Vulnerability index

Browse CVEs

1,246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
Powerjob HIGH 7.5
CVE-2020-28865

An issue was discovered in PowerJob through 3.2.2, allows attackers to change arbitrary user passwords via the id parameter to /appinfo/save.

Fix: after 3.2.2
Fix from $1,950 2022-06-16
Rundeck HIGH 7.5
CVE-2022-31044

Rundeck is an open source automation service with a web console, command line tools and a WebAPI. The Key Storage converter plugin mechanism was not …

Mitigation only
Fix from $1,950 2022-06-15
Gradle Enterprise HIGH 7.5
CVE-2022-30587

Gradle Enterprise through 2022.2.2 has Incorrect Access Control that leads to information disclosure.

Fix: 2022.2.3+
Fix from $1,950 2022-06-06
Spectrum Protect Plus HIGH 7.5
CVE-2022-22396

Credentials are printed in clear text in the IBM Spectrum Protect Plus 10.1.0.0 through 10.1.9.3 virgo log file in certain cases. Credentials could b…

Fix: 10.1.10+
Fix from $1,950 2022-06-06
Powerstoreos HIGH 7.8
CVE-2022-22557

PowerStore contains Plain-Text Password Storage Vulnerability in PowerStore X & T environments running versions 2.0.0.x and 2.0.1.x A locally authent…

Fix: 2.1.0.0 / 2.1.1.0+
Fix from $1,950 2022-06-02
Unity Operating Environment MEDIUM 6.7
CVE-2022-29085

Dell Unity, Dell UnityVSA, and Dell Unity XT versions prior to 5.2.0.0.5.173 contain a plain-text password storage vulnerability when certain off-arr…

Fix: 5.2.0.0.5.173+
Fix from $1,600 2022-06-02
Curl MEDIUM 5.7
CVE-2022-27774

An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extr…

Fix: after 7.82.0
Fix from $1,600 2022-06-02
Curl MEDIUM 6.5
CVE-2022-27776

A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the…

Fix: 7.83.0+
Fix from $1,600 2022-06-02
Pyxis Anesthesia Station Es Firmware HIGH 8.8
CVE-2022-22767

Specific BD Pyxis™ products were installed with default credentials and may presently still operate with these credentials. There may be scenarios wh…

Mitigation only
Fix from $1,950 2022-06-02
GitLab HIGH 7.5
CVE-2022-1413

Missing input masking in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versi…

Fix: 14.8.6 / 14.9.4+
Fix from $1,950 2022-05-19
Mxcontrolcenter HIGH 8.8
CVE-2022-30018

Mobotix Control Center (MxCC) through 2.5.4.5 has Insufficiently Protected Credentials, Storing Passwords in a Recoverable Format via the MxCC.ini co…

Fix: after 2.5.4.5
Fix from $1,950 2022-05-19
Blue Ocean MEDIUM 6.5
CVE-2022-30952

Jenkins Pipeline SCM API for Blue Ocean Plugin 1.25.3 and earlier allows attackers with Job/Configure permission to access credentials with attacker-…

Fix: after 1.25.3
Fix from $1,600 2022-05-17
Bizhub 226i Firmware HIGH 7.5
CVE-2022-29588

Konica Minolta bizhub MFP devices before 2022-04-14 use cleartext password storage for the /var/log/nginx/html/ADMINPASS and /etc/shadow files.

