Vulnerability index

Browse CVEs

1,246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
Gglocker MEDIUM 5.5
CVE-2021-3179

GGLocker iOS application, contains an insecure data storage of the password hash value which results in an authentication bypass.

Mitigation only
Fix from $1,600 2021-12-16
Knime Server MEDIUM 5.5
CVE-2021-45097

KNIME Server before 4.12.6 and 4.13.x before 4.13.4 (when installed in unattended mode) keeps the administrator's password in a file without appropri…

Fix: 4.13.4+
Fix from $1,600 2021-12-16
Modelsim MEDIUM 6.5
CVE-2021-42023

A vulnerability has been identified in ModelSim Simulation (All versions), Questa Simulation (All versions). The RSA white-box implementation in affe…

Patch available
Fix from $1,600 2021-12-14
Compact 5500r Ip Firmware HIGH 8.8
CVE-2021-40857

Auerswald COMpact 5500R devices before 8.2B allow Privilege Escalation via the passwd=1 substring.

Fix: after 8.0b
Fix from $1,950 2021-12-13
Transport Dr64 Firmware MEDIUM 6.5
CVE-2021-37187

An issue was discovered on Digi TransPort devices through 2021-07-21. An authenticated attacker may read a password file (with reversible passwords) …

Fix: after 8.3.1.2
Fix from $1,600 2021-12-10
Gryphon Tower Firmware CRITICAL 9.8
CVE-2021-20146

An unprotected ssh private key exists on the Gryphon devices which could be used to achieve root access to a server affiliated with Gryphon's develop…

Fix: after 04.0004.12
Fix from $2,300 2021-12-09
Allegro HIGH 8.1
CVE-2021-43978

Allegro WIndows 3.3.4152.0, embeds software administrator database credentials into its binary files, which allows users to access and modify data us…

Patch available
Fix from $1,950 2021-12-08
Azure Active Directory HIGH 8.1
CVE-2021-42306

An information disclosure vulnerability manifests when a user or an application uploads unprotected private key data as part of an authentication cer…

Fix: 2021-10-15 / 2021-10-30+
Fix from $1,950 2021-11-24
Security Guardium Key Lifecycle Manager MEDIUM 5.5
CVE-2021-38976

IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 stores user credentials in plain clear text which can be read by a local user. X-Force ID: …

Fix: after 4.0.0.3
Fix from $1,600 2021-11-15
Debian Linux MEDIUM 6.5
CVE-2021-43332

In GNU Mailman before 2.1.36, the CSRF token for the Cgi/admindb.py admindb page contains an encrypted version of the list admin password. This could…

Fix: 2.1.36+
Fix from $1,600 2021-11-12
Superset MEDIUM 6.5
CVE-2021-41972

Apache Superset up to and including 1.3.1 allowed for database connections password leak for authenticated users. This information could be accessed …

Fix: after 1.3.1
Fix from $1,600 2021-11-12
Liquidfiles HIGH 8.8
CVE-2021-43397

LiquidFiles before 3.6.3 allows remote attackers to elevate their privileges from Admin (or User Admin) to Sysadmin.

Fix: 3.6.3+
Fix from $1,950 2021-11-11
Gui For Windows HIGH 7.8
CVE-2021-40503

An information disclosure vulnerability exists in SAP GUI for Windows - versions < 7.60 PL13, 7.70 PL4, which allows an attacker with sufficient priv…

Fix: 7.60+
Fix from $1,950 2021-11-10
Fortisiem MEDIUM 5.5
CVE-2021-41023

A unprotected storage of credentials in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows an authenticated user to disclosure agent pas…

Fix: after 4.1.4
Fix from $1,600 2021-11-02
Smacom MEDIUM 5.9
CVE-2020-23036

MEDIA NAVI Inc SMACom v1.2 was discovered to contain an insecure session validation vulnerability in the session handling of the `password` authentic…

