Vulnerability index

Browse CVEs

1,246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
Data Center Expert CRITICAL 9.8
CVE-2022-32518

A CWE-522: Insufficiently Protected Credentials vulnerability exists that could result in unwanted access to a DCE instance when performed over a net…

Fix: 7.9.0+
Fix from $2,300 2023-01-30
Data Center Expert CRITICAL 9.8
CVE-2022-32519

A CWE-257: Storing Passwords in a Recoverable Format vulnerability exists that could result in unwanted access to a DCE instance when performed over …

Fix: 7.9.0+
Fix from $2,300 2023-01-30
Data Center Expert CRITICAL 9.8
CVE-2022-32520

A CWE-522: Insufficiently Protected Credentials vulnerability exists that could result in unwanted access to a DCE instance when performed over a net…

Fix: 7.9.0+
Fix from $2,300 2023-01-30
Revenue Collection System CRITICAL 9.8
CVE-2022-46967

An access control issue in Revenue Collection System v1.0 allows unauthenticated attackers to view the contents of /admin/DBbackup/ directory.

No fix yet
Fix from $2,300 2023-01-26
User Verification CRITICAL 9.8
CVE-2022-4693

The User Verification WordPress plugin before 1.0.94 was affected by an Auth Bypass security vulnerability. To bypass authentication, we only need to…

Fix: 1.0.94+
Fix from $2,300 2023-01-23
Proficy Historian HIGH 7.5
CVE-2022-38469

An unauthorized user with network access and the decryption key could decrypt sensitive data, such as usernames and passwords.

Fix: 2023+
Fix from $1,950 2023-01-18
Singularity Container Services Library HIGH 7.6
CVE-2022-23538

github.com/sylabs/scs-library-client is the Go client for the Singularity Container Services (SCS) Container Library Service. When the scs-library-cl…

Patch available
Fix from $1,950 2023-01-17
Freeradius HIGH 7.5
CVE-2022-41859

In freeradius, the EAP-PWD function compute_password_element() leaks information about the password which allows an attacker to substantially reduce …

Fix: 3.0.0+
Fix from $1,950 2023-01-17
Metasys Application And Data Server HIGH 7.5
CVE-2021-36204

Under some circumstances an Insufficiently Protected Credentials vulnerability in Johnson Controls Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 an…

Fix: 10.1.6 / 11.0.3+
Fix from $1,950 2023-01-13
Theme Cesnet MEDIUM 5.5
CVE-2016-15014

A vulnerability has been found in CESNET theme-cesnet up to 1.x on ownCloud and classified as problematic. Affected by this vulnerability is an unkno…

Fix: 2.0.0+
Fix from $1,600 2023-01-07
Ua Modbus Server HIGH 7.5
CVE-2022-2967

Prosys OPC UA Simulation Server version prior to v5.3.0-64 and UA Modbus Server versions 1.4.18-5 and prior do not sufficiently protect credentials, …

Fix: 1.4.20 / 5.4.0+
Fix from $1,950 2023-01-03
Security Verify Governance MEDIUM 6.5
CVE-2022-22458

IBM Security Verify Governance, Identity Manager 10.0.1 stores user credentials in plain clear text which can be read by a remote authenticated user.…

Patch available
Fix from $1,600 2022-12-22
Passwordstate MEDIUM 6.5
CVE-2022-4612

A vulnerability has been found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome and classified as problematic. This vulnerab…

Fix: 9.5+
Fix from $1,600 2022-12-19
Ruggedcom Rm1224 Lte\(4g\) Eu Firmware MEDIUM 5.7
CVE-2022-46142

Affected devices store the CLI user passwords encrypted in flash memory. Attackers with physical access to the device could retrieve the file and dec…

Mitigation only
Fix from $1,600 2022-12-13
Pcvue MEDIUM 5.5
CVE-2022-4312

A cleartext storage of sensitive information vulnerability exists in PcVue versions 8.10 through 15.2.3. This could allow an unauthorized user with a…

