Vulnerabilities (CVE)

Filtered by CWE-316
Total 25 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-25649 1 Delinea 1 Secret Server 2026-06-17 N/A 6.7 MEDIUM
In Delinea PAM Secret Server 11.4, it is possible for an attacker (with Administrator access to the Secret Server machine) to read the following data from a memory dump: the decrypted master key, database credentials (when SQL Server Authentication is enabled), the encryption key of RabbitMQ queue messages, and session cookies.
CVE-2024-24915 2 Checkpoint, Microsoft 2 Smartconsole, Windows 2026-06-17 N/A 6.1 MEDIUM
Credentials are not cleared from memory after being used. A user with Administrator permissions can execute memory dump for SmartConsole process and fetch them.
CVE-2023-40724 1 Siemens 1 Qms Automotive 2026-06-17 N/A 7.3 HIGH
A vulnerability has been identified in QMS Automotive (All versions < V12.39). User credentials are found in memory as plaintext. An attacker could perform a memory dump, and get access to credentials, and use it for impersonation.
CVE-2021-31989 1 Axis 1 Device Manager 2026-06-17 3.5 LOW 5.3 MEDIUM
A user with permission to log on to the machine hosting the AXIS Device Manager client could under certain conditions extract a memory dump from the built-in Windows Task Manager application. The memory dump may potentially contain credentials of connected Axis devices.
CVE-2014-2366 1 Advantech 1 Advantech Webaccess 2026-06-17 9.0 HIGH N/A
upAdminPg.asp in Advantech WebAccess before 7.2 allows remote authenticated users to discover credentials by reading HTML source code.