Vulnerability index

Browse CVEs

1,246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
Delicia HIGH 7.5
CVE-2023-31824

An issue found in DERICIA Co. Ltd, DELICIA v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token in …

No fix yet
Fix from $1,950 2023-07-13
Analytics CRITICAL 9.8
CVE-2023-34128

Tomcat application credentials are hardcoded in SonicWall GMS and Analytics configuration file. This issue affects GMS: 9.3.2-SP1 and earlier version…

Fix: 9.3.2+
Fix from $2,300 2023-07-13
Mabl MEDIUM 6.5
CVE-2023-37951

Jenkins mabl Plugin 0.0.46 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission…

Fix: after 0.0.46
Fix from $1,600 2023-07-12
Keeper MEDIUM 5.5
CVE-2023-36266

An issue was discovered in Keeper Password Manager for Desktop version 16.10.2 (fixed in 17.2), and the KeeperFill Browser Extensions version 16.5.4 …

No fix yet
Fix from $1,600 2023-07-12
Windows Server 2016 MEDIUM 6.5
CVE-2023-35348

Active Directory Federation Service Security Feature Bypass Vulnerability

Patch available
Fix from $1,600 2023-07-11
Calamares Nixos Extensions MEDIUM 5.5
CVE-2023-36476

calamares-nixos-extensions provides Calamares branding and modules for NixOS, a distribution of GNU/Linux. Users of calamares-nixos-extensions versio…

Fix: 0.3.13+
Fix from $1,600 2023-06-29
Cmseasy HIGH 7.5
CVE-2020-18406

An issue was discovered in cmseasy v7.0.0 that allows user credentials to be sent in clear text due to no encryption of form data.

No fix yet
Fix from $1,950 2023-06-27
Central Authentication Service HIGH 7.5
CVE-2023-28857

Apereo CAS is an open source multilingual single sign-on solution for the web. Apereo CAS can be configured to use authentication based on client X50…

Fix: 6.5.9.1 / 6.6.6+
Fix from $1,950 2023-06-27
Rabbitmq C MEDIUM 5.5
CVE-2023-35789

An issue was discovered in the C AMQP client library (aka rabbitmq-c) through 0.13.0 for RabbitMQ. Credentials can only be entered on the command lin…

Fix: after 0.13.0
Fix from $1,600 2023-06-16
Alaris Infusion Central HIGH 7.3
CVE-2022-47376

The Alaris Infusion Central software, versions 1.1 to 1.3.2, may contain a recoverable password after the installation. No patient health data is sto…

Fix: after 1.3.2
Fix from $1,950 2023-06-13
Gl Ar750s Firmware MEDIUM 5.9
CVE-2023-33620

GL.iNET GL-AR750S-Ext firmware v3.215 uses an insecure protocol in its communications which allows attackers to eavesdrop via a man-in-the-middle att…

No fix yet
Fix from $1,600 2023-06-13
Fortisiem CRITICAL 9.8
CVE-2023-26204

A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 al…

Fix: after 6.7.5
Fix from $2,300 2023-06-13
Vuforia Studio HIGH 7.5
CVE-2023-29168

The local Vuforia web application does not support HTTPS, and federated credentials are passed via basic authentication.

Fix: 9.9+
Fix from $1,950 2023-06-07
Aspera Cargo HIGH 7.5
CVE-2023-22862

IBM Aspera Connect 4.2.5 and IBM Aspera Cargo 4.2.5 transmits authentication credentials, but it uses an insecure method that is susceptible to unaut…

Fix: 4.2.6+
Fix from $1,950 2023-06-05
Firefox HIGH 8.8
CVE-2023-25740

After downloading a Windows <code>.scf</code> script from the local filesystem, an attacker could supply a remote path that would lead to unexpected …

Fix: 110.0+
Fix from $1,950 2023-06-02
Ix Workforce Engagement MEDIUM 6.5
CVE-2023-31187

