CWE-312

CWE-312 · 3 records · 1 with a public proof-of-concept

Records the NVD classes under CWE-312, highest CVSS first.

  1. CRITICAL 9.8CVE-2026-15721

    Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 8.8CVE-2026-55997public PoC

    Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in plaintext with no expiration, so a malicious user could obtain one either through the Rancher API, etcd, stored

    AI risk analysis on Exploit-DB.ai →

  3. UNSCOREDCVE-2026-86443

    Cleartext storage of sensitive information in the DuoxMe application for Android, in versions prior to 4.3.4, allows an attacker with local access to the device to retrieve the credentials stored by the application and impersonate the user account.

    AI risk analysis on Exploit-DB.ai →