Vulnerability index

Browse CVEs

1,246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
Openbsi MEDIUM 5.5
CVE-2022-29959

Emerson OpenBSI through 2022-04-29 mishandles credential storage. It is an engineering environment for the ControlWave and Bristol Babcock line of RT…

Fix: 5.9+
Fix from $1,600 2022-08-16
Airvelocity 1500 Firmware MEDIUM 6.8
CVE-2022-36307

The AirVelocity 1500 prints SNMP credentials on its physically accessible serial port during boot. This was fixed in AirVelocity 1500 software versio…

Fix: after 15.18.00.2511
Fix from $1,600 2022-08-16
Airvelocity 1500 Firmware CRITICAL 9.1
CVE-2022-36308

Airspan AirVelocity 1500 web management UI displays SNMP credentials in plaintext on software versions older than 15.18.00.2511, and stores SNMPv3 cr…

Fix: after 15.18.00.2511
Fix from $2,300 2022-08-16
Workstation MEDIUM 5.9
CVE-2022-22983

VMware Workstation (16.x prior to 16.2.4) contains an unprotected storage of credentials vulnerability. A malicious actor with local user privileges …

Fix: 16.2.4+
Fix from $1,600 2022-08-10
Robotic Process Automation MEDIUM 6.5
CVE-2022-33169

IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to insufficiently protected credentials for users created via a bulk upload. …

Fix: after 21.0.3
Fix from $1,600 2022-08-01
Hcl Commerce MEDIUM 5.0
CVE-2021-27785

HCL Commerce's Remote Store server could allow a local attacker to obtain sensitive personal information. The vulnerability requires the victim to fi…

Fix: after 9.1.10
Fix from $1,600 2022-07-30
Twinsoft CRITICAL 9.8
CVE-2021-22640

An attacker can decrypt the Ovarro TBox login password by communication capture and brute force attacks.

Fix: 1.46 / 12.4+
Fix from $2,300 2022-07-28
Http Request MEDIUM 6.5
CVE-2022-36901

Jenkins HTTP Request Plugin 1.15 and earlier stores HTTP Request passwords unencrypted in its global configuration file on the Jenkins controller whe…

Fix: after 1.15
Fix from $1,600 2022-07-27
Anchore HIGH 7.5
CVE-2022-1766

Anchore Enterprise anchorectl version 0.1.4 improperly stored credentials when generating a Software Bill of Materials. anchorectl will add the crede…

Fix: 0.1.5 / 4.0.1+
Fix from $1,950 2022-07-20
Bigfix Platform MEDIUM 6.5
CVE-2022-27544

BigFix Web Reports authorized users may see SMTP credentials in clear text.

Fix: after 10.0.6
Fix from $1,600 2022-07-19
My Cloud Home Duo Firmware HIGH 7.5
CVE-2022-22998

Implemented protections on AWS credentials that were not properly protected.

Fix: 8.5.1-102+
Fix from $1,950 2022-07-12
Opc Da Server MEDIUM 5.5
CVE-2022-1794

The CODESYS OPC DA Server prior V3.5.18.20 stores PLC passwords as plain text in its configuration file so that it is visible to all authorized Micro…

Fix: 3.5.18.20+
Fix from $1,600 2022-07-11
Rpc.py CRITICAL 9.8
CVE-2022-35411EPSS 46%

rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header is sent. In other words, altho…

Fix: after 0.6.0
Fix from $2,300 2022-07-08
Hcl Launch MEDIUM 5.5
CVE-2022-27548

HCL Launch stores user credentials in plain clear text which can be read by a local user.

Mitigation only
Fix from $1,600 2022-07-06
Pingid Integration For Windows Login MEDIUM 5.5
CVE-2022-23725

PingID Windows Login prior to 2.8 does not properly set permissions on the Windows Registry entries used to store sensitive API keys under some circu…

Fix: 2.8+
Fix from $1,600 2022-06-30
Hpe Network Virtualization MEDIUM 6.5
CVE-2022-34816

Jenkins HPE Network Virtualization Plugin 1.0 stores passwords unencrypted in its global configuration file on the Jenkins controller where they can …

Mitigation only
Fix from $1,600 2022-06-30
Skype Notifier MEDIUM 6.5
CVE-2022-34805

Jenkins Skype notifier Plugin 1.1.0 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can…

Fix: after 1.1.0
Fix from $1,600 2022-06-30
Jigomerge MEDIUM 6.5
CVE-2022-34806

Jenkins Jigomerge Plugin 0.9 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by u…

Fix: after 0.9
Fix from $1,600 2022-06-30
Elasticsearch Query MEDIUM 6.5
CVE-2022-34807

Jenkins Elasticsearch Query Plugin 1.2 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it …

Fix: after 1.2
Fix from $1,600 2022-06-30
Rqm MEDIUM 6.5
CVE-2022-34809

Jenkins RQM Plugin 2.8 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by…

Fix: after 2.8
Fix from $1,600 2022-06-30
Marval Msm CRITICAL 9.8
CVE-2022-31887

Marval MSM v14.19.0.12476 has a 0-Click Account Takeover vulnerability which allows an attacker to change any user's password in the organization, th…

No fix yet
Fix from $2,300 2022-06-28
Debian Linux MEDIUM 6.1
CVE-2022-31085

LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior t…

Fix: 8.0+
Fix from $1,600 2022-06-27
Remote Desktop Manager MEDIUM 6.5
CVE-2022-2221

Information Exposure vulnerability in My Account Settings of Devolutions Remote Desktop Manager before 2022.1.8 allows authenticated users to access …

Fix: 2022.1.8+
Fix from $1,600 2022-06-27
Sannav MEDIUM 6.5
CVE-2022-28167

Brocade SANnav before Brocade SANvav v. 2.2.0.2 and Brocade SANanv v.2.1.1.8 logs the Brocade Fabric OS switch password in plain text in asyncjobsche…

Fix: 2.1.1.8 / 2.2.0.2+
Fix from $1,600 2022-06-27
Sepcos Control And Protection Relay Firmware CRITICAL 9.1
CVE-2022-2103

An attacker with weak credentials could access the TCP port via an open FTP port, allowing an attacker to read sensitive files and write to remotely …

Fix: 1.23.21 / 1.24.8+
Fix from $2,300 2022-06-24
Sepcos Control And Protection Relay Firmware MEDIUM 6.5
CVE-2022-1666

The default password for the web application’s root user (the vendor’s private account) was weak and the MD5 hash was used to crack the password usin…

Fix: 1.23.21 / 1.24.8+
Fix from $1,600 2022-06-24
Squash Tm Publisher MEDIUM 6.5
CVE-2022-34213

Jenkins Squash TM Publisher (Squash4Jenkins) Plugin 1.0.0 and earlier stores passwords unencrypted in its global configuration file on the Jenkins co…

Fix: after 1.0.0
Fix from $1,600 2022-06-23
Convertigo Mobile Platform MEDIUM 6.5
CVE-2022-34199

Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they c…

Fix: after 1.1
Fix from $1,600 2022-06-23
Easyqa MEDIUM 6.5
CVE-2022-34202

Jenkins EasyQA Plugin 1.0 and earlier stores user passwords unencrypted in its global configuration file on the Jenkins controller where they can be …

Fix: after 1.0
Fix from $1,600 2022-06-23
Atvise MEDIUM 5.9
CVE-2022-21184

An information disclosure vulnerability exists in the License registration functionality of Bachmann Visutec GmbH Atvise 3.5.4, 3.6 and 3.7. A plaint…

Mitigation only
Fix from $1,600 2022-06-17