CWE-312
CWE-312 · 3 records · 1 with a public proof-of-concept
Records the NVD classes under CWE-312, highest CVSS first.
- CRITICAL 9.8CVE-2026-15721
Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
- HIGH 8.8CVE-2026-55997public PoC
Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in plaintext with no expiration, so a malicious user could obtain one either through the Rancher API, etcd, stored…
- UNSCOREDCVE-2026-86443
Cleartext storage of sensitive information in the DuoxMe application for Android, in versions prior to 4.3.4, allows an attacker with local access to the device to retrieve the credentials stored by the application and impersonate the user account.