Vulnerability index

Browse CVEs

1,246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
Drive Manager HIGH 7.8
CVE-2021-39373

Samsung Drive Manager 2.0.104 on Samsung H3 devices allows attackers to bypass intended access controls on disk management. WideCharToMultiByte, Wide…

No fix yet
Fix from $1,950 2021-09-01
Nomad MEDIUM 5.5
CVE-2021-21681

Jenkins Nomad Plugin 0.7.4 and earlier stores Docker passwords unencrypted in the global config.xml file on the Jenkins controller where they can be …

Fix: after 0.7.4
Fix from $1,600 2021-08-31
Wha Gw F2d2 0 As Z2 Eth Firmware MEDIUM 5.5
CVE-2021-34560

In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.9 a form contains a password field with autocomplete enabled. The stored credentials can be captured by …

Fix: after 3.0.9
Fix from $1,600 2021-08-31
Netmodule Router Software HIGH 7.5
CVE-2021-39289

Certain NetModule devices have Insecure Password Handling (cleartext or reversible encryption), These models with firmware before 4.3.0.113, 4.4.0.11…

Fix: 4.3.0.113 / 4.4.0.111+
Fix from $1,950 2021-08-23
Counterparty Settlement And Billing HIGH 7.2
CVE-2021-35529

Insufficiently Protected Credentials vulnerability in client environment of Hitachi ABB Power Grids Retail Operations and Counterparty Settlement Bil…

Fix: 5.7.3+
Fix from $1,950 2021-08-20
Debian Linux MEDIUM 5.3
CVE-2021-38165

Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may ap…

Fix: after 2.8.9
Fix from $1,600 2021-08-07
R08sfcpu Firmware CRITICAL 9.1
CVE-2021-20597

Insufficiently Protected Credentials vulnerability in Mitsubishi Electric MELSEC iQ-R series Safety CPU modules R08/16/32/120SFCPU firmware versions …

Mitigation only
Fix from $2,300 2021-08-06
Sitemanager Firmware MEDIUM 5.5
CVE-2021-32003

Unprotected Transport of Credentials vulnerability in SiteManager provisioning service allows local attacker to capture credentials if the service is…

Fix: 9.5.621256022+
Fix from $1,600 2021-08-05
Curl MEDIUM 5.3
CVE-2021-22923

When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink XML file, those sam…

Fix: 1.0.1.1 / 7.78.0+
Fix from $1,600 2021-08-05
Mylife HIGH 7.5
CVE-2021-27491

Ypsomed mylife Cloud, mylife Mobile Application:Ypsomed mylife Cloud,All versions prior to 1.7.2,Ypsomed mylife App,All versions prior to 1.7.5,The Y…

Fix: 1.7.2 / 1.7.5+
Fix from $1,950 2021-07-30
Mylife HIGH 7.1
CVE-2021-27495

Ypsomed mylife Cloud, mylife Mobile Application:Ypsomed mylife Cloud,All versions prior to 1.7.2,Ypsomed mylife App,All versions prior to 1.7.5,he Yp…

Fix: 1.7.2 / 1.7.5+
Fix from $1,950 2021-07-30
Catalyst Sd Wan Manager MEDIUM 5.5
CVE-2021-34700

A vulnerability in the CLI interface of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to read arbitrary files on the und…

Fix: 20.4.2 / 20.5.1+
Fix from $1,600 2021-07-22
Emc Repository Manager HIGH 8.8
CVE-2020-5315

Dell EMC Repository Manager (DRM) version 3.2 contains a plain-text password storage vulnerability. Proxy server user password is stored in a plain t…

Fix: after 3.2
Fix from $1,950 2021-07-19
Orca Hcm CRITICAL 9.8
CVE-2021-35965

The Orca HCM digital learning platform uses a weak factory default administrator password, which is hard-coded in the source code of the webpage in p…

Fix: after 10.0
Fix from $2,300 2021-07-19
Gatsby Source Wordpress HIGH 7.5
CVE-2021-32770

Gatsby is a framework for building websites. The gatsby-source-wordpress plugin prior to versions 4.0.8 and 5.9.2 leaks .htaccess HTTP Basic Authenti…

Fix: 4.0.8 / 5.9.2+
Fix from $1,950 2021-07-15
Security Access Manager HIGH 7.5
CVE-2021-20439

IBM Security Access Manager 9.0 and IBM Security Verify Access Docker 10.0.0 stores user credentials in plain clear text which can be read by an unau…

Patch available
Fix from $1,950 2021-07-15
Ecostruxure Control Expert HIGH 7.1
CVE-2021-22778

Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of U…

Fix: 15.0+
Fix from $1,950 2021-07-14
Ecostruxure Control Expert HIGH 7.1
CVE-2021-22780

Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of U…

Fix: 15.0+
Fix from $1,950 2021-07-14
Ecostruxure Control Expert MEDIUM 5.5
CVE-2021-22781

Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of U…

Fix: 15.0+
Fix from $1,600 2021-07-14
Esoms HIGH 7.5
CVE-2021-35527

Password autocomplete vulnerability in the web application password field of Hitachi ABB Power Grids eSOMS allows attacker to gain access to user cre…

Fix: 6.3.1+
Fix from $1,950 2021-07-14
Emc Unity Operating Environment MEDIUM 6.7
CVE-2021-21590

Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerability. A local malicious user wi…

Fix: 5.1.0.0.5.394+
Fix from $1,600 2021-07-12
Emc Unity Operating Environment MEDIUM 6.7
CVE-2021-21591

Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerability. A local malicious user wi…

Fix: 5.1.0.0.5.394+
Fix from $1,600 2021-07-12
Vsa Agent CRITICAL 9.8
CVE-2021-30116 KEVEPSS 86%

Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page …

Fix: 9.5.0.24 / 9.5.7a+
Fix from $2,300 2021-07-09
Pandora Fms MEDIUM 5.9
CVE-2021-34075

In Artica Pandora FMS <=754 in the File Manager component, there is sensitive information exposed on the client side which attackers can access.

Fix: after 754
Fix from $1,600 2021-06-30
Deception HIGH 7.5
CVE-2021-35050

User credentials stored in a recoverable format within Fidelis Network and Deception CommandPost. In the event that an attacker gains access to the C…

Fix: 9.3.3+
Fix from $1,950 2021-06-25
Dir 2640 Us Firmware MEDIUM 6.8
CVE-2021-34204

D-Link DIR-2640-US 1.01B04 is affected by Insufficiently Protected Credentials. D-Link AC2600(DIR-2640) stores the device system account password in …

No fix yet
Fix from $1,600 2021-06-16
Tl Wpa4220 Firmware HIGH 7.5
CVE-2021-28857

TP-Link's TL-WPA4220 4.0.2 Build 20180308 Rel.37064 username and password are sent via the cookie.

No fix yet
Fix from $1,950 2021-06-15
Sannav HIGH 7.5
CVE-2020-15381

Brocade SANnav before version 2.1.1 contains an Improper Authentication vulnerability that allows cleartext transmission of authentication credential…

Fix: 2.1.1+
Fix from $1,950 2021-06-09
Codebeamer HIGH 7.5
CVE-2020-26515

An insufficiently protected credentials issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The remember-me cookie (CB_LOGIN) issue…

Fix: 10.1.0+
Fix from $1,950 2021-06-08
Dir 868l Firmware HIGH 7.5
CVE-2020-29321

The D-Link router DIR-868L 3.01 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthent…

No fix yet
Fix from $1,950 2021-06-04