Vulnerabilities > Cleartext Storage of Sensitive Information

DATE CVE VULNERABILITY TITLE RISK
2023-11-30 CVE-2023-46386 Cleartext Storage of Sensitive Information vulnerability in Loytec Linx-151 Firmware and Linx-212 Firmware
LOYTEC electronics GmbH LINX-212 and LINX-151 devices (all versions) are vulnerable to Insecure Permissions via registry.xml file.
network
low complexity
loytec CWE-312
7.5
2023-11-30 CVE-2023-46388 Cleartext Storage of Sensitive Information vulnerability in Loytec Linx-151 Firmware and Linx-212 Firmware
LOYTEC electronics GmbH LINX-212 and LINX-151 devices (all versions) are vulnerable to Insecure Permissions via dpal_config.zml file.
network
low complexity
loytec CWE-312
7.5
2023-11-24 CVE-2023-48707 Cleartext Storage of Sensitive Information vulnerability in Codeigniter Shield 1.0.0
CodeIgniter Shield is an authentication and authorization provider for CodeIgniter 4.
network
low complexity
codeigniter CWE-312
6.5
2023-11-22 CVE-2023-47312 Cleartext Storage of Sensitive Information vulnerability in H-Mdm Headwind MDM 5.22.1
Headwind MDM Web panel 5.22.1 is vulnerable to Incorrect Access Control due to Login Credential Leakage via Audit Entries.
network
low complexity
h-mdm CWE-312
6.5
2023-11-21 CVE-2023-48305 Cleartext Storage of Sensitive Information vulnerability in Nextcloud Server
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform.
local
low complexity
nextcloud CWE-312
4.4
2023-11-21 CVE-2023-48700 Cleartext Storage of Sensitive Information vulnerability in Nautobot Nautobot-Plugin-Device-Onboarding
The Nautobot Device Onboarding plugin uses the netmiko and NAPALM libraries to simplify the onboarding process of a new device into Nautobot down to, in many cases, an IP Address and a Location.
network
low complexity
nautobot CWE-312
6.5
2023-10-27 CVE-2023-46376 Cleartext Storage of Sensitive Information vulnerability in Zentao BIZ
Zentao Biz version 8.7 and before is vulnerable to Information Disclosure.
network
low complexity
zentao CWE-312
7.5
2023-10-25 CVE-2023-46128 Cleartext Storage of Sensitive Information vulnerability in Networktocode Nautobot 2.0.0/2.0.1/2.0.2
Nautobot is a Network Automation Platform built as a web application atop the Django Python framework with a PostgreSQL or MySQL database.
network
low complexity
networktocode CWE-312
6.5
2023-10-25 CVE-2023-46653 Cleartext Storage of Sensitive Information vulnerability in Jenkins Lambdatest-Automation
Jenkins lambdatest-automation Plugin 1.20.10 and earlier logs LAMBDATEST Credentials access token at the INFO level, potentially resulting in its exposure.
network
low complexity
jenkins CWE-312
6.5
2023-10-16 CVE-2023-45151 Cleartext Storage of Sensitive Information vulnerability in Nextcloud Server
Nextcloud server is an open source home cloud platform.
network
low complexity
nextcloud CWE-312
8.8