Vulnerabilities > Cleartext Storage of Sensitive Information

DATE CVE VULNERABILITY TITLE RISK
2024-12-11 CVE-2024-35117 IBM OpenPages with Watson 9.0 may write sensitive information, under specific configurations, in clear text to the system tracing log files that could be obtained by a privileged user.
network
high complexity
CWE-312
4.4
2024-11-04 CVE-2024-10523 Cleartext Storage of Sensitive Information vulnerability in Tp-Link Tapo H100 Firmware
This vulnerability exists in TP-Link IoT Smart Hub due to storage of Wi-Fi credentials in plain text within the device firmware.
low complexity
tp-link CWE-312
4.6
2024-10-29 CVE-2024-7783 Cleartext Storage of Sensitive Information vulnerability in Mintplexlabs Anythingllm 0.0.1/0.1.0
mintplex-labs/anything-llm version latest contains a vulnerability where sensitive information, specifically a password, is improperly stored within a JWT (JSON Web Token) used as a bearer token in single user mode.
network
low complexity
mintplexlabs CWE-312
7.5
2024-10-10 CVE-2024-9798 Cleartext Storage of Sensitive Information vulnerability in Linuxfoundation Zowe API Mediation Layer
The health endpoint is public so everybody can see a list of all services.
network
low complexity
linuxfoundation CWE-312
5.3
2024-10-10 CVE-2024-9802 Cleartext Storage of Sensitive Information vulnerability in Linuxfoundation Zowe API Mediation Layer
The conformance validation endpoint is public so everybody can verify the conformance of onboarded services.
network
low complexity
linuxfoundation CWE-312
5.3
2024-10-09 CVE-2024-9466 Cleartext Storage of Sensitive Information vulnerability in Paloaltonetworks Expedition
A cleartext storage of sensitive information vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to reveal firewall usernames, passwords, and API keys generated using those credentials.
network
low complexity
paloaltonetworks CWE-312
6.5
2024-10-04 CVE-2024-6400 Cleartext Storage of Sensitive Information vulnerability in Finrota
Cleartext Storage of Sensitive Information vulnerability in Finrota Netahsilat allows Retrieve Embedded Sensitive Data.This issue solved in versions 1.21.10, 1.23.01, 1.23.08, 1.23.11 and 1.24.03.
network
low complexity
finrota CWE-312
7.5
2024-10-02 CVE-2024-20448 Cleartext Storage of Sensitive Information vulnerability in Cisco Nexus Dashboard Fabric Controller
A vulnerability in the Cisco Nexus Dashboard Fabric Controller (NDFC) software, formerly Cisco Data Center Network Manager (DCNM), could allow an attacker with access to a backup file to view sensitive information. This vulnerability is due to the improper storage of sensitive information within config only and full backup files.
network
low complexity
cisco CWE-312
8.6
2024-09-30 CVE-2024-8459 Cleartext Storage of Sensitive Information vulnerability in Planet Gs-4210-24P2S Firmware and Gs-4210-24Pl4C Firmware
Certain switch models from PLANET Technology store SNMPv3 users' passwords in plaintext within the configuration files, allowing remote attackers with administrator privileges to read the file and obtain the credentials.
network
low complexity
planet CWE-312
4.9
2024-09-27 CVE-2024-8644 Cleartext Storage of Sensitive Information vulnerability in Oceanicsoft Valeapp
Cleartext Storage of Sensitive Information in a Cookie vulnerability in Oceanic Software ValeApp allows Protocol Manipulation, : JSON Hijacking (aka JavaScript Hijacking).This issue affects ValeApp: before v2.0.0.
network
low complexity
oceanicsoft CWE-312
7.5