Vulnerability index

Browse CVEs

1,244 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
Solr HIGH 7.5
CVE-2023-50291

Insufficiently Protected Credentials vulnerability in Apache Solr. This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.3.…

Fix: 8.11.3 / 9.3.0+
Fix from $1,950 2024-02-09
Clearml HIGH 7.1
CVE-2024-24595

Allegro AI’s open-source version of ClearML stores passwords in plaintext within the MongoDB instance, resulting in a compromised server leaking all …

Mitigation only
Fix from $1,950 2024-02-05
Rapid Scada MEDIUM 5.5
CVE-2024-21869

In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the affected product stores plaintext credentials in various places. This may al…

Fix: after 5.8.4
Fix from $1,600 2024-02-02
Kylin HIGH 7.5
CVE-2023-29055

In Apache Kylin version 2.0.0 to 4.0.3, there is a Server Config web interface that displays the content of file 'kylin.properties', that may contain…

Fix: 4.0.4+
Fix from $1,950 2024-01-29
Networker MEDIUM 6.5
CVE-2024-22432

Networker 19.9 and all prior versions contains a Plain-text Password stored in temporary config file during backup duration in NMDA MySQL Database ba…

Fix: after 19.9
Fix from $1,600 2024-01-25
Oneview MEDIUM 5.5
CVE-2023-6573

HPE OneView may have a missing passphrase during restore.

Fix: 8.70+
Fix from $1,600 2024-01-23
Device Manager HIGH 7.5
CVE-2023-49106

Missing Password Field Masking vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Agent component).This issue affects Hitachi …

Fix: 8.8.5-04+
Fix from $1,950 2024-01-16
Alarm System MEDIUM 5.9
CVE-2023-50125

A default engineer password set on the Hozard alarm system (Alarmsysteem) v1.0 allows an attacker to bring the alarm system to a disarmed state.

Mitigation only
Fix from $1,600 2024-01-11
Kepware Kepserverex MEDIUM 5.3
CVE-2023-29447

An insufficiently protected credentials vulnerability in KEPServerEX could allow an adversary to capture user credentials as the web server uses basi…

Fix: after 8.5
Fix from $1,600 2024-01-10
Download Manager HIGH 7.5
CVE-2023-6421

The Download Manager WordPress plugin before 3.2.83 does not protect file download's passwords, leaking it upon receiving an invalid one.

Fix: 3.2.83+
Fix from $1,950 2024-01-01
Network Functions Manager For Transport MEDIUM 6.5
CVE-2022-39820

In Network Element Manager in NOKIA NFM-T R19.9, an Unprotected Storage of Credentials vulnerability occurs under /root/RestUploadManager.xml.DRC and…

No fix yet
Fix from $1,600 2023-12-25
Db2 Mirror For I MEDIUM 5.3
CVE-2023-47741

IBM i 7.3, 7.4, 7.5, IBM i Db2 Mirror for i 7.4 and 7.5 web browser clients may leave clear-text passwords in browser memory that can be viewed using…

Patch available
Fix from $1,600 2023-12-18
Openid MEDIUM 6.7
CVE-2023-50770

Jenkins OpenId Connect Authentication Plugin 2.6 and earlier stores a password of a local user account used as an anti-lockout feature in a recoverab…

Fix: after 2.6
Fix from $1,600 2023-12-13
Rely Pcie Firmware CRITICAL 9.8
CVE-2023-47577

An issue discovered in Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 allows for unauthorized password changes due to no check for current password.

Mitigation only
Fix from $2,300 2023-12-13
Opencast HIGH 7.5
CVE-2018-16153

An issue was discovered in Apereo Opencast 4.x through 10.x before 10.6. It sends system digest credentials during authentication attempts to arbitra…

Fix: 10.6+
Fix from $1,950 2023-12-12
Api Connect MEDIUM 5.5
CVE-2023-47722

IBM API Connect V10.0.5.3 and V10.0.6.0 stores user credentials in browser cache which can be read by a local user. IBM X-Force ID: 271912.

Mitigation only
Fix from $1,600 2023-12-09
Filr HIGH 7.2
CVE-2023-32268

Exposure of Proxy Administrator Credentials An authenticated administrator equivalent Filr user can access the credentials of proxy administrators.

Fix: 23.2.1+
Fix from $1,950 2023-12-06
Change Request MEDIUM 6.5
CVE-2023-49280

XWiki Change Request is an XWiki application allowing to request changes on a wiki without publishing directly the changes. Change request allows to …

Fix: 1.10+
Fix from $1,600 2023-12-04
Ac21000 G6 Firmware MEDIUM 6.8
CVE-2023-24047

An Insecure Credential Management issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges via use of w…

Mitigation only
Fix from $1,600 2023-12-04
Powerprotect Data Manager Dm5500 Firmware MEDIUM 5.5
CVE-2023-44300

Dell DM5500 5.14.0.0, contain a Plain-text Password Storage Vulnerability in the appliance. A local attacker with privileges could potentially exploi…

Fix: after 5.14.0.0
Fix from $1,600 2023-12-04
Jira MEDIUM 6.5
CVE-2023-49653

Jenkins Jira Plugin 3.11 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission t…

Fix: after 3.11
Fix from $1,600 2023-11-29
Otrs HIGH 7.5
CVE-2023-6254

A Vulnerability in OTRS AgentInterface and ExternalInterface allows the reading of plain text passwords which are send back to the client in the serv…

Fix: after 8.0.37
Fix from $1,950 2023-11-27
Rvtools HIGH 7.5
CVE-2023-44303

RVTools, Version 3.9.2 and above, contain a sensitive data exposure vulnerability in the password encryption utility (RVToolsPasswordEncryption.exe) …

Fix: 4.5.0+
Fix from $1,950 2023-11-24
Fortisiem MEDIUM 6.5
CVE-2023-41676

An exposure of sensitive information to an unauthorized actor [CWE-200] in FortiSIEM version 7.0.0 and before 6.7.5 may allow an attacker with acces…

Fix: after 6.7.5
Fix from $1,600 2023-11-14
Ucs\@school MEDIUM 6.5
CVE-2020-17477

Incorrect LDAP ACLs in ucs-school-ldap-acls-master in UCS@school before 4.4v5-errata allow remote teachers, staff, and school administrators to read …

Fix: after 4.4
Fix from $1,600 2023-10-26
Writercms HIGH 7.5
CVE-2023-43905

Incorrect access control in writercms v1.1.0 allows attackers to directly obtain backend account passwords via unspecified vectors.

Mitigation only
Fix from $1,950 2023-10-26
Warnings MEDIUM 6.5
CVE-2023-46651

Jenkins Warnings Plugin 10.5.0 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permis…

Fix: after 10.5.0
Fix from $1,600 2023-10-25
Tauri MEDIUM 5.5
CVE-2023-46115

Tauri is a framework for building binaries for all major desktop platforms. This advisory is not describing a vulnerability in the Tauri code base it…

Fix: 2.0.0+
Fix from $1,600 2023-10-20
Firewall HIGH 7.5
CVE-2023-5552

A password disclosure vulnerability in the Secure PDF eXchange (SPX) feature allows attackers with full email access to decrypt PDFs in Sophos Firewa…

Fix: after 19.5.3
Fix from $1,950 2023-10-18
Tsplus Remote Work CRITICAL 9.8
CVE-2023-27132

TSplus Remote Work 16.0.0.0 places a cleartext password on the "var pass" line of the HTML source code for the secure single sign-on web portal. NOTE…

Fix: after 16.0.0.0
Fix from $2,300 2023-10-17