Vulnerability index

Browse CVEs

1,246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
Katalon MEDIUM 6.5
CVE-2022-43419

Jenkins Katalon Plugin 1.0.32 and earlier stores API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by u…

Fix: 1.0.33+
Fix from $1,600 2022-10-19
Junos HIGH 7.8
CVE-2022-22251

On cSRX Series devices software permission issues in the container filesystem and stored files combined with storing passwords in a recoverable forma…

Fix: 21.2+
Fix from $1,950 2022-10-18
Nessus MEDIUM 6.5
CVE-2022-28291

Insufficiently Protected Credentials: An authenticated user with debug privileges can retrieve stored Nessus policy credentials from the “nessusd” pr…

No fix yet
Fix from $1,600 2022-10-17
Decision Manager HIGH 7.5
CVE-2019-14840

A flaw was found in the RHDM, where sensitive HTML form fields like Password has auto-complete enabled which may lead to leak of credentials.

No fix yet
Fix from $1,950 2022-10-17
Passster MEDIUM 5.9
CVE-2022-3206

The Passster WordPress plugin before 3.5.5.5.2 stores the password inside a cookie named "passster" using base64 encoding method which is easy to dec…

Fix: 3.5.5.5.2+
Fix from $1,600 2022-10-17
Grafana HIGH 7.5
CVE-2022-31130

Grafana is an open source observability and data visualization platform. Versions of Grafana for endpoints prior to 9.1.8 and 8.5.14 could leak authe…

Fix: 8.5.14 / 9.1.8+
Fix from $1,950 2022-10-13
Simatic Et 200 Sp Open Controller Cpu 1515sp Pc2 Firmware HIGH 7.8
CVE-2022-38465

A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl.…

Fix: 2.9.2 / 4.5.0+
Fix from $1,950 2022-10-11
Robotic Process Automation HIGH 7.5
CVE-2022-39168

IBM Robotic Process Automation Clients are vulnerable to proxy credentials being exposed in upgrade logs. IBM X-Force ID: 235422.

Patch available
Fix from $1,950 2022-09-29
Cloudcnm Secumanager HIGH 7.5
CVE-2020-15341

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated update_all_realm_license API.

No fix yet
Fix from $1,950 2022-09-29
Cloudcnm Secumanager CRITICAL 9.8
CVE-2020-15347

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the q6xV4aW8bQ4cfD-b password for the axiros account.

No fix yet
Fix from $2,300 2022-09-29
Chipolo HIGH 7.4
CVE-2022-37193

Chipolo ONE Bluetooth tracker (2020) Chipolo iOS app version 4.13.0 is vulnerable to Incorrect Access Control. Chipolo devices suffer from access rev…

Mitigation only
Fix from $1,950 2022-09-27
Cons3rt MEDIUM 6.5
CVE-2022-41255

Jenkins CONS3RT Plugin 1.0.0 and earlier stores Cons3rt API token unencrypted in job config.xml files on the Jenkins controller where it can be viewe…

Fix: after 1.0.0
Fix from $1,600 2022-09-21
1350 Optical Management System MEDIUM 6.5
CVE-2022-39816

In NOKIA 1350 OMS R14.2, Insufficiently Protected Credentials (cleartext administrator password) occur in the edit configuration page. Exploitation r…

Mitigation only
Fix from $1,600 2022-09-13
Rancher CRITICAL 9.9
CVE-2021-36783

A Insufficiently Protected Credentials vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Members, Project Owners and Project…

Fix: 2.5.13 / 2.6.4+
Fix from $2,300 2022-09-07
Emc Powerscale Onefs CRITICAL 9.8
CVE-2022-34371

Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.3, contain an unprotected transport of credentials v…

Fix: after 9.4.0.3
Fix from $2,300 2022-09-02
Cognos Analytics MEDIUM 5.5
CVE-2021-39045

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a local attacker to obtain information due to the autocomplete feature on password input …

Fix: 11.1.7 / 11.2.3+
Fix from $1,600 2022-09-01
Versionvault Express MEDIUM 6.5
CVE-2022-27560

HCL VersionVault Express exposes administrator credentials.

Mitigation only
Fix from $1,600 2022-08-30
Foreman HIGH 7.8
CVE-2021-20260

A flaw was found in the Foreman project. The Datacenter plugin exposes the password through the API to an authenticated local attacker with view_host…

Mitigation only
Fix from $1,950 2022-08-26
PostgreSQL MEDIUM 5.9
CVE-2021-43767

Odyssey passes to client unencrypted bytes from man-in-the-middle When Odyssey storage is configured to use the PostgreSQL server using 'trust' authe…

Fix: 9.6.24 / 10.19+
Fix from $1,600 2022-08-25
Zenon MEDIUM 6.1
CVE-2022-34837

Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who successfully exploit the vulnerability may add more …

Fix: after 8.20
Fix from $1,600 2022-08-24
Zenon HIGH 8.4
CVE-2022-34838

Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who successfully exploit the vulnerability may add or al…

Fix: after 8.20
Fix from $1,950 2022-08-24
Git MEDIUM 6.5
CVE-2022-38663

Jenkins Git Plugin 4.11.4 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log provided by the Git Username…

Fix: after 4.11.4
Fix from $1,600 2022-08-23
Collabnet MEDIUM 6.5
CVE-2022-38665

Jenkins CollabNet Plugins Plugin 2.0.8 and earlier stores a RabbitMQ password unencrypted in its global configuration file on the Jenkins controller …

Fix: after 2.0.8
Fix from $1,600 2022-08-23
Prologue MEDIUM 6.5
CVE-2020-35992

Fiserv Prologue through 2020-12-16 does not properly protect the database password. If an attacker were to gain access to the configuration file (spe…

Fix: after 2020-12-16
Fix from $1,600 2022-08-23
Keycloak HIGH 7.5
CVE-2021-3513

A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. This is due to a wrong error …

Fix: 13.0.0+
Fix from $1,950 2022-08-22
Standard Manageability CRITICAL 9.8
CVE-2022-30601

Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow an unauthenticated user to potentially enable inf…

Mitigation only
Fix from $2,300 2022-08-18
Standard Manageability MEDIUM 5.5
CVE-2022-30944

Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow a privileged user to potentially enable informati…

Mitigation only
Fix from $1,600 2022-08-18
Single Event Api HIGH 7.8
CVE-2022-26844

Insufficiently protected credentials in the installation binaries for Intel(R) SEAPI in all versions may allow an authenticated user to potentially e…

Mitigation only
Fix from $1,950 2022-08-18
Team Blue MEDIUM 5.5
CVE-2022-29507

Insufficiently protected credentials in the Intel(R) Team Blue mobile application in all versions may allow an authenticated user to potentially enab…

Mitigation only
Fix from $1,600 2022-08-18
Datacenter Group Event HIGH 7.5
CVE-2022-30296

Insufficiently protected credentials in the Intel(R) Datacenter Group Event iOS application, all versions, may allow an unauthenticated user to poten…

Mitigation only
Fix from $1,950 2022-08-18