Vulnerabilities > Cleartext Storage of Sensitive Information

DATE CVE VULNERABILITY TITLE RISK
2020-10-28 CVE-2020-27986 Cleartext Storage of Sensitive Information vulnerability in Sonarsource Sonarqube 8.4.2.36762
SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI.
network
low complexity
sonarsource CWE-312
7.5
2020-10-21 CVE-2020-27613 Cleartext Storage of Sensitive Information vulnerability in Bigbluebutton
The installation procedure in BigBlueButton before 2.2.28 (or earlier) uses ClueCon as the FreeSWITCH password, which allows local users to achieve unintended FreeSWITCH access.
local
low complexity
bigbluebutton CWE-312
8.4
2020-10-21 CVE-2020-6648 Cleartext Storage of Sensitive Information vulnerability in Fortinet Fortios and Fortiproxy
A cleartext storage of sensitive information vulnerability in FortiOS command line interface in versions 6.2.4 and earlier and FortiProxy 2.0.0, 1.2.9 and earlier may allow an authenticated attacker to obtain sensitive information such as users passwords by connecting to FortiGate CLI and executing the "diag sys ha checksum show" command.
network
low complexity
fortinet CWE-312
6.5
2020-09-22 CVE-2020-4619 Cleartext Storage of Sensitive Information vulnerability in IBM Data Risk Manager
IBM Data Risk Manager (iDNA) 2.0.6 stores user credentials in plain in clear text which can be read by an authenticated user.
network
low complexity
ibm CWE-312
6.5
2020-09-18 CVE-2020-8225 Cleartext Storage of Sensitive Information vulnerability in Nextcloud Desktop
A cleartext storage of sensitive information in Nextcloud Desktop Client 2.6.4 gave away information about used proxies and their authentication credentials.
network
low complexity
nextcloud CWE-312
7.5
2020-09-16 CVE-2020-2274 Cleartext Storage of Sensitive Information vulnerability in Jenkins Elastest
Jenkins ElasTest Plugin 1.2.1 and earlier stores its server password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
local
low complexity
jenkins CWE-312
5.5
2020-09-09 CVE-2020-15784 Cleartext Storage of Sensitive Information vulnerability in Siemens Spectrum Power 4 4.70
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP8).
network
low complexity
siemens CWE-312
5.3
2020-08-26 CVE-2020-15485 Cleartext Storage of Sensitive Information vulnerability in Niscomed M1000 Multipara Patient Monitor Firmware
An issue was discovered on Nescomed Multipara Monitor M1000 devices.
local
low complexity
niscomed CWE-312
5.5
2020-08-26 CVE-2020-15484 Cleartext Storage of Sensitive Information vulnerability in Niscomed M1000 Multipara Patient Monitor Firmware
An issue was discovered on Nescomed Multipara Monitor M1000 devices.
network
low complexity
niscomed CWE-312
7.5
2020-08-11 CVE-2020-17495 Cleartext Storage of Sensitive Information vulnerability in Django-Celery-Results Project Django-Celery-Results
django-celery-results through 1.2.1 stores task results in the database.
network
low complexity
django-celery-results-project CWE-312
7.5