Fix: after 15.2.3
Fix from $1,600 2022-12-12
My Cloud Os MEDIUM 5.5
CVE-2022-29839

Insufficiently Protected Credentials vulnerability in the remote backups application on Western Digital My Cloud devices that could allow an attacker…

Fix: 5.25.124+
Fix from $1,600 2022-12-09
Craft Cms HIGH 7.5
CVE-2022-37783

All Craft CMS versions between 3.0.0 and 3.7.32 disclose password hashes of users who authenticate using their E-Mail address or username in Anti-CSR…

Fix: after 3.7.32
Fix from $1,950 2022-12-05
Airtable MEDIUM 6.4
CVE-2022-46155

Airtable.js is the JavaScript client for Airtable. Prior to version 0.11.6, Airtable.js had a misconfigured build script in its source package. When …

Fix: 0.11.6+
Fix from $1,600 2022-11-29
Maximo Application Suite MEDIUM 5.5
CVE-2022-41732

IBM Maximo Mobile 8.7 and 8.8 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 237407.

Mitigation only
Fix from $1,600 2022-11-28
Gx Works3 MEDIUM 6.5
CVE-2022-29833

Insufficiently Protected Credentials vulnerability in Mitsubishi Electric Corporation GX Works3 versions 1.015R and later allows a remote unauthentic…

Fix: after 1.086q
Fix from $1,600 2022-11-25
Xwiki MEDIUM 6.5
CVE-2022-41933

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When the `reset a forgotten password` featur…

Fix: 13.10.8 / 14.4.3+
Fix from $1,600 2022-11-23
Ns Nd Integration Performance Publisher MEDIUM 6.5
CVE-2022-45392

Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier stores passwords unencrypted in job config.xml files on the Jenkins cont…

Fix: 4.8.0.146+
Fix from $1,600 2022-11-15
Reverse Proxy Auth MEDIUM 6.5
CVE-2022-45384

Jenkins Reverse Proxy Auth Plugin 1.7.3 and earlier stores the LDAP manager password unencrypted in the global config.xml file on the Jenkins control…

Fix: 1.7.4+
Fix from $1,600 2022-11-15
Camp CRITICAL 9.8
CVE-2022-37109EPSS 49%

patrickfuller camp up to and including commit bbd53a256ed70e79bd8758080936afbf6d738767 is vulnerable to Incorrect Access Control. Access to the passw…

Fix: 2022-07-21+
Fix from $2,300 2022-11-14
Active Management Technology Software Development Kit HIGH 8.8
CVE-2022-26341

Insufficiently protected credentials in software in Intel(R) AMT SDK before version 16.0.4.1, Intel(R) EMA before version 1.7.1 and Intel(R) MC befor…

Fix: 1.7.1 / 2.3.2+
Fix from $1,950 2022-11-11
Upsmon Pro MEDIUM 6.5
CVE-2022-38121

UPSMON PRO configuration file stores user password in plaintext under public user directory. A remote attacker with general user privilege can access…

Mitigation only
Fix from $1,600 2022-11-10
Electron MEDIUM 6.1
CVE-2022-36077

The Electron framework enables writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions prior to 21.0.0-beta.1, 20.0.1…

Fix: 18.3.7 / 19.0.11+
Fix from $1,600 2022-11-08
Devolutions Server MEDIUM 6.5
CVE-2022-3781

Dashlane password and Keepass Server password in My Account Settings  are not encrypted in the database in Devolutions Remote Desktop Manager 2022.2.…

Fix: 2022.2.27 / 2022.3.2+
Fix from $1,600 2022-11-01
Ansible Automation Platform MEDIUM 5.5
CVE-2022-3644

The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the…

No fix yet
Fix from $1,600 2022-10-25
Enterprise HIGH 7.5
CVE-2022-41575

A credential-exposure vulnerability in the support-bundle mechanism in Gradle Enterprise 2022.3 through 2022.3.3 allows remote attackers to access a …

Fix: 2022.3.3+
Fix from $1,950 2022-10-21