Vulnerabilities > Cleartext Storage of Sensitive Information

DATE CVE VULNERABILITY TITLE RISK
2021-07-15 CVE-2020-12731 Cleartext Storage of Sensitive Information vulnerability in Magicsmotion Flamingo 2 Firmware
The MagicMotion Flamingo 2 application for Android stores data on an sdcard under com.vt.magicmotion/files/Pictures, whence it can be read by other applications.
network
low complexity
magicsmotion CWE-312
7.5
2021-07-08 CVE-2021-31816 Cleartext Storage of Sensitive Information vulnerability in Octopus Server
When configuring Octopus Server if it is configured with an external SQL database, on initial configuration the database password is written to the OctopusServer.txt log file in plaintext.
network
low complexity
octopus CWE-312
7.5
2021-07-08 CVE-2021-31817 Cleartext Storage of Sensitive Information vulnerability in Octopus Server
When configuring Octopus Server if it is configured with an external SQL database, on initial configuration the database password is written to the OctopusServer.txt log file in plaintext.
network
low complexity
octopus CWE-312
7.5
2021-07-05 CVE-2021-36158 Cleartext Storage of Sensitive Information vulnerability in Alpinelinux Aports
In the xrdp package (in branches through 3.14) for Alpine Linux, RDP sessions are vulnerable to man-in-the-middle attacks because pre-generated RSA certificates and private keys are used.
network
high complexity
alpinelinux CWE-312
5.9
2021-06-29 CVE-2021-29481 Cleartext Storage of Sensitive Information vulnerability in Ratpack Project Ratpack
Ratpack is a toolkit for creating web applications.
network
low complexity
ratpack-project CWE-312
7.5
2021-06-24 CVE-2021-29950 Cleartext Storage of Sensitive Information vulnerability in Mozilla Thunderbird
Thunderbird unprotects a secret OpenPGP key prior to using it for a decryption, signing or key import task.
network
low complexity
mozilla CWE-312
7.5
2021-06-24 CVE-2021-29954 Cleartext Storage of Sensitive Information vulnerability in Mozilla Hubs Cloud Reticulum
Proxy functionality built into Hubs Cloud’s Reticulum software allowed access to internal URLs, including the metadata service.
network
low complexity
mozilla CWE-312
critical
9.8
2021-06-24 CVE-2021-29956 Cleartext Storage of Sensitive Information vulnerability in Mozilla Thunderbird
OpenPGP secret keys that were imported using Thunderbird version 78.8.1 up to version 78.10.1 were stored unencrypted on the user's local disk.
network
low complexity
mozilla CWE-312
4.3
2021-06-15 CVE-2021-28858 Cleartext Storage of Sensitive Information vulnerability in Tp-Link Tl-Wpa4220 Firmware 4.0.2
TP-Link's TL-WPA4220 4.0.2 Build 20180308 Rel.37064 does not use SSL by default.
local
low complexity
tp-link CWE-312
5.5
2021-06-11 CVE-2021-23182 Cleartext Storage of Sensitive Information vulnerability in Gallagher Command Centre
Cleartext Storage of Sensitive Information in Memory vulnerability in Gallagher Command Centre Server allows OSDP reader master keys to be discoverable in server memory dumps.
local
low complexity
gallagher CWE-312
4.4