Vulnerability index

Browse CVEs

1,244 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
Easysoft MEDIUM 6.5
CVE-2023-43777

Eaton easySoft software is used to program easy controllers and displays for configuring, programming and defining parameters for all the intelligent…

Fix: 8.01+
Fix from $1,600 2023-10-17
Snapgathers MEDIUM 5.5
CVE-2023-27315

SnapGathers versions prior to 4.9 are susceptible to a vulnerability which could allow a local authenticated attacker to discover plaintext domain …

Fix: 4.9+
Fix from $1,600 2023-10-12
Bigfix Insights For Vulnerability Remediation HIGH 8.2
CVE-2022-44757

BigFix Insights for Vulnerability Remediation (IVR) uses weak cryptography that can lead to credential exposure. An attacker could gain access to se…

Fix: 2.0.3+
Fix from $1,950 2023-10-11
Bigfix Insights For Vulnerability Remediation MEDIUM 5.3
CVE-2022-44758

BigFix Insights/IVR fixlet uses improper credential handling within certain fixlet content. An attacker can gain access to information that is not e…

Fix: 2.0.3+
Fix from $1,600 2023-10-11
Cyber Protect HIGH 7.5
CVE-2023-44158

Sensitive information disclosure due to insufficient token field masking. The following products are affected: Acronis Cyber Protect 15 (Linux, Windo…

Fix: 15+
Fix from $1,950 2023-09-27
Openstack Platform MEDIUM 5.5
CVE-2023-1633

A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining acce…

Mitigation only
Fix from $1,600 2023-09-24
Eve HIGH 8.8
CVE-2023-43633

On boot, the Pillar eve container checks for the existence and content of “/config/GlobalConfig/global.json”. If the file exists, it overrides the e…

Fix: 8.6.0 / 9.5.0+
Fix from $1,950 2023-09-21
Eve HIGH 8.8
CVE-2023-43634

When sealing/unsealing the “vault” key, a list of PCRs is used, which defines which PCRs are used. In a previous project, CYMOTIVE found that the co…

Fix: 8.6.0 / 9.5.0+
Fix from $1,950 2023-09-21
Edge Virtualization Engine HIGH 8.8
CVE-2023-43631

On boot, the Pillar eve container checks for the existence and content of “/config/authorized_keys”. If the file is present, and contains a supporte…

Fix: 8.6.0 / 9.5.0+
Fix from $1,950 2023-09-21
Edge Virtualization Engine HIGH 8.8
CVE-2023-43630

PCR14 is not in the list of PCRs that seal/unseal the “vault” key, but due to the change that was implemented in commit “7638364bc0acf8b5c481b5ce5fea…

Fix: 9.5.0+
Fix from $1,950 2023-09-20
Edge Virtualization Engine HIGH 8.8
CVE-2023-43635

Vault Key Sealed With SHA1 PCRs The measured boot solution implemented in EVE OS leans on a PCR locking mechanism. Different parts of the syst…

Fix: 9.5.0+
Fix from $1,950 2023-09-20
Ekorccp Firmware MEDIUM 5.5
CVE-2022-47561

The web application stores credentials in clear text in the "admin.xml" file, which can be accessed without logging into the website, which could all…

Mitigation only
Fix from $1,600 2023-09-20
Dgx H100 Firmware CRITICAL 9.8
CVE-2023-25531

NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause insufficient protection of credentials. A successful exploit of thi…

Fix: 23.08.18+
Fix from $2,300 2023-09-20
Dgx H100 Firmware HIGH 7.5
CVE-2023-25532

NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause insufficient protection of credentials. A successful exploit of thi…

Fix: 23.08.18+
Fix from $1,950 2023-09-20
Tewa 700g Firmware MEDIUM 5.5
CVE-2023-41010

Insecure Permissions vulnerability in Sichuan Tianyi Kanghe Communication Co., Ltd China Telecom Tianyi Home Gateway v.TEWA-700G allows a local attac…

