Threats Tagged 'cwe-260'
View all threats tagged with 'cwe-260'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-260'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-103548 is a vulnerability in Itron MV-90 xi version 3.0 where passwords are stored improperly in a recoverable format within the configuration file. This allows attackers with some level of access to decode stored passwords and password histories, potentially gaining unauthorized access to the MV-90 application as any user. Join the discussion | CVE Database V5 | 09/30/2026, 19:45:14 UTC Added: 09/30/2026, 20:03:42 UTC |
0 MiniDVBLinux 5.4 contains an unauthenticated configuration download vulnerability that allows remote attackers to access sensitive system configuration files through a direct object reference. Attackers can exploit the backup download endpoint by sending a GET request with 'action=getconfig' to retrieve a complete system configuration archive containing sensitive credentials. Join the discussion | CVE Database V5 | 12/09/2025, 20:53:43 UTC Added: 12/09/2025, 21:13:01 UTC |
0 Tinycontrol LAN Controller v3 LK3 version 1.58a contains an unauthenticated vulnerability that allows remote attackers to download configuration backup files containing sensitive credentials. Attackers can retrieve the lk3_settings.bin file and extract base64-encoded user and admin passwords without authentication. Join the discussion | CVE Database V5 | 12/09/2025, 20:49:46 UTC Added: 12/09/2025, 20:57:57 UTC |
0 IBM QRadar SIEM 7.5 through 7.5.0 UP14 stores user credentials in configuration files in source control which can be read by an authenticated user. Join the discussion | CVE Database V5 | 11/12/2025, 21:19:55 UTC Added: 11/12/2025, 21:36:47 UTC |
0 IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5, and 6.2.1.0 stores user credentials in configuration files which can be read by a local user. Join the discussion | CVE Database V5 | 10/16/2025, 14:54:53 UTC Added: 10/16/2025, 14:59:00 UTC |
IBM MQ LTS 9.1.0.0 through 9.1.0.29, 9.2.0.0 through 9.2.0.36, 9.3.0.0 through 9.3.0.30 and 9.4.0.0 through 9.4.0.12 and IBM MQ CD 9.3.0.0 through 9.3.5.1 and 9.4.0.0 through 9.4.3.0 Java and JMS stores a password in client configuration files when trace is enabled which can be read by a local user. Join the discussion | CVE Database V5 | 09/07/2025, 00:37:00 UTC Added: 09/07/2025, 00:47:24 UTC |
0 eslint-ban-moment is an Eslint plugin for final assignment in VIHU. In 3.0.0 and earlier, a sensitive Supabase URI is exposed in .env. A valid Supabase URI with embedded username and password will allow an attacker complete unauthorized access and control over database and user data. This could lead to data exfiltration, modification or deletion. Join the discussion | CVE Database V5 | 08/21/2025, 16:14:29 UTC Added: 08/21/2025, 16:32:48 UTC |
Standard Windows users can access the configuration file for database access of the BRAIN2 application and decrypt it. Join the discussion | CVE Database V5 | 06/23/2025, 12:37:55 UTC Added: 06/23/2025, 12:49:29 UTC |
IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow an unauthenticated user in the environment to obtain highly sensitive information in configuration files. Join the discussion | CVE Database V5 | 06/03/2025, 15:16:19 UTC Added: 06/03/2025, 15:28:43 UTC |
Showing 1 to 9 of 9 results