Threats Tagged 'cwe-256'
View all threats tagged with 'cwe-256'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-256'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-50268: CWE-256: Plaintext Storage of a Password in SteeltoeOSS Steeltoe.Configuration.EncryptionCVE-2026-50268 0 Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Configuration.Encryption 4.0.0 through 4.1.0, configuring `encrypt:rsa:algorithm=OAEP` does not enable OAEP encryption. Due to an incorrect BouncyCastle transformation string, the `OAEP` setting selects PKCS#1 v1.5, which is the same algorithm as the `DEFAULT` setting. Steeltoe.Configuration.Encryption version 4.2.0 patches the issue. Join the discussion | CVE Database V5 | 06/17/2026, 22:01:19 UTC Added: 06/17/2026, 22:35:08 UTC |
CVE-2024-39575: CWE-256: Plaintext Storage of a Password in Dell Dell EMC VxRail ApplianceCVE-2024-39575 0 update_disk_psu_baseline.sh requires password in plain text Join the discussion | CVE Database V5 | 06/16/2026, 17:54:08 UTC Added: 06/16/2026, 18:30:54 UTC |
CVE-2024-45636: CWE-256 Plaintext Storage of a Password in IBM Security QRadar EDRCVE-2024-45636 0 IBM Security QRadar EDR 3.12 through 3.12.24 stores user credentials in plain text which can be read by a local privileged user. Join the discussion | CVE Database V5 | 06/11/2026, 15:10:38 UTC Added: 06/11/2026, 15:30:09 UTC |
CVE-2024-5960: CWE-256 Plaintext Storage of a Password in Eliz Software PanelCVE-2024-5960 0 Plaintext Storage of a Password vulnerability in Eliz Software Panel allows : Use of Known Domain Credentials. This issue affects Panel: before v2.3.24. Join the discussion | CVE Database V5 | 09/18/2024, 14:49:32 UTC Added: 06/03/2026, 14:18:51 UTC |
Showing 1 to 4 of 4 results