No fix yet
Fix from $1,600 2023-09-14
Sterling External Authentication Server MEDIUM 5.5
CVE-2023-32338

IBM Sterling Secure Proxy and IBM Sterling External Authentication Server 6.0.3 and 6.1.0 stores user credentials in plain clear text which can be re…

Mitigation only
Fix from $1,600 2023-09-05
Pharmahelp Firmware CRITICAL 9.8
CVE-2022-45611

An issue was discovered in Fresenius Kabi PharmaHelp 5.1.759.0 allows attackers to gain escalated privileges via via capture of user login informatio…

Mitigation only
Fix from $2,300 2023-08-22
Social Media Skeleton HIGH 7.5
CVE-2023-40173

Social media skeleton is an uncompleted/framework social media project implemented using a php, css ,javascript and html. Prior to version 1.0.5 Soci…

Fix: 1.0.5+
Fix from $1,950 2023-08-18
Manageengine Admanager Plus MEDIUM 6.5
CVE-2023-31492EPSS 8%

Zoho ManageEngine ADManager Plus version 7182 and prior disclosed the default passwords for the account restoration of unauthorized domains to the au…

Fix: 7.1+
Fix from $1,600 2023-08-17
Maven Artifact Choicelistprovider \(nexus\) MEDIUM 6.5
CVE-2023-40347

Jenkins Maven Artifact ChoiceListProvider (Nexus) Plugin 1.14 and earlier does not set the appropriate context for credentials lookup, allowing attac…

Fix: after 1.14
Fix from $1,600 2023-08-16
Delphix MEDIUM 6.5
CVE-2023-40345

Jenkins Delphix Plugin 3.0.2 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Overall/Read permission…

Fix: after 3.0.2
Fix from $1,600 2023-08-16
Raid Controller Web Interface MEDIUM 5.5
CVE-2023-4327

Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user …

Mitigation only
Fix from $1,600 2023-08-15
Raid Controller Web Interface MEDIUM 5.5
CVE-2023-4328

Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user…

Mitigation only
Fix from $1,600 2023-08-15
Android CRITICAL 9.8
CVE-2023-20965

In processMessageImpl of ClientModeImpl.java, there is a possible credential disclosure in the TOFU flow due to a logic error in the code. This could…

Patch available
Fix from $2,300 2023-08-14
Flexiva Fax 150w Firmware CRITICAL 9.8
CVE-2023-36082

An isssue in GatesAIr Flexiva FM Transmitter/Exiter Fax 150W allows a remote attacker to gain privileges via the LDAP and SMTP credentials.

Mitigation only
Fix from $2,300 2023-08-03
Chrome MEDIUM 6.5
CVE-2022-4926

Insufficient policy enforcement in Intents in Google Chrome on Android prior to 109.0.5414.119 allowed a remote attacker to bypass same origin policy…

Fix: 109.0.5414.119+
Fix from $1,600 2023-07-29
E Invoice Approval System HIGH 7.5
CVE-2023-35067

Plaintext Storage of a Password vulnerability in Infodrom Software E-Invoice Approval System allows Read Sensitive Strings Within an Executable. Thi…

Fix: 20230701+
Fix from $1,950 2023-07-25
Weincloud HIGH 8.8
CVE-2023-37362

Weintek Weincloud v0.13.6 could allow an attacker to abuse the registration functionality to login with testing credentials to the official websi…

Mitigation only
Fix from $1,950 2023-07-19
Delicia HIGH 7.5
CVE-2023-31824

An issue found in DERICIA Co. Ltd, DELICIA v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token in …

No fix yet
Fix from $1,950 2023-07-13
Analytics CRITICAL 9.8
CVE-2023-34128

Tomcat application credentials are hardcoded in SonicWall GMS and Analytics configuration file. This issue affects GMS: 9.3.2-SP1 and earlier version…

Fix: 9.3.2+
Fix from $2,300 2023-07-13