Threats Tagged 'cwe-312'
View all threats tagged with 'cwe-312'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-312'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-21080: CWE-312 Cleartext storage of sensitive information in Samsung Mobile Smart SwitchCVE-2026-21080 0 Cleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data. Join the discussion | CVE Database V5 | 08/10/2026, 07:43:38 UTC Added: 08/10/2026, 08:26:50 UTC |
CVE-2026-15721: CWE-312 Cleartext storage of sensitive information in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human ResourcesCVE-2026-15721 0 Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1. Join the discussion | CVE Database V5 | 08/04/2026, 08:18:08 UTC Added: 08/04/2026, 09:18:34 UTC |
CVE-2026-34490: CWE-312 Cleartext storage of sensitive information in Johnson Controls XAAP ApplicationCVE-2026-34490 0 Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retrieve Sensitive Data. This issue affects XAAP Application: before 1.53. Join the discussion | CVE Database V5 | 07/31/2026, 17:17:33 UTC Added: 07/31/2026, 19:28:13 UTC |
CVE-2026-59327: CWE-312 Cleartext Storage of Sensitive Information in Spring Spring Tools for EclipseCVE-2026-59327 0 Spring Tools for Eclipse versions 5.2.0 and earlier store the Spring Boot DevTools remote secret in cleartext within launch configuration files. These files are saved as XML in the workspace metadata or project directories, potentially exposing the secret if accessed via filesystem, backups, or version control. The secret protects the remote restart/reload endpoint, which can execute arbitrary class bytes on the target application. Exposure of this secret could allow an attacker with read access to achieve remote code execution. The vulnerability has a medium severity with a CVSS score of 4.4. Join the discussion | CVE Database V5 | 07/30/2026, 05:29:20 UTC Added: 07/30/2026, 06:24:12 UTC |
CVE-2026-55985: CWE-312 in Tycon Systems TPDIN-Monitor-WEB2CVE-2026-55985 0 The web management interface in Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated users. Any party with access to the administrative dashboard can immediately read these credentials, which may be used to compromise other systems on the local network. Join the discussion | CVE Database V5 | 07/24/2026, 21:37:29 UTC Added: 07/24/2026, 22:07:39 UTC |
CVE-2026-16802: CWE-312 Cleartext storage of sensitive information in Devolutions PowerShell UniversalCVE-2026-16802 0 Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local actor with file system access to read secret values via secret variables stored in cleartext on disk when no vault is selected. Join the discussion | CVE Database V5 | 07/24/2026, 14:55:56 UTC Added: 07/24/2026, 15:08:41 UTC |
CVE-2024-58023: CWE-312 Cleartext Storage of Sensitive Information in Bosch Bosch Configuration ManagerCVE-2024-58023 0 Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive information. Join the discussion | CVE Database V5 | 07/23/2026, 07:52:32 UTC Added: 07/23/2026, 08:37:35 UTC |
CVE-2026-13380: CWE-201 Insertion of sensitive information into sent data in VSee ClinicCVE-2026-13380 0 VSee Clinic version 7.1.26 and VSee Clinic API 1.3.0 expose cleartext SFTP credentials in HTTP responses from three unauthenticated endpoints when SFTP is configured. These credentials can be retrieved without authentication, allowing an attacker to access the associated SFTP server. This vulnerability is classified under CWE-201 and CWE-312 and has a critical severity with a CVSS score of 9. No official patch or remediation guidance is currently available. Join the discussion | CVE Database V5 | 07/20/2026, 20:11:46 UTC Added: 07/20/2026, 20:27:18 UTC |
Showing 1 to 8 of 8 results