VulnSea

CWE-313

CVEs classified under CWE-313, newest first.

6 CVEsRSS

CVE-2026-90842Low· 3.7PoC
1w ago

A weakness has been identified in PHPGurukul Blood Donor Management System 1.0

A weakness has been identified in PHPGurukul Blood Donor Management System 1.0. Affected by this issue is some unknown functionality of the file application/models/admin/Login_Model.php. This manipulation of the argument password/email/c…

TwilightPHPGurukul · Blood Donor Management SystemEPSS 0.20%via NVD
CVE-2026-14663Medium· 6.5
1mo ago

Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of the faulty ciphertext

Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of the faulty ciphertext. The OpenSSL version and OpenSSL configuration determine the disabled ciphers. If the applica…

Sunlitpostgresql · postgresqlEPSS 0.10%via NVD
CVE-2026-8804None
2mo ago

Puppet resource_api (shipped in Puppet Core 8.x and Puppet Enterprise 2023.8.x and 2025.x) does not preserve the sensitive flag on parameters defined via the resource-api, causing values such as passwords to be stored in cleartext in the…

Puppet resource_api (shipped in Puppet Core 8.x and Puppet Enterprise 2023.8.x and 2025.x) does not preserve the sensitive flag on parameters defined via the resource-api, causing values such as passwords to be stored in cleartext in the…

SunlitEPSS 0.11%via NVD
CVE-2026-52783High· 8.2
2mo ago

OpenProject is open-source, web-based project management software

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, OpenProject's Storages module writes the OneDrive/SharePoint userless OAuth access_token plaintext to Rails.cache under the deterministic key …

TwilightEPSS 0.20%via NVD
CVE-2026-5531Medium· 5.3
5mo ago

A vulnerability has been found in SourceCodester Student Result Management System 1.0

A vulnerability has been found in SourceCodester Student Result Management System 1.0. Impacted is an unknown function of the file /login_credentials.txt of the component HTTP GET Request Handler. The manipulation leads to cleartext stor…

SunlitEPSS 0.20%via NVD
CVE-2018-10622Medium· 5.2
8y ago

Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format

Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials for network authentication.

Sunlitmedtronic · mycarelink_24952_patient_monitor_firmwareEPSS 0.33%via NVD
CWE-313 vulnerabilities (CVEs) · VulnSea