Vulnerability index

Browse CVEs

1,246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
GitLab HIGH 7.5
CVE-2022-0738

An issue has been discovered in GitLab affecting all versions starting from 14.6 before 14.6.5, all versions starting from 14.7 before 14.7.4, all ve…

Fix: 14.6.5 / 14.7.4+
Fix from $1,950 2022-03-28
Epolicy Orchestrator MEDIUM 6.7
CVE-2022-0859

McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a local attacker to point an ePO server to an arbitrary SQL server during…

Fix: 5.10.0+
Fix from $1,600 2022-03-23
Epolicy Orchestrator MEDIUM 5.3
CVE-2022-0862

A lack of password change protection vulnerability in a depreciated API of McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allow…

Fix: 5.10.0+
Fix from $1,600 2022-03-23
Epas Gtw Firmware MEDIUM 5.5
CVE-2020-25184

Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x stores the password in plaintext in a file that is in the same directory as the executable f…

Fix: 1.1.0+
Fix from $1,600 2022-03-18
Dbcharts MEDIUM 6.5
CVE-2022-27216

Jenkins dbCharts Plugin 0.5.2 and earlier stores JDBC connection passwords unencrypted in its global configuration file on the Jenkins controller whe…

Fix: after 0.5.2
Fix from $1,600 2022-03-15
Vmware Vrealize Codestream MEDIUM 6.5
CVE-2022-27217

Jenkins Vmware vRealize CodeStream Plugin 1.2 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they c…

Fix: after 1.2
Fix from $1,600 2022-03-15
Gitlab Authentication MEDIUM 6.5
CVE-2022-27206

Jenkins GitLab Authentication Plugin 1.13 and earlier stores the GitLab client secret unencrypted in the global config.xml file on the Jenkins contro…

Fix: after 1.13
Fix from $1,600 2022-03-15
PostgreSQL MEDIUM 5.9
CVE-2021-23222

A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryp…

Fix: 9.6.24 / 10.19+
Fix from $1,600 2022-03-02
Vdi Client MEDIUM 5.5
CVE-2022-22908

SangforCSClient.exe in Sangfor VDI Client 5.4.2.1006 allows attackers, when they are able to read process memory, to discover the contents of the Use…

No fix yet
Fix from $1,600 2022-02-26
Dvc 215ip Firmware HIGH 8.6
CVE-2022-24610

Settings/network settings/wireless settings on the Alecto DVC-215IP camera version 63.1.1.173 and below shows the Wi-Fi passphrase hidden, but by edi…

Fix: 63.1.1.173+
Fix from $1,950 2022-02-24
Jqueryform MEDIUM 6.5
CVE-2022-24982

Forms generated by JQueryForm.com before 2022-02-05 allows a remote authenticated attacker to access the cleartext credentials of all other form user…

Fix: 2022-02-05+
Fix from $1,600 2022-02-16
Pipeline\ MEDIUM 6.5
CVE-2022-25184

Jenkins Pipeline: Build Step Plugin 2.15 and earlier reveals password parameter default values when generating a pipeline script using the Pipeline S…

Fix: after 2.15
Fix from $1,600 2022-02-15
Conext Combox Firmware HIGH 7.5
CVE-2021-22798

A CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause Sensitive data such as login credentials being exposed when a N…

Mitigation only
Fix from $1,950 2022-02-11
Globalprotect MEDIUM 5.5
CVE-2022-0019

An insufficiently protected credentials vulnerability exists in the Palo Alto Networks GlobalProtect app on Linux that exposes the hashed credentials…

Fix: 5.1.10 / 5.3.2+
Fix from $1,600 2022-02-10
Simatic Pcs 7 HIGH 8.8
CVE-2021-40360

A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions), SIMATIC PCS 7 V9.1 (All versions < V9.1 …

Fix: 7.4+
Fix from $1,950 2022-02-09
Superset MEDIUM 6.5
CVE-2021-44451EPSS 8%

Apache Superset up to and including 1.3.2 allowed for registered database connections password leak for authenticated users. This information could b…

