Vulnerabilities > Cleartext Storage of Sensitive Information

DATE CVE VULNERABILITY TITLE RISK
2021-05-14 CVE-2021-30183 Cleartext Storage of Sensitive Information vulnerability in Octopus Server
Cleartext storage of sensitive information in multiple versions of Octopus Server where in certain situations when running import or export processes, the password used to encrypt and decrypt sensitive values would be written to the logs in plaintext.
network
low complexity
octopus CWE-312
7.5
2021-05-13 CVE-2021-20995 Cleartext Storage of Sensitive Information vulnerability in Wago products
In multiple managed switches by WAGO in different versions the webserver cookies of the web based UI contain user credentials.
network
low complexity
wago CWE-312
7.5
2021-05-10 CVE-2021-25645 Cleartext Storage of Sensitive Information vulnerability in Couchbase Server
An issue was discovered in Couchbase Server before 6.0.5, 6.1.x through 6.5.x before 6.5.2, and 6.6.x before 6.6.1.
local
low complexity
couchbase CWE-312
4.4
2021-05-06 CVE-2021-22206 Cleartext Storage of Sensitive Information vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 11.6.
network
low complexity
gitlab CWE-312
4.9
2021-04-30 CVE-2021-21547 Cleartext Storage of Sensitive Information vulnerability in Dell products
Dell EMC Unity, UnityVSA, and Unity XT versions prior to 5.0.7.0.5.008 contain a plain-text password storage vulnerability when the Dell Upgrade Readiness Utility is run on the system.
local
low complexity
dell CWE-312
6.7
2021-04-28 CVE-2020-22783 Cleartext Storage of Sensitive Information vulnerability in Etherpad
Etherpad <1.8.3 stored passwords used by users insecurely in the database and in log files.
network
low complexity
etherpad CWE-312
6.5
2021-04-23 CVE-2021-31791 Cleartext Storage of Sensitive Information vulnerability in Sentrysoftware Hardware Sentry KM for BMC Patrol
In Hardware Sentry KM before 10.0.01 for BMC PATROL, a cleartext password may be discovered after a failure or timeout of a command.
network
low complexity
sentrysoftware CWE-312
7.5
2021-04-23 CVE-2021-25898 Cleartext Storage of Sensitive Information vulnerability in Void Aural REC Monitor 9.0.0.1
An issue was discovered in svc-login.php in Void Aural Rec Monitor 9.0.0.1.
network
low complexity
void CWE-312
7.5
2021-04-23 CVE-2021-31539 Cleartext Storage of Sensitive Information vulnerability in Wowza Streaming Engine
Wowza Streaming Engine before 4.8.8.01 (in a default installation) has cleartext passwords stored in the conf/admin.password file.
local
low complexity
wowza CWE-312
5.5
2021-04-13 CVE-2021-3473 Cleartext Storage of Sensitive Information vulnerability in Lenovo Xclarity Controller
An internal product security audit of Lenovo XClarity Controller (XCC) discovered that the XCC configuration backup/restore password may be written to an internal XCC log buffer if Lenovo XClarity Administrator (LXCA) is used to perform the backup/restore.
network
low complexity
lenovo CWE-312
4.9