component User Data Storage Module. This manipulation causes cleartext storage in a file or on disk. Remote exploitation of the attack is…

  • CVE-2024-4235LowApr 26, 2024
    risk 0.18cvss 2.7epss 0.01

    A vulnerability classified as problematic was found in Netgear DG834Gv5 1.6.01.34. This vulnerability affects unknown code of the component Web Management Interface. The manipulation leads to cleartext storage of sensitive information. The attack can be initiated remotely. The…

  • CVE-2021-40087LowAug 25, 2021
    risk 0.18cvss 2.7epss 0.00

    An issue was discovered in PrimeKey EJBCA before 7.6.0. When audit logging changes to the alias configurations of various protocols that use an enrollment secret, any modifications to the secret were logged in cleartext in the audit log (that can only be viewed by an…

  • CVE-2020-36248LowFeb 19, 2021
    risk 0.18cvss 3.9epss 0.00

    The ownCloud application before 2.15 for Android allows attackers to use adb to include a PIN preferences value in a backup archive, and consequently bypass the PIN lock feature by restoring from this archive.

  • CVE-2023-41335LowSep 27, 2023
    risk 0.17cvss 3.7epss 0.00

    Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. When users update their passwords, the new credentials may be briefly held in the server database. While this doesn't grant the server any added capabilities—it already learns the…

  • CVE-2025-23291LowSep 30, 2025
    risk 0.16cvss 2.4epss 0.00

    NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an User/Attacker may cause an authorized action. A successful exploit of this vulnerability may lead to information disclosure.

  • CVE-2024-46383LowNov 15, 2024
    risk 0.16cvss 2.4epss 0.00

    Hathway Skyworth Router CM5100-511 v4.1.1.24 was discovered to store sensitive information about USB and Wifi connected devices in plaintext.

  • CVE-2024-39846LowJun 29, 2024
    risk 0.16cvss 3.5epss 0.00

    NewPass before 1.2.0 stores passwords (rather than password hashes) directly, which makes it easier to obtain unauthorized access to sensitive information. NOTE: in each case, data at rest is encrypted, but is decrypted within process memory during use.

  • CVE-2025-5154LowMay 25, 2025
    risk 0.15cvss 2.3epss 0.00

    A vulnerability, which was classified as problematic, was found in PhonePe App 25.03.21.0 on Android. Affected is an unknown function of the file /data/data/com.phonepe.app/databases/ of the component SQLite Database. The manipulation leads to cleartext storage in a file or on…

  • CVE-2024-9040LowSep 20, 2024
    risk 0.15cvss 2.3epss 0.00

    A vulnerability, which was classified as problematic, was found in code-projects Blood Bank Management System 1.0. This affects an unknown part of the component Password Handler. The manipulation leads to cleartext storage in a file or on disk. An attack has to be approached…

  • CVE-2024-40594LowJul 6, 2024
    risk 0.15cvss 2.3epss 0.00

    The OpenAI ChatGPT app before 2024-07-05 for macOS opts out of the sandbox, and stores conversations in cleartext in a location accessible to other apps.

  • CVE-2023-2863LowMay 24, 2023
    risk 0.15cvss 2.3epss 0.00

    A vulnerability has been found in Simple Design Daily Journal 1.012.GP.B on Android and classified as problematic. Affected by this vulnerability is an unknown functionality of the component SQLite Database. The manipulation leads to cleartext storage in a file or on disk. It is…

  • CVE-2026-18591LowAug 3, 2026
    risk 0.14cvss 2.1epss 0.00

    A vulnerability was identified in Meesho Online Shopping App up to 20260607 on Android. Affected by this vulnerability is an unknown functionality of the component com.meesho.supply. Such manipulation of the argument user_id/phone number/email address/name leads to cleartext…

  • CVE-2025-6748LowJun 27, 2025
    risk 0.14cvss 2.1epss 0.00

    A vulnerability classified as problematic has been found in Bharti Airtel Thanks App 4.105.4 on Android. Affected is an unknown function of the file /Android/data/com.myairtelapp/files/. The manipulation leads to cleartext storage in a file or on disk. It is possible to launch…

  • CVE-2025-2120LowMar 9, 2025
    risk 0.14cvss 2.1epss 0.00

    A vulnerability was found in Thinkware Car Dashcam F800 Pro up to 20250226. It has been rated as problematic. This issue affects some unknown processing of the file /tmp/hostapd.conf of the component Configuration File Handler. The manipulation leads to cleartext storage in a…

  • CVE-2019-10433LowOct 1, 2019
    risk 0.14cvss 3.3epss 0.00

    Jenkins Dingding[钉钉] Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.

  • CVE-2026-4387LowMay 29, 2026
    risk 0.13cvss epss 0.00

    StrongDM Desktop Application before 23.74.0 (Desktop Client before 53.77.0) on Microsoft Windows stores authentication state, including a JSON Web Token and asymmetric key material, in cleartext in a per-user state file located at C:\Users\\.sdm\state.kv. The file is…

  • CVE-2025-47824LowJun 27, 2025
    risk 0.13cvss 2.0epss 0.00

    Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have cleartext storage of code.

  • CVE-2025-47820LowJun 27, 2025
    risk 0.13cvss 2.0epss 0.00

    Flock Safety Gunshot Detection devices before 1.3 have cleartext storage of code.

  • CVE-2025-2922LowMar 28, 2025
    risk 0.13cvss 2.0epss 0.00

    A vulnerability classified as problematic was found in Netis WF-2404 1.1.124EN. Affected by this vulnerability is an unknown functionality of the component BusyBox Shell. The manipulation leads to cleartext storage of sensitive information. It is possible to launch the attack on…