Vulnerability index

Browse CVEs

1,246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
Dir 880l Firmware HIGH 7.5
CVE-2020-29322

The D-Link router DIR-880L 1.07 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthent…

No fix yet
Fix from $1,950 2021-06-04
Dir 885l Mfc Firmware HIGH 7.5
CVE-2020-29323

The D-link router DIR-885L-MFC 1.15b02, v1.21b05 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that al…

No fix yet
Fix from $1,950 2021-06-04
Thousandeyes Recorder MEDIUM 5.5
CVE-2021-1537

A vulnerability in the installer software of Cisco ThousandEyes Recorder could allow an unauthenticated, local attacker to access sensitive informati…

Fix: 1.0.5+
Fix from $1,600 2021-06-04
Cognos Analytics HIGH 7.5
CVE-2019-4723

IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete settings in N…

Patch available
Fix from $1,950 2021-06-01
Cognos Analytics HIGH 7.5
CVE-2019-4724

IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete settings in N…

Patch available
Fix from $1,950 2021-06-01
Nginx Controller HIGH 7.8
CVE-2021-23019

The NGINX Controller 2.0.0 thru 2.9.0 and 3.x before 3.15.0 Administrator password may be exposed in the systemd.txt file that is included in the NGI…

Fix: 3.15.0+
Fix from $1,950 2021-06-01
Ceph MEDIUM 5.4
CVE-2020-27839

A flaw was found in ceph-dashboard. The JSON Web Token (JWT) used for user authentication is stored by the frontend application in the browser’s loca…

Fix: 14.2.17 / 15.2.9+
Fix from $1,600 2021-05-26
Versa Analytics MEDIUM 5.5
CVE-2019-25030

In Versa Director, Versa Analytics and VOS, Passwords are not hashed using an adaptive cryptographic hash function or key derivation function prior t…

Mitigation only
Fix from $1,600 2021-05-26
Archer MEDIUM 5.5
CVE-2021-29253

The Tableau integration in RSA Archer 6.4 P1 (6.4.0.1) through 6.9 P2 (6.9.0.2) is affected by an insecure credential storage vulnerability. An malic…

Fix: 6.6.0.8 / 6.7.0.8+
Fix from $1,600 2021-05-26
Security Guardium HIGH 7.8
CVE-2021-20389

IBM Security Guardium 11.2 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 195770.

Patch available
Fix from $1,950 2021-05-24
Fido U2f Firmware CRITICAL 9.8
CVE-2020-12061

An issue was discovered in Nitrokey FIDO U2F firmware through 1.1. Communication between the microcontroller and the secure element transmits credent…

Fix: after 1.1
Fix from $2,300 2021-05-21
Brain Cube Core HIGH 7.5
CVE-2020-24396

homee Brain Cube v2 (2.28.2 and 2.28.4) devices have sensitive SSH keys within downloadable and unencrypted firmware images. This allows remote attac…

Mitigation only
Fix from $1,950 2021-05-20
Digital Experience Platform MEDIUM 5.9
CVE-2021-29043

The Portal Store module in Liferay Portal 7.0.0 through 7.3.5, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 21, 7.2 before fix pack 10…

Fix: after 7.3.5
Fix from $1,600 2021-05-17
Noobaa Operator HIGH 8.8
CVE-2021-3528

A flaw was found in noobaa-operator in versions before 5.7.0, where internal RPC AuthTokens between the noobaa operator and the noobaa core are leake…

Fix: 5.7.0+
Fix from $1,950 2021-05-13
0852 0303 Firmware HIGH 7.5
CVE-2021-20997

In multiple managed switches by WAGO in different versions it is possible to read out the password hashes of all Web-based Management users.

