Vulnerabilities > Cleartext Storage of Sensitive Information

DATE CVE VULNERABILITY TITLE RISK
2021-02-23 CVE-2021-26595 Cleartext Storage of Sensitive Information vulnerability in Rangerstudio Directus
In Directus 8.x through 8.8.1, an attacker can learn sensitive information such as the version of the CMS, the PHP version used by the site, and the name of the DBMS, simply by view the result of the api-aa, called automatically upon a connection.
network
low complexity
rangerstudio CWE-312
5.3
2021-02-23 CVE-2021-23827 Cleartext Storage of Sensitive Information vulnerability in Keybase
Keybase Desktop Client before 5.6.0 on Windows and macOS, and before 5.6.1 on Linux, allows an attacker to obtain potentially sensitive media (such as private pictures) in the Cache and uploadtemps directories.
local
low complexity
keybase CWE-312
5.5
2021-02-22 CVE-2021-27549 Cleartext Storage of Sensitive Information vulnerability in Genymobile Genymotion Desktop
Genymotion Desktop through 3.2.0 leaks the host's clipboard data to the Android application by default.
network
low complexity
genymobile CWE-312
5.3
2021-02-19 CVE-2020-36248 Cleartext Storage of Sensitive Information vulnerability in Owncloud
The ownCloud application before 2.15 for Android allows attackers to use adb to include a PIN preferences value in a backup archive, and consequently bypass the PIN lock feature by restoring from this archive.
low complexity
owncloud CWE-312
4.6
2021-02-16 CVE-2021-27233 Cleartext Storage of Sensitive Information vulnerability in Mutare Voice 3.0.0/3.2.6/3.3.7
An issue was discovered in Mutare Voice (EVM) 3.x before 3.3.8.
network
low complexity
mutare CWE-312
4.9
2021-02-13 CVE-2021-27210 Cleartext Storage of Sensitive Information vulnerability in Tp-Link Archer C5V Firmware 1.7181221
TP-Link Archer C5v 1.7_181221 devices allows remote attackers to retrieve cleartext credentials via [USER_CFG#0,0,0,0,0,0#0,0,0,0,0,0]0,0 to the /cgi?1&5 URI.
network
low complexity
tp-link CWE-312
6.5
2021-02-12 CVE-2021-20408 Cleartext Storage of Sensitive Information vulnerability in IBM Security Verify Information Queue 1.0.6/1.0.7
IBM Security Verify Information Queue 1.0.6 and 1.0.7 could disclose highly sensitive information to a local user due to inproper storage of a plaintext cryptographic key.
local
low complexity
ibm CWE-312
5.5
2021-02-12 CVE-2021-20407 Cleartext Storage of Sensitive Information vulnerability in IBM Security Verify Information Queue 1.0.6/1.0.7
IBM Security Verify Information Queue 1.0.6 and 1.0.7 discloses sensitive information in source code that could be used in further attacks against the system.
network
low complexity
ibm CWE-312
7.5
2021-02-12 CVE-2021-27205 Cleartext Storage of Sensitive Information vulnerability in Telegram
Telegram before 7.4 (212543) Stable on macOS stores the local copy of self-destructed messages in a sandbox path, leading to sensitive information disclosure.
local
low complexity
telegram CWE-312
5.5
2021-02-12 CVE-2021-27204 Cleartext Storage of Sensitive Information vulnerability in Telegram
Telegram before 7.4 (212543) Stable on macOS stores the local passcode in cleartext, leading to information disclosure.
local
low complexity
telegram CWE-312
5.5