Vulnerability index

Browse CVEs

1,244 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
Unclassified MEDIUM 6.3
CVE-2024-33497

A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT278…

Mitigation only
Fix from $1,600 2024-05-14
Unclassified MEDIUM 6.3
CVE-2024-33496

A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT278…

Mitigation only
Fix from $1,600 2024-05-14
Txseries For Multiplatform HIGH 7.5
CVE-2024-22345

IBM TXSeries for Multiplatforms 8.2 transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorize…

Mitigation only
Fix from $1,950 2024-05-14
Unclassified MEDIUM 6.5
CVE-2024-22266

 VMware Avi Load Balancer contains an information disclosure vulnerability. A malicious actor with access to the system logs can view cloud connectio…

Mitigation only
Fix from $1,600 2024-05-08
Unclassified MEDIUM 6.5
CVE-2024-23551

Database scanning using username and password stores the credentials in plaintext or encoded format within files at the endpoint. This has been ident…

Mitigation only
Fix from $1,600 2024-05-07
Edc Connector MEDIUM 5.3
CVE-2024-4536

In Eclipse Dataspace Components from version 0.2.1 to 0.6.2, in the EDC Connector component ( https://github.com/eclipse-edc/Connector ), an attacker…

Fix: 0.6.3+
Fix from $1,600 2024-05-07
Unclassified HIGH 8.0
CVE-2024-29941

Insecure storage of the ICT MIFARE and DESFire encryption keys in the firmware binary allows malicious actors to create credentials for any site code…

Mitigation only
Fix from $1,950 2024-05-06
Simple Editor HIGH 7.5
CVE-2023-40510

LG Simple Editor getServerSetting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affecte…

Mitigation only
Fix from $1,950 2024-05-03
Simple Editor HIGH 7.5
CVE-2023-40511

LG Simple Editor checkServer Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected ins…

Mitigation only
Fix from $1,950 2024-05-03
Loadmaster HIGH 7.5
CVE-2024-3543

Use of reversible password encryption algorithm allows attackers to decrypt passwords.  Sensitive information can be easily unencrypted by the attack…

Fix: 7.2.54.10 / 7.2.59.4+
Fix from $1,950 2024-05-02
Openmanage Enterprise HIGH 7.8
CVE-2024-28961

Dell OpenManage Enterprise, versions 4.0.0 and 4.0.1, contains a sensitive information disclosure vulnerability. A local low privileged malicious use…

Mitigation only
Fix from $1,950 2024-04-29
Unclassified MEDIUM 6.1
CVE-2024-28325

Asus RT-N12+ B1 router stores credentials in cleartext, which could allow local attackers to obtain unauthorized access and modify router settings.

Mitigation only
Fix from $1,600 2024-04-26
Unclassified CRITICAL 9.8
CVE-2024-32238EPSS 53%

H3C ER8300G2-X is vulnerable to Incorrect Access Control. The password for the router's management system can be accessed via the management system p…

Mitigation only
Fix from $2,300 2024-04-22
Aspera Faspex HIGH 7.8
CVE-2023-37400

IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to escalate their privileges due to insecure credential storage. IBM X-Force ID: 259…

Fix: 5.0.8+
Fix from $1,950 2024-04-19
Azure Identity Library For .net MEDIUM 5.5
CVE-2024-29992

Azure Identity Library for .NET Information Disclosure Vulnerability

Fix: 1.11.0+
Fix from $1,600 2024-04-09
Fortiproxy HIGH 8.8
CVE-2023-41677

A insufficiently protected credentials in Fortinet FortiProxy 7.4.0, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, 2.0.0 through 2.0.13, 1.2.0 through 1…

Fix: 6.2.16 / 6.4.15+
Fix from $1,950 2024-04-09
Nexus Dashboard MEDIUM 6.0
CVE-2024-20282

A vulnerability in Cisco Nexus Dashboard could allow an authenticated, local attacker with valid rescue-user credentials to elevate privileges to roo…

Fix: 3.1+
Fix from $1,600 2024-04-03
Unclassified MEDIUM 6.1
CVE-2024-29216

Exposed IOCTL with insufficient access control issue exists in cg6kwin2k.sys prior to 2.1.7.0. By sending a specific IOCTL request, a user without th…

Mitigation only
Fix from $1,600 2024-03-25
Unclassified HIGH 8.8
CVE-2024-29071

HGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network-adjacent unauthenticated attacker may change the system …

Mitigation only
Fix from $1,950 2024-03-25
Tg Firmware HIGH 7.5
CVE-2022-47037

Siklu TG Terragraph devices before 2.1.1 allow attackers to discover valid, randomly generated credentials via GetCredentials.

Fix: 2.1.1+
Fix from $1,950 2024-03-18
Host Access Transformation Services MEDIUM 5.5
CVE-2021-38938

IBM Host Access Transformation Services (HATS) 9.6 through 9.6.1.4 and 9.7 through 9.7.0.3 stores user credentials in plain clear text which can be r…

Fix: after 9.7.0.3
Fix from $1,600 2024-03-15
Hustle HIGH 8.6
CVE-2024-0368

The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up…

Fix: 7.8.4+
Fix from $1,950 2024-03-13
Go Sdk HIGH 7.5
CVE-2024-28110

Go SDK for CloudEvents is the official CloudEvents SDK to integrate applications with CloudEvents. Prior to version 2.15.2, using cloudevents.WithRou…

Fix: after 2.15.1
Fix from $1,950 2024-03-06
Command Centre MEDIUM 6.5
CVE-2024-21815

Insufficiently protected credentials (CWE-522) for third party DVR integrations to the Command Centre Server are accessible to authenticated but unpr…

Fix: 8.70.2526 / 8.80.1526+
Fix from $1,600 2024-03-05
Couchbase Server MEDIUM 5.3
CVE-2023-50436

An issue was discovered in Couchbase Server before 7.2.4. ns_server admin credentials are leaked in encoded form in the diag.log file. The earliest a…

Fix: 7.2.4+
Fix from $1,600 2024-02-29
Erp Xl MEDIUM 6.5
CVE-2023-4538

The database access credentials configured during installation are stored in a special table, and are encrypted with a shared key, same among all Com…

Fix: after 2023.2
Fix from $1,600 2024-02-15
Big Ip Next Cloud Native Network Functions HIGH 7.1
CVE-2024-23306

A vulnerability exists in BIG-IP Next CNF and SPK systems that may allow access to undisclosed sensitive files.  Note: Software versions which have r…

Fix: 1.2.0+
Fix from $1,950 2024-02-14
Ecostruxure Control Expert HIGH 7.1
CVE-2023-27975

CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause unauthorized access to the project file in EcoStruxure Control Ex…

Fix: 16.0 / 2023+
Fix from $1,950 2024-02-14
Openbmc MEDIUM 5.3
CVE-2023-32280

Insufficiently protected credentials in some Intel(R) Server Product OpenBMC firmware before versions egs-1.05 may allow an unauthenticated user to e…

Mitigation only
Fix from $1,600 2024-02-14
Storage Defender Resiliency Service MEDIUM 5.5
CVE-2024-22312

IBM Storage Defender - Resiliency Service 2.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 278748.

Patch available
Fix from $1,600 2024-02-10