VulnSea

CWE-256

CVEs classified under CWE-256, newest first.

14 CVEsRSS

CVE-2026-77407High· 7.0
6d ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, PlainAuth values defined in auth.go retain passwords as exported plaintext fields in Connection.Config.SASL after a successful PLAIN authentication handshake. The Connection…

Twilightrabbitmq · amqp091-goEPSS 0.13%via NVD
CVE-2026-2380High· 7.4
6d ago

On affected platforms running Arista EOS with OpenConfig-related services (i.e., gNMI, gNSI, RESTCONF and NETCONF), sensitive requests and responses may be unintentionally logged

On affected platforms running Arista EOS with OpenConfig-related services (i.e., gNMI, gNSI, RESTCONF and NETCONF), sensitive requests and responses may be unintentionally logged. These may be stored on the local EOS device or recorded o…

TwilightArista Networks · EOSEPSS 0.25%via NVD
CVE-2026-46488Critical· 9.1PoC
1w ago

motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection

motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Prior to 0.44.0, motionEye accepts the client-controlled meye_username and meye_password_hash c…

Abyssalmotioneye-project · motioneyeEPSS 0.27%via NVD
CVE-2026-82783Medium· 4.2
1w ago

Plaintext storage of a password issue exists in CONPROSYS nano Series

Plaintext storage of a password issue exists in CONPROSYS nano Series . If this vulnerability is exploited, an attacker with physical access to the product may obtain credentials.

SunlitContec Co., Ltd. · Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*EPSS 0.13%via NVD
CVE-2026-89444High· 7.0
1w ago

kernel: platform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer (CVE-2026-89444)

A flaw was found in the Linux kernel. The `dell-wmi-sysman` driver, responsible for managing Dell WMI (Windows Management Instrumentation) system attributes, incorrectly logs sensitive information. Specifically, when setting a BIOS attribu…

TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVE-2026-19051High· 7.1
2w ago

Plaintext storage of a password vulnerability in Menulux Software Inc

Plaintext storage of a password vulnerability in Menulux Software Inc. Menulux Portal allows Retrieve Embedded Sensitive Data. This issue affects Menulux Portal: before 20260903211448.

TwilightEPSS 0.21%via NVD
CVE-2026-15933None
2w ago

OptimiDoc Server (On-Premise) stores credentials for external services in cleartext

OptimiDoc Server (On-Premise) stores credentials for external services in cleartext. An authenticated administrator can view previously configured service passwords, including SMTP, FTP (for scan delivery), Active Directory (for user lis…

SunlitEPSS 0.36%via NVD
CVE-2026-82453High· 7.5
3w ago

rust-iot-platform through commit 5df942ab stores user passwords in cleartext without hashing in the user model

rust-iot-platform through commit 5df942ab stores user passwords in cleartext without hashing in the user model. Attackers can read API responses from user retrieval and listing routes to obtain plaintext credentials for all accounts.

TwilightEPSS 0.28%via NVD
CVE-2026-55765High· 8.5
1mo ago

CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments

CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG embedded cleartext role passwords in `ALTER ROLE` and `CREATE ROLE` statements generated by Set…

TwilightEPSS 0.29%via NVD
CVE-2026-55164Medium· 4.9
1mo ago

Lemur manages TLS certificate creation

Lemur manages TLS certificate creation. Prior to 1.9.2, lemur.users.service.update assigned a replacement password directly to users.password, while lemur/users/models.py registered User.hash_password only for the before_insert event. Be…

Sunlitlemur · lemurEPSS 0.29%via NVD
CVE-2026-50268Low· 1.9
2mo ago

Steeltoe: OAEP setting silently selects PKCS#1 v1.5 padding

Steeltoe: OAEP setting silently selects PKCS#1 v1.5 padding

SunlitSteeltoe · Steeltoe.Configuration.EncryptionEPSS 0.05%via GHSA
CVE-2026-42151High· 7.5
4mo ago

Prometheus is an open-source monitoring system and time series database

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of…

Twilightprometheus · prometheusEPSS 0.35%via NVD
CVE-2026-33216High· 8.6
6mo ago

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, for MQTT deployments using usercodes/passwords: MQTT passwords are incorrectly classified as a non-auth…

Twilightlinuxfoundation · nats-serverEPSS 0.36%via NVD
CVE-2026-21660Critical· 9.8
6mo ago

A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to unauthorized access, exposure of sensitive information, an…

A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to unauthorized access, exposure of sensitive information, an…

Midnightjohnsoncontrols · frick_controls_quantum_hd_firmwareEPSS 0.23%via NVD
CWE-256 vulnerabilities (CVEs) · VulnSea