Fix: 2022-04-14+
Fix from $1,950 2022-05-16
3cx CRITICAL 9.8
CVE-2022-28005EPSS 6%

An issue was discovered in the 3CX Phone System Management Console prior to version 18 Update 3 FINAL. An unauthenticated attacker could abuse improp…

Fix: after 18.0.3.450
Fix from $2,300 2022-05-06
Strapi HIGH 7.5
CVE-2021-46440

Storing passwords in a recoverable format in the DOCUMENTATION plugin component of Strapi before 3.6.9 and 4.x before 4.1.5 allows an attacker to acc…

Fix: 3.6.9 / 4.1.5+
Fix from $1,950 2022-05-03
Emc Repository Manager HIGH 7.8
CVE-2022-26856

Dell EMC Repository Manager version 3.4.0 contains a plain-text password storage vulnerability. A local attacker could potentially exploit this vulne…

Mitigation only
Fix from $1,950 2022-04-21
Glpi HIGH 7.5
CVE-2022-24867

GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. When you …

Fix: 10.0.0+
Fix from $1,950 2022-04-21
Da50n Firmware MEDIUM 6.5
CVE-2022-27179

A malicious actor having access to the exported configuration file may obtain the stored credentials and thereby gain access to the protected resourc…

Mitigation only
Fix from $1,600 2022-04-20
Manageengine Adaudit Plus HIGH 8.8
CVE-2022-29457EPSS 8%

Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure du…

Fix: 5.7 / 6.1+
Fix from $1,950 2022-04-18
Ansible Automation Platform MEDIUM 5.5
CVE-2021-3681

A flaw was found in Ansible Galaxy Collections. When collections are built manually, any files in the repository directory that are not explicitly ex…

Mitigation only
Fix from $1,600 2022-04-18
Emc Powerscale Onefs MEDIUM 6.7
CVE-2022-22550

Dell PowerScale OneFS, versions 8.2.2 and above, contain a password disclosure vulnerability. An unprivileged local attacker could potentially exploi…

Fix: after 9.3.0
Fix from $1,600 2022-04-12
Manageengine Adaudit Plus HIGH 8.8
CVE-2022-24978

Zoho ManageEngine ADAudit Plus before 7055 allows authenticated Privilege Escalation on Integrated products. This occurs because a password field is …

Fix: after 6.0
Fix from $1,950 2022-04-05
Intellij Idea MEDIUM 5.5
CVE-2022-28651

In JetBrains IntelliJ IDEA before 2021.3.3 it was possible to get passwords from protected fields

Fix: 2021.3.3+
Fix from $1,600 2022-04-05
Arc MEDIUM 5.9
CVE-2021-45892

An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4. There is storage of Passwords in a Recoverable Format.

Mitigation only
Fix from $1,600 2022-04-05
C0 10dd1e D Firmware HIGH 7.5
CVE-2021-32978

The programming protocol allows for a previously entered password and lock state to be read by an attacker. If the previously entered password was su…

Fix: 3.00+
Fix from $1,950 2022-04-04
Net Viewer HIGH 8.6
CVE-2022-1026EPSS 15%

Kyocera multifunction printers running vulnerable versions of Net View unintentionally expose sensitive user information, including usernames and pas…

Fix: after 2s0_1000.005.0012s5_2000.002.505
Fix from $1,950 2022-04-04
Myvue HIGH 7.5
CVE-2021-33024

Philips Vue PACS versions 12.2.x.x and prior transmits or stores authentication credentials, but it uses an insecure method susceptible to unauthoriz…

Fix: 12.2.1.5 / 12.2.8.0+
Fix from $1,950 2022-04-01
Archer HIGH 7.5
CVE-2022-26948

The Archer RSS feed integration for Archer 6.x through 6.9 SP1 (6.9.1.0) is affected by an insecure credential storage vulnerability. A malicious att…

Fix: 6.9.1.1+
Fix from $1,950 2022-03-30
Instant Messaging MEDIUM 6.5
CVE-2022-28135

Jenkins instant-messaging Plugin 1.41 and earlier stores passwords for group chats unencrypted in the global configuration file of plugins based on J…

Fix: 1.42+
Fix from $1,600 2022-03-29
Proxmox MEDIUM 6.5
CVE-2022-28141

Jenkins Proxmox Plugin 0.5.0 and earlier stores the Proxmox Datacenter password unencrypted in the global config.xml file on the Jenkins controller w…

Fix: after 0.5.0
Fix from $1,600 2022-03-29