Vulnerability index

Browse CVEs

1,246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
Oneview MEDIUM 5.5
CVE-2023-28084

HPE OneView and HPE OneView Global Dashboard appliance dumps may expose authentication tokens

Fix: 2.72 / 6.60.04+
Fix from $1,600 2023-04-25
Oneview MEDIUM 5.5
CVE-2023-28086

An HPE OneView appliance dump may expose proxy credential settings

Fix: 6.60.04 / 8.2+
Fix from $1,600 2023-04-25
Oneview MEDIUM 5.5
CVE-2023-28087

An HPE OneView appliance dump may expose OneView user accounts

Fix: 6.60.04 / 8.2+
Fix from $1,600 2023-04-25
Oneview HIGH 7.8
CVE-2023-28088

An HPE OneView appliance dump may expose SAN switch administrative credentials

Fix: 6.60.04 / 8.2+
Fix from $1,950 2023-04-25
Oneview HIGH 7.1
CVE-2023-28089

An HPE OneView appliance dump may expose FTP credentials for c7000 Interconnect Modules

Fix: 6.60.04 / 8.2+
Fix from $1,950 2023-04-25
Oneview MEDIUM 5.5
CVE-2023-28090

An HPE OneView appliance dump may expose SNMPv3 read credentials

Fix: 6.60.04 / 8.2+
Fix from $1,600 2023-04-25
Superset MEDIUM 6.5
CVE-2023-30776

An authenticated user with specific data permissions could access database connections stored passwords by requesting a specific REST API. This issue…

Fix: after 2.0.1
Fix from $1,600 2023-04-24
Expo Software Development Kit CRITICAL 9.6
CVE-2023-28131EPSS 23%

A vulnerability in the expo.io framework allows an attacker to take over accounts and steal credentials on an application/website that configured the…

Fix: 48.0.0+
Fix from $2,300 2023-04-24
Rnp HIGH 7.5
CVE-2021-33589

Ribose RNP before 0.15.1 does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than on the tin of the algor…

Fix: 0.15.1+
Fix from $1,950 2023-04-21
Tripleplay HIGH 8.8
CVE-2023-25760

Incorrect Access Control in Tripleplay Platform releases prior to Caveman 3.4.0 allows authenticated user to modify other users passwords via a craft…

Mitigation only
Fix from $1,950 2023-04-19
Gatemanager HIGH 8.8
CVE-2022-4308

Plaintext Storage of a Password vulnerability in Secomea GateManager (USB wizard) allows Authentication abuse on SiteManager, if the generated file i…

Fix: 10.0.622425017+
Fix from $1,950 2023-04-19
Pe8108 Firmware HIGH 7.2
CVE-2023-25407

Aten PE8108 2.4.232 is vulnerable to Incorrect Access Control. Restricted users have read access to administrator credentials.

No fix yet
Fix from $1,950 2023-04-11
Pe8108 Firmware HIGH 7.5
CVE-2023-25413

Aten PE8108 2.4.232 is vulnerable to Incorrect Access Control. The device allows unauthenticated access to Telnet and SNMP credentials.

No fix yet
Fix from $1,950 2023-04-11
Remote Desktop Manager MEDIUM 6.5
CVE-2023-1574

Information disclosure in the user creation feature of a MSSQL data source in Devolutions Remote Desktop Manager 2023.1.9 and below on Windows allows…

Fix: 2023.1.10+
Fix from $1,600 2023-04-02
Intellij Idea HIGH 7.5
CVE-2022-48433

In JetBrains IntelliJ IDEA before 2023.1 the NTLM hash could leak through an API method used in the IntelliJ IDEA built-in web server.

Fix: 2023.1+
Fix from $1,950 2023-03-29
Kvms Pro HIGH 7.5
CVE-2023-1518

CP Plus KVMS Pro versions 2.01.0.T.190521 and prior are vulnerable to sensitive credentials being leaked because they are insufficiently protected.…

Fix: after 2.01.0.t.190521
Fix from $1,950 2023-03-28
Infrasuite Device Master HIGH 8.8
CVE-2023-1137

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which a low-level user could extract files and plaintex…

Fix: 1.0.5+
Fix from $1,950 2023-03-27
Security Key Lifecycle Manager MEDIUM 5.5
CVE-2023-25686

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 stores user credentials in plain clear text which can be read by a local …

Patch available
Fix from $1,600 2023-03-21
Fx5uc 32mr\/ds Ts Firmware HIGH 7.5
CVE-2023-0457

Plaintext Storage of a Password vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series, MELSEC iQ-R Series, MELSEC-Q Series and MELSEC-L…

Mitigation only
Fix from $1,950 2023-03-03
Wmb250ac Firmware CRITICAL 9.8
CVE-2022-45599

Aztech WMB250AC Mesh Routers Firmware Version 016 2020 is vulnerable to PHP Type Juggling in file /var/www/login.php, allows attackers to gain escala…

No fix yet
Fix from $2,300 2023-02-22
On Event Series MEDIUM 5.5
CVE-2022-41614

Insufficiently protected credentials in the Intel(R) ON Event Series Android application before version 2.0 may allow an authenticated user to potent…

Fix: 2.0+
Fix from $1,600 2023-02-16
Fortinac HIGH 7.8
CVE-2022-40678

An insufficiently protected credentials in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 th…

Fix: after 9.2.5
Fix from $1,950 2023-02-16
Mp C307 Firmware CRITICAL 9.1
CVE-2022-43969

Ricoh mp_c4504ex devices with firmware 1.06 mishandle credentials.

Fix: after 1.20
Fix from $2,300 2023-02-16
Prosafe Fs726tp Firmware HIGH 7.5
CVE-2023-24498

An uspecified endpoint in the web server of the switch does not properly authenticate the user identity, and may allow downloading a config page with…

Mitigation only
Fix from $1,950 2023-02-15
Sn Xvr3804e1 Firmware HIGH 7.5
CVE-2023-23463

Sunell DVR, latest version, Insufficiently Protected Credentials (CWE-522) may be exposed through an unspecified request.

Mitigation only
Fix from $1,950 2023-02-15
Media Control Panel HIGH 7.5
CVE-2023-23466

Media CP Media Control Panel latest version. Insufficiently protected credential change.

No fix yet
Fix from $1,950 2023-02-15
Megarac Sp X HIGH 7.5
CVE-2023-25191

AMI MegaRAC SPX devices allow Password Disclosure through Redfish. The fixed versions are SPx_12-update-7.00 and SPx_13-update-5.00.

Mitigation only
Fix from $1,950 2023-02-15
Hawk MEDIUM 6.5
CVE-2022-41564

The Hawk Console component of TIBCO Software Inc.'s TIBCO Hawk and TIBCO Operational Intelligence Hawk RedTail contains a vulnerability that will ret…

Fix: 6.2.2 / 7.2.1+
Fix from $1,600 2023-02-14
Redpanda MEDIUM 5.5
CVE-2023-24619

Redpanda before 22.3.12 discloses cleartext AWS credentials. The import functionality in the rpk binary logs an AWS Access Key ID and Secret in clear…

Fix: 22.1.12 / 22.2.10+
Fix from $1,600 2023-02-13
Driver Distributor HIGH 7.5
CVE-2022-43460

Driver Distributor v2.2.3.1 and earlier contains a vulnerability where passwords are stored in a recoverable format. If an attacker obtains a configu…

Fix: after 2.2.3.1
Fix from $1,950 2023-02-13