Vulnerability index

Browse CVEs

1,244 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
Unclassified HIGH 8.5
CVE-2024-28981

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.8, including 8.3.x, discloses database passwords when searchi…

Mitigation only
Fix from $1,950 2024-09-12
Ios Xr MEDIUM 5.5
CVE-2024-20489

A vulnerability in the storage method of the PON Controller configuration file could allow an authenticated, local attacker with low privileges to ob…

Mitigation only
Fix from $1,600 2024-09-11
Veeam Backup \& Replication HIGH 8.8
CVE-2024-40710

A series of related high-severity vulnerabilities, the most notable enabling remote code execution (RCE) as the service account and extraction of sen…

Fix: 12.2.0.334+
Fix from $1,950 2024-09-07
Unclassified HIGH 8.8
CVE-2023-49233

Insufficient access checks in Visual Planning Admin Center 8 before v.1 Build 240207 allow attackers in possession of a non-administrative Visual Pla…

No fix yet
Fix from $1,950 2024-09-03
Gncc C2 Firmware MEDIUM 6.8
CVE-2024-31800

Authentication Bypass in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to gain a privileged command shell via the U…

No fix yet
Fix from $1,600 2024-08-15
Prison Management System HIGH 7.5
CVE-2024-7813

A vulnerability, which was classified as problematic, has been found in SourceCodester Prison Management System 1.0. This issue affects some unknown …

No fix yet
Fix from $1,950 2024-08-15
Workplace Desktop MEDIUM 6.5
CVE-2024-39818

Protection mechanism failure for some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct information disclosure via network acce…

Fix: 5.17.13 / 6.0.0+
Fix from $1,600 2024-08-14
Zabbix HIGH 8.1
CVE-2024-36460

The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain text.

Fix: after 6.4.15
Fix from $1,950 2024-08-12
Meetinghub Paperless Meetings CRITICAL 9.1
CVE-2024-6118

A Plaintext Storage of a Password vulnerability in ebooknote function in Hamastar MeetingHub Paperless Meetings 2021 allows remote attackers to obtai…

Mitigation only
Fix from $2,300 2024-08-05
Forminator HIGH 7.5
CVE-2024-7389

The Forminator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.29.1 via class-forminator…

Fix: 1.29.2+
Fix from $1,950 2024-08-02
Remote Desktop Manager HIGH 7.4
CVE-2024-6492

Exposure of Sensitive Information in edge browser session proxy feature in Devolutions Remote Desktop Manager 2024.2.14.0 and earlier on Windows allo…

Fix: 2024.2.15.0+
Fix from $1,950 2024-07-16
Datacap MEDIUM 5.5
CVE-2024-39733

IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 stores user credentials in plain clear text which can be read by a local user. IBM X-For…

Mitigation only
Fix from $1,600 2024-07-14
Unclassified HIGH 7.5
CVE-2024-38453

The Avalara for Salesforce CPQ app before 7.0 for Salesforce allows attackers to read an API key. NOTE: the current version is 11 as of mid-2024.

Mitigation only
Fix from $1,950 2024-07-03
Unclassified HIGH 8.8
CVE-2023-41926

The webserver utilizes basic authentication for its user login to the configuration interface. As encryption is disabled on port 80, it enables poten…

Mitigation only
Fix from $1,950 2024-07-02
Teamcity MEDIUM 5.3
CVE-2024-39878

In JetBrains TeamCity before 2024.03.3 private key could be exposed via testing GitHub App Connection

Fix: 2024.03.3+
Fix from $1,600 2024-07-01
Teamcity MEDIUM 5.3
CVE-2024-39879

In JetBrains TeamCity before 2024.03.3 application token could be exposed in EC2 Cloud Profile settings

Fix: 2024.03.3+
Fix from $1,600 2024-07-01
Youtrack HIGH 7.5
CVE-2024-38505

In JetBrains YouTrack before 2024.2.34646 user access token was sent to the third-party site

Fix: 2024.2.34646+
Fix from $1,950 2024-06-18
Unclassified HIGH 8.5
CVE-2024-38282

Utilizing default credentials, an attacker is able to log into the camera's operating system which could allow changes to be made to the operations o…

Mitigation only
Fix from $1,950 2024-06-13
Unclassified HIGH 7.0
CVE-2024-38285

Logs storing credentials are insufficiently protected and can be decoded through the use of open source tools.

Mitigation only
Fix from $1,950 2024-06-13
Unclassified MEDIUM 6.5
CVE-2024-26330

An issue was discovered in Kape CyberGhostVPN 8.4.3.12823 on Windows. After a successful logout, user credentials remain in memory while the process …

Mitigation only
Fix from $1,600 2024-06-11
Sinec Traffic Analyzer MEDIUM 5.5
CVE-2024-35208

A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server stored the password…

Fix: 1.2+
Fix from $1,600 2024-06-11
Aqua HIGH 7.5
CVE-2024-37051

GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 202…

Fix: 2023.1.3 / 2023.1.6+
Fix from $1,950 2024-06-10
Two Factor Authentication HIGH 8.1
CVE-2024-5657

The CraftCMS plugin Two-Factor Authentication in versions 3.3.1, 3.3.2 and 3.3.3 discloses the password hash of the currently authenticated user afte…

Fix: 3.3.4+
Fix from $1,950 2024-06-06
Unclassified HIGH 7.5
CVE-2024-36127

apko is an apk-based OCI image builder. apko exposures HTTP basic auth credentials from repository and keyring URLs in log output. This vulnerability…

Patch available
Fix from $1,950 2024-06-03
Unclassified CRITICAL 9.4
CVE-2024-5176

Insufficiently Protected Credentials vulnerability in Baxter Welch Allyn Configuration Tool may allow Remote Services with Stolen Credentials.This is…

Mitigation only
Fix from $2,300 2024-05-31
Unclassified MEDIUM 6.5
CVE-2024-33849

ci solution CI-Out-of-Office Manager through 6.0.0.77 uses a Hard-coded Cryptographic Key.

Mitigation only
Fix from $1,600 2024-05-28
Unclassified MEDIUM 5.5
CVE-2024-35192

Trivy is a security scanner. Prior to 0.51.2, if a malicious actor is able to trigger Trivy to scan container images from a crafted malicious registr…

Patch available
Fix from $1,600 2024-05-20
Unclassified CRITICAL 9.8
CVE-2024-36081

Westermo EDW-100 devices through 2024-05-03 allow an unauthenticated user to download a configuration file containing a cleartext password. NOTE: thi…

Mitigation only
Fix from $2,300 2024-05-19
Bigfix Platform MEDIUM 6.7
CVE-2024-23583

An attacker could potentially intercept credentials via the task manager and perform unauthorized access to the Client Deploy Tool on Windows systems.

Fix: 9.5.25 / 10.0.12+
Fix from $1,600 2024-05-17
Unclassified HIGH 7.6
CVE-2024-27109

Insufficiently protected credentials in GE HealthCare EchoPAC products

Mitigation only
Fix from $1,950 2024-05-14