Avaya IX Workforce Engagement v15.2.7.1195 - CWE-522: Insufficiently Protected Credentials

No fix yet
Fix from $1,600 2023-05-30
Tgstation Server MEDIUM 6.5
CVE-2023-32687

tgstation-server is a toolset to manage production BYOND servers. Starting in version 4.7.0 and prior to 5.12.1, instance users with the list chat bo…

Fix: 5.12.1+
Fix from $1,600 2023-05-29
Wftpd HIGH 7.5
CVE-2023-33263

In WFTPD 3.25, usernames and password hashes are stored in an openly viewable wftpd.ini configuration file within the WFTPD directory. NOTE: this is …

No fix yet
Fix from $1,950 2023-05-25
Ij Network Tool MEDIUM 6.5
CVE-2023-1763

Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS …

Fix: after 4.7.5
Fix from $1,600 2023-05-17
Ns Nd Integration Performance Publisher HIGH 7.5
CVE-2023-33000

Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.149 and earlier does not mask credentials displayed on the configuration form, increasin…

Fix: after 4.8.0.149
Fix from $1,950 2023-05-16
Jedox MEDIUM 5.3
CVE-2022-47880

An Information disclosure vulnerability in /be/rpc.php in Jedox GmbH Jedox 2020.2.5 allow remote, authenticated users with permissions to modify data…

No fix yet
Fix from $1,600 2023-05-12
Data Center Manager MEDIUM 6.5
CVE-2022-40685

Insufficiently protected credentials in the Intel(R) DCM software before version 5.0.1 may allow an authenticated user to potentially enable informat…

Fix: 5.0.1+
Fix from $1,600 2023-05-10
Staros HIGH 8.8
CVE-2023-20046

A vulnerability in the key-based SSH authentication feature of Cisco StarOS Software could allow an authenticated, remote attacker to elevate privile…

Fix: 21.22.14 / 21.23.31+
Fix from $1,950 2023-05-09
Postgresnio MEDIUM 5.9
CVE-2023-31136

PostgresNIO is a Swift client for PostgreSQL. Any user of PostgresNIO prior to version 1.14.2 connecting to servers with TLS enabled is vulnerable to…

Fix: 1.14.2+
Fix from $1,600 2023-05-09
Businessobjects MEDIUM 5.9
CVE-2023-28764

SAP BusinessObjects Platform - versions 420, 430, Information design tool transmits sensitive information as cleartext in the binaries over the netwo…

Mitigation only
Fix from $1,600 2023-05-09
Ncr\/camera Firmware HIGH 7.5
CVE-2023-24506

Milesight NCR/camera version 71.8.0.6-r5 exposes credentials through an unspecified request.

Mitigation only
Fix from $1,950 2023-05-08
Surelock HIGH 7.5
CVE-2023-2335

Plaintext Password in Registry vulnerability in 42gears surelock windows surelockwinsetupv2.40.0.Exe on Windows (Registery modules) allows Retrieve…

Fix: after 2.40.0
Fix from $1,950 2023-04-27
Data Security Firewall Firmware CRITICAL 9.8
CVE-2023-1778

This vulnerability exists in GajShield Data Security Firewall firmware versions prior to v4.28 (except v4.21) due to insecure default credentials whi…

Fix: 4.21 / 4.28+
Fix from $2,300 2023-04-27
Typed Rest Client HIGH 7.5
CVE-2023-30846

typed-rest-client is a library for Node Rest and Http Clients with typings for use with TypeScript. Users of the typed-rest-client library version 1.…

Fix: 1.8.0+
Fix from $1,950 2023-04-26
Freepbx Linux 7 HIGH 8.1
CVE-2023-26567

Sangoma FreePBX 1805 through 2302 (when obtained as a ,.ISO file) places AMPDBUSER, AMPDBPASS, AMPMGRUSER, and AMPMGRPASS in the list of global varia…

Mitigation only
Fix from $1,950 2023-04-26