Vulnerability index

Browse CVEs

1,244 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
Unclassified CRITICAL 9.8
CVE-2023-48010

STMicroelectronics SPC58 is vulnerable to Missing Protection Mechanism for Alternate Hardware Interface. Code running as Supervisor on the SPC58 Powe…

Mitigation only
Fix from $2,300 2024-12-05
Aspect Ent 12 Firmware HIGH 7.5
CVE-2024-51546

Credentials Disclosure vulnerabilities allow access to on board project back-up bundles.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEX…

Fix: 3.08.03+
Fix from $1,950 2024-12-05
Aspect Ent 12 Firmware CRITICAL 9.8
CVE-2024-51545

Username Enumeration vulnerabilities allow access to application level username add, delete, modify and list functions.  Affected products: ABB ASP…

Fix: 3.08.03+
Fix from $2,300 2024-12-05
Veeam Backup \& Replication MEDIUM 6.5
CVE-2024-42457

A vulnerability in Veeam Backup & Replication allows users with certain operator roles to expose saved credentials by leveraging a combination of met…

Fix: 12.3.0.310+
Fix from $1,600 2024-12-04
Unclassified CRITICAL 9.0
CVE-2019-17082

Insufficiently Protected Credentials vulnerability in OpenText™ AccuRev allows Authentication Bypass. When installed on a Linux or Solaris system th…

Mitigation only
Fix from $2,300 2024-11-26
Firefox MEDIUM 5.7
CVE-2024-11703

On Android, Firefox may have inadvertently allowed viewing saved passwords without the required device PIN authentication. This vulnerability affects…

Fix: 133.0+
Fix from $1,600 2024-11-26
Unclassified MEDIUM 6.3
CVE-2024-6749

Seth Fogie, member of the AXIS Camera Station Pro Bug Bounty Program, has found that the Incident report feature may expose sensitive credentials on …

Mitigation only
Fix from $1,600 2024-11-26
Unclassified MEDIUM 5.5
CVE-2024-47142

AIPHONE IXG SYSTEM IXG-2C7 firmware Ver.2.03 and earlier and IXG-2C7-L firmware Ver.2.03 and earlier contain an issue with insufficiently protected c…

Mitigation only
Fix from $1,600 2024-11-22
Unclassified MEDIUM 6.5
CVE-2024-39290

Insufficiently protected credentials issue exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent unauthenticated attacker may obtain sensiti…

Mitigation only
Fix from $1,600 2024-11-22
Catalyst Sd Wan Manager MEDIUM 6.5
CVE-2021-1232

A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to read arb…

Mitigation only
Fix from $1,600 2024-11-18
Unclassified CRITICAL 9.1
CVE-2022-45157

A vulnerability has been identified in the way that Rancher stores vSphere's CPI (Cloud Provider Interface) and CSI (Container Storage Interface) cre…

Mitigation only
Fix from $2,300 2024-11-13
Unclassified HIGH 8.0
CVE-2024-51240

An issue in the luci-mod-rpc package in OpenWRT Luci LTS allows for privilege escalation from an admin account to root via the JSON-RPC-API, which is…

Mitigation only
Fix from $1,950 2024-11-05
Bitrix24 MEDIUM 6.8
CVE-2024-34885

Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to read SMTP accounts pass…

No fix yet
Fix from $1,600 2024-11-04
Cics Transaction Gateway HIGH 7.5
CVE-2023-50310

IBM CICS Transaction Gateway for Multiplatforms 9.2 and 9.3 transmits or stores authentication credentials, but it uses an insecure method that is su…

Mitigation only
Fix from $1,950 2024-10-23
Unclassified HIGH 8.4
CVE-2024-43812

Kieback & Peter's DDC4000 series has an insufficiently protected credentials vulnerability, which may allow an unauthenticated attacker with access t…

Mitigation only
Fix from $1,950 2024-10-22
Uos HIGH 7.8
CVE-2024-9677

The insufficiently protected credentials vulnerability in the CLI command of the USG FLEX H series uOS firmware version V1.21 and earlier versions co…

Fix: 1.30+
Fix from $1,950 2024-10-22
Litespeed Cache CRITICAL 9.8
CVE-2024-44000EPSS 82%

Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Authentication Bypass.This issue …

Fix: 6.5.0.1+
Fix from $2,300 2024-10-20
Unclassified HIGH 8.2
CVE-2024-7755

The EWON FLEXY 202 transmits credentials using a weak encoding method base64. An attacker who is present in the network can sniff the traffic and dec…

Mitigation only
Fix from $1,950 2024-10-17
Unclassified HIGH 8.7
CVE-2024-49396

The affected product is vulnerable due to insufficiently protected credentials, which may allow an attacker to impersonate Elvaco and send false info…

Mitigation only
Fix from $1,950 2024-10-17
Ata 191 Firmware MEDIUM 5.5
CVE-2024-20462

A vulnerability in the web-based management interface of Cisco ATA 190 Series Multiplatform Analog Telephone Adapter firmware could allow an authenti…

Fix: 11.2.5 / 12.0.2+
Fix from $1,600 2024-10-16
Teamcity MEDIUM 6.5
CVE-2024-47161

In JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST API

Fix: 2024.07.3+
Fix from $1,600 2024-10-08
Credentials HIGH 7.5
CVE-2024-47805

Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentials using…

Fix: 1371.1373.v4eb_fa_b_7161e9 / 1380.va_435002fa_924+
Fix from $1,950 2024-10-02
Adam 5630 Firmware MEDIUM 5.7
CVE-2024-34542

Advantech ADAM-5630 shares user credentials plain text between the device and the user source device during the login process.

Fix: 2.5.2+
Fix from $1,600 2024-09-27
Adam 5550 Firmware MEDIUM 5.7
CVE-2024-37187

Advantech ADAM-5550 share user credentials with a low level of encryption, consisting of base 64 encoding.

Mitigation only
Fix from $1,600 2024-09-27
Pgadmin 4 MEDIUM 6.5
CVE-2024-9014EPSS 10%

pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially ob…

Fix: 8.12+
Fix from $1,600 2024-09-23
Cognos Analytics MEDIUM 5.5
CVE-2024-40703

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and IBM Cognos Analytics Reports for iOS 11.0.0.7 could …

Fix: 12.0.3+
Fix from $1,600 2024-09-22
Youtrack MEDIUM 5.3
CVE-2024-47162

In JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports page

Fix: 2024.3.44799+
Fix from $1,600 2024-09-19
Unclassified CRITICAL 9.1
CVE-2024-8986

The grafana plugin SDK bundles build metadata into the binaries it compiles; this metadata includes the repository URI for the plugin being built, as…

Mitigation only
Fix from $2,300 2024-09-19
Omflow HIGH 7.5
CVE-2024-8777

OMFLOW from The SYSCOM Group has an information leakage vulnerability, allowing unauthorized remote attackers to read arbitrary system configurations…

Fix: 1.2.1.3+
Fix from $1,950 2024-09-16
Foreseer Electrical Power Monitoring System HIGH 8.1
CVE-2024-31415

The Eaton Foreseer software provides the feasibility for the user to configure external servers for multiple purposes such as network management, use…

Fix: 7.8.600+
Fix from $1,950 2024-09-13