No fix yet
Fix from $1,600 2021-10-22
Eos MEDIUM 6.5
CVE-2021-28496

On systems running Arista EOS and CloudEOS with the affected release version, when using shared secret profiles the password configured for use by Bi…

Fix: 4.23.10 / 4.24.8+
Fix from $1,600 2021-10-21
Windows 10 HIGH 7.5
CVE-2021-40476

Windows AppContainer Elevation Of Privilege Vulnerability

Patch available
Fix from $1,950 2021-10-13
Debian Linux MEDIUM 6.5
CVE-2021-41125

Scrapy is a high-level web crawling and scraping framework for Python. If you use `HttpAuthMiddleware` (i.e. the `http_user` and `http_pass` spider a…

Fix: 1.8.1 / 2.5.1+
Fix from $1,600 2021-10-06
Fortisdnconnector MEDIUM 6.5
CVE-2021-36178

A insufficiently protected credentials in Fortinet FortiSDNConnector version 1.1.7 and below allows attacker to disclose third-party devices credenti…

Fix: 1.1.8+
Fix from $1,600 2021-10-06
Command Line Interface HIGH 7.5
CVE-2021-41092

Docker CLI is the command line interface for the docker container runtime. A bug was found in the Docker CLI where running `docker login my-private-r…

Fix: 20.10.9+
Fix from $1,950 2021-10-04
Enterprise Sonic Os MEDIUM 6.5
CVE-2021-36309

Dell Enterprise SONiC OS, versions 3.3.0 and earlier, contains a sensitive information disclosure vulnerability. An authenticated malicious user with…

Fix: after 3.3.0
Fix from $1,600 2021-10-01
Ecs Router Controller Ecs Firmware HIGH 8.8
CVE-2021-41297

ECOA BAS controller is vulnerable to weak access control mechanism allowing authenticated user to remotely escalate privileges by disclosing credenti…

Mitigation only
Fix from $1,950 2021-09-30
Ecs Router Controller Ecs Firmware CRITICAL 9.8
CVE-2021-41300

ECOA BAS controller’s special page displays user account and passwords in plain text, thus unauthenticated attackers can access the page and obtain p…

Mitigation only
Fix from $2,300 2021-09-30
Financial HIGH 7.5
CVE-2021-39342

The Credova_Financial WordPress plugin discloses a site's associated Credova API account username and password in plaintext via an AJAX action whenev…

Fix: 1.4.9+
Fix from $1,950 2021-09-29
Security Verify Bridge MEDIUM 5.5
CVE-2021-38863

IBM Security Verify Bridge 1.0.5.0 stores user credentials in plain clear text which can be read by a locally authenticated user. IBM X-Force ID: 208…

Fix: 1.0.7+
Fix from $1,600 2021-09-23
Sd Wan MEDIUM 6.5
CVE-2021-1589

A vulnerability in the disaster recovery feature of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain unauthorized …

Fix: 20.3.4 / 20.4.2+
Fix from $1,600 2021-09-23
Qsw M2116p 2t2s Firmware HIGH 7.5
CVE-2021-28813

A vulnerability involving insecure storage of sensitive information has been reported to affect QSW-M2116P-2T2S and QNAP switches running QuNetSwitch…

Fix: 1.0.6 / 1.0.6.1509+
Fix from $1,950 2021-09-10
Metamako Operating System HIGH 7.8
CVE-2021-28498

In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, user enable passwords set in clear text could resul…

Fix: 0.26.7 / 0.32.0+
Fix from $1,950 2021-09-09
Metamako Operating System MEDIUM 5.5
CVE-2021-28499

In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, user account passwords set in clear text could leak…

Fix: 0.32.0+
Fix from $1,600 2021-09-09
Evolved Programmable Network Manager MEDIUM 5.5
CVE-2021-34733

A vulnerability in the CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, local att…

Fix: 3.8 / 5.0+
Fix from $1,600 2021-09-02