Fix: after 1.3.2
Fix from $1,600 2022-02-01
Shenyu HIGH 7.5
CVE-2022-23223

On Apache ShenYu versions 2.4.0 and 2.4.1, and endpoint existed that disclosed the passwords of all users. Users are recommended to upgrade to versio…

Patch available
Fix from $1,950 2022-01-25
Emc System Update MEDIUM 5.5
CVE-2022-22554

Dell EMC System Update, version 1.9.2 and prior, contain an Unprotected Storage of Credentials vulnerability. A local attacker with user privleges co…

Fix: after 1.9.2.0
Fix from $1,600 2022-01-24
Agilia Connect Firmware CRITICAL 9.8
CVE-2021-23196

The web application on Agilia Link+ version 3.0 implements authentication and session management mechanisms exclusively on the client-side and does n…

Fix: 3.0+
Fix from $2,300 2022-01-21
Agilia Connect MEDIUM 5.5
CVE-2021-23207

An attacker with physical access to the host can extract the secrets from the registry and create valid JWT tokens for the Fresenius Kabi Vigilant Ma…

Fix: 3.0+
Fix from $1,600 2022-01-21
MongoDB MEDIUM 5.5
CVE-2021-32039

Users with appropriate file access may be able to access unencrypted user credentials saved by MongoDB Extension for VS Code in a binary file. These …

Fix: after 0.7.0
Fix from $1,600 2022-01-20
Metrics MEDIUM 5.5
CVE-2022-20621

Jenkins Metrics Plugin 4.0.2.8 and earlier stores an access key unencrypted in its global configuration file on the Jenkins controller where it can b…

Fix: after 4.0.2.8
Fix from $1,600 2022-01-12
Hashicorp Vault MEDIUM 6.5
CVE-2022-23109

Jenkins HashiCorp Vault Plugin 3.7.0 and earlier does not mask Vault credentials in Pipeline build logs or in Pipeline step descriptions when Pipelin…

Fix: after 3.7.0
Fix from $1,600 2022-01-12
Conjur Secrets HIGH 7.5
CVE-2022-23117

Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent processes to retrieve all userna…

Fix: after 1.0.9
Fix from $1,950 2022-01-12
Data File Manager CRITICAL 9.8
CVE-2021-37400

An attacker may obtain the user credentials from the communication between the PLC and the software. As a result, the PLC user program may be uploade…

Fix: after 8.19.1
Fix from $2,300 2021-12-28
Data File Manager CRITICAL 9.8
CVE-2021-37401

An attacker may obtain the user credentials from file servers, backup repositories, or ZLD files saved in SD cards. As a result, the PLC user program…

Fix: after 8.19.1
Fix from $2,300 2021-12-28
Microsmart Fc6a Firmware HIGH 7.6
CVE-2021-20826

Unprotected transport of credentials vulnerability in IDEC PLCs (FC6A Series MICROSmart All-in-One CPU module v2.32 and earlier, FC6A Series MICROSma…

Fix: after 8.19.1
Fix from $1,950 2021-12-24
Emc Avamar Server MEDIUM 6.7
CVE-2021-36317

Dell EMC Avamar Server version 19.4 contains a plain-text password storage vulnerability in AvInstaller. A local attacker could potentially exploit t…

Patch available
Fix from $1,600 2021-12-21
Emc Avamar Server MEDIUM 6.7
CVE-2021-36318

Dell EMC Avamar versions 18.2,19.1,19.2,19.3,19.4 contain a plain-text password storage vulnerability. A high privileged user could potentially explo…

Patch available
Fix from $1,600 2021-12-21
Syncthru Web Service HIGH 7.5
CVE-2021-42913

The SyncThru Web Service on Samsung SCX-6x55X printers allows an attacker to gain access to a list of SMB users and cleartext passwords by reading th…

Mitigation only
Fix from $1,950 2021-12-20