CWE-256

CWE-256 · 3 records · 1 with a public proof-of-concept

Records the NVD classes under CWE-256, highest CVSS first.

  1. HIGH 7.5CVE-2026-84884

    IBM Guardium Data Protection 12.2 stores internal REST service-account passwords in a reversible plaintext-equivalent format. An authenticated attacker who gains access to the stored credential could recover the password and obtain an administrative REST acces…

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 7.4CVE-2026-2380

    On affected platforms running Arista EOS with OpenConfig-related services (i.e., gNMI, gNSI, RESTCONF and NETCONF), sensitive requests and responses may be unintentionally logged. These may be stored on the local EOS device or recorded on remote accounting ser…

    AI risk analysis on Exploit-DB.ai →

  3. UNSCOREDCVE-2026-104892public PoC

    Plane is an open-source project management tool. Prior to 1.4.0, aPITokenLogMiddleware logs API keys in plaintext. This allows someone with low privileges to steal user API keys and further escalate their privileges. This issue is fixed in 1.4.0.

    AI risk analysis on Exploit-DB.ai →