Fix: after 1.2.3.s0
Fix from $1,950 2021-05-13
Dominaplus CRITICAL 9.8
CVE-2020-21994

AVE DOMINAplus <=1.10.x suffers from clear-text credentials disclosure vulnerability that allows an unauthenticated attacker to issue a request to an…

Fix: after 1.10.77
Fix from $2,300 2021-04-28
P2r8852e2 Firmware CRITICAL 9.8
CVE-2021-30167

The manage users profile services of the network camera device allows an authenticated. Remote attackers can modify URL parameters and further amend …

Fix: 7.1.94.8908+
Fix from $2,300 2021-04-28
P2r8852e2 Firmware CRITICAL 9.8
CVE-2021-30168

The sensitive information of webcam device is not properly protected. Remote attackers can unauthentically grant administrator’s credential and furth…

Fix: 7.1.94.8908+
Fix from $2,300 2021-04-28
P2r8852e2 Firmware HIGH 7.5
CVE-2021-30169

The sensitive information of webcam device is not properly protected. Remote attackers can unauthentically grant user’s credential.

Fix: 7.1.94.8908+
Fix from $1,950 2021-04-28
Solr HIGH 7.5
CVE-2021-29262EPSS 8%

When starting Apache Solr versions prior to 8.8.2, configured with the SaslZkACLProvider or VMParamsAllAndReadonlyDigestZkACLProvider and no existing…

Fix: 8.8.2+
Fix from $1,950 2021-04-13
Fortiweb MEDIUM 6.5
CVE-2020-15942

An information disclosure vulnerability in Web Vulnerability Scan profile of Fortinet's FortiWeb version 6.2.x below 6.2.4 and version 6.3.x below 6.…

Fix: after 6.3.4
Fix from $1,600 2021-04-12
Capi Release MEDIUM 6.5
CVE-2021-22115

Cloud Controller API versions prior to 1.106.0 logs service broker credentials if the default value of db logging config field is changed. CAPI datab…

Fix: 1.106.0 / 16.2.0+
Fix from $1,600 2021-04-08
Deltaflow CRITICAL 9.8
CVE-2021-28171

The Vangene deltaFlow E-platform does not take properly protective measures. Attackers can obtain privileged permissions remotely by tampering with u…

Fix: 7.7+
Fix from $2,300 2021-04-06
Grand Elite 3 Connect Firmware HIGH 8.8
CVE-2020-11925

An issue was discovered in Luvion Grand Elite 3 Connect through 2020-02-25. Authentication to the device is based on a username and password. The roo…

Fix: after 2020-02-25
Fix from $1,950 2021-04-02
Jabber \(xmpp\) Notifier And Control MEDIUM 6.5
CVE-2021-21634

Jenkins Jabber (XMPP) notifier and control Plugin 1.41 and earlier stores passwords unencrypted in its global configuration file on the Jenkins contr…

Fix: after 1.41
Fix from $1,600 2021-03-30
Mym71080i B Firmware HIGH 7.5
CVE-2021-29255

MicroSeven MYM71080i-B 2.0.5 through 2.0.20 devices send admin credentials in cleartext to pnp.microseven.com TCP port 7007. An attacker on the same …

Fix: after 2.0.20
Fix from $1,950 2021-03-26
Xpon Rtl9601d Software Development Kit CRITICAL 9.8
CVE-2021-27372

Realtek xPON RTL9601D SDK 1.9 stores passwords in plaintext which may allow attackers to possibly gain access to the device with root permissions via…

Mitigation only
Fix from $2,300 2021-03-25
iOS HIGH 7.8
CVE-2021-1392

A vulnerability in the CLI command permissions of Cisco IOS and Cisco IOS XE Software could allow an authenticated, local attacker to retrieve the pa…

Mitigation only
Fix from $1,950 2021-03-24
Openshift MEDIUM 6.3
CVE-2019-10225

A flaw was found in atomic-openshift of openshift-4.2 where the basic-user RABC role in OpenShift Container Platform doesn't sufficiently protect the…

Mitigation only
Fix from $1,600 2021-03-19
Stealth HIGH 7.8
CVE-2021-3141

In Unisys Stealth (core) before 6.0.025.0, the Keycloak password is stored in a recoverable format that might be accessible by a local attacker, who …

Fix: 6.0.025.0+
Fix from $1,950 2021-03-18