Vulnerability index

Browse CVEs

1,246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
Openshift Builder HIGH 8.8
CVE-2021-3344

A privilege escalation flaw was found in OpenShift builder. During build time, credentials outside the build context are automatically mounted into t…

Fix: 4.5.33 / 4.6.16+
Fix from $1,950 2021-03-16
Adguard Home HIGH 7.5
CVE-2021-27935

An issue was discovered in AdGuard before 0.105.2. An attacker able to get the user's cookie is able to bruteforce their password offline, because th…

Fix: 0.105.2+
Fix from $1,950 2021-03-03
Factorytalk Services Platform CRITICAL 9.8
CVE-2021-22681 KEVEPSS 61%

Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers a…

Fix: after 20
Fix from $2,300 2021-03-03
Windows 10 MEDIUM 5.5
CVE-2021-1731

PFX Encryption Security Feature Bypass Vulnerability

Patch available
Fix from $1,600 2021-02-25
Xp100u Firmware HIGH 7.5
CVE-2021-3252

KACO New Energy XP100U Up to XP-JAVA 2.0 is affected by incorrect access control. Credentials will always be returned in plain-text from the local se…

No fix yet
Fix from $1,950 2021-02-23
Maximo For Civil Infrastructure MEDIUM 6.5
CVE-2021-20445

IBM Maximo for Civil Infrastructure 7.6.2 could allow a user to obtain sensitive information due to insecure storeage of authentication credentials. …

Patch available
Fix from $1,600 2021-02-18
Solarcity Solar Monitoring Gateway HIGH 8.8
CVE-2020-9306

Tesla SolarCity Solar Monitoring Gateway through 5.46.43 has a "Use of Hard-coded Credentials" issue because Digi ConnectPort X2e uses a .pyc file to…

Fix: after 5.46.43
Fix from $1,950 2021-02-18
Security Verify Information Queue MEDIUM 5.3
CVE-2021-20410

IBM Security Verify Information Queue 1.0.6 and 1.0.7 sends user credentials in plain clear text which can be read by an authenticated user using man…

Patch available
Fix from $1,600 2021-02-12
Fx Aggregator Terminal Client HIGH 7.5
CVE-2021-27187

The Sovremennye Delovye Tekhnologii FX Aggregator terminal client 1 stores authentication credentials in cleartext in login.sav when the Save Passwor…

Mitigation only
Fix from $1,950 2021-02-12
Control Center MEDIUM 5.5
CVE-2020-14391

A flaw was found in the GNOME Control Center in Red Hat Enterprise Linux 8 versions prior to 8.2, where it improperly uses Red Hat Customer Portal cr…

Mitigation only
Fix from $1,600 2021-02-08
Psyprax HIGH 7.5
CVE-2020-10554

An issue was discovered in Psyprax beforee 3.2.2. Passwords used to encrypt the data are stored in the database in an obfuscated format, which can be…

Fix: 3.2.2+
Fix from $1,950 2021-02-05
Mediawiki HIGH 7.5
CVE-2020-29005

The API in the Push extension for MediaWiki through 1.35 used cleartext for ApiPush credentials, allowing for potential information disclosure.

Fix: after 1.35
Fix from $1,950 2021-01-29
Anydana A MEDIUM 6.5
CVE-2020-27258

In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, an information disclosure vulnerability in the communication protocol of the in…

Fix: 3.0+
Fix from $1,600 2021-01-19
Anydana A Firmware MEDIUM 5.7
CVE-2020-27270

SOOIL Developments CoLtd DiabecareRS, AnyDana-i ,AnyDana-A, communication protocol of the insulin pump & AnyDana-i,AnyDana-A mobile apps doesnt use a…

Fix: 3.0+
Fix from $1,600 2021-01-19
Contrail Networking MEDIUM 5.0
CVE-2021-0212

An Information Exposure vulnerability in Juniper Networks Contrail Networking allows a locally authenticated attacker able to read files to retrieve …

Fix: 1911.31+
Fix from $1,600 2021-01-15
Junos Space MEDIUM 6.8
CVE-2021-0220

The Junos Space Network Management Platform has been found to store shared secrets in a recoverable format that can be exposed through the UI. An att…

Mitigation only
Fix from $1,600 2021-01-15
Secure Firewall Management Center MEDIUM 5.5
CVE-2021-1126

A vulnerability in the storage of proxy server credentials of Cisco Firepower Management Center (FMC) could allow an authenticated, local attacker to…

Fix: 6.7.0+
Fix from $1,600 2021-01-13
Tracetronic Ecu Test MEDIUM 5.5
CVE-2021-21612

Jenkins TraceTronic ECU-TEST Plugin 2.23.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins controller wher…

Fix: after 2.23.1
Fix from $1,600 2021-01-13
Bumblebee Hp Alm MEDIUM 5.5
CVE-2021-21614

Jenkins Bumblebee HP ALM Plugin 4.1.5 and earlier stores credentials unencrypted in its global configuration file on the Jenkins controller where the…

Fix: after 4.1.5
Fix from $1,600 2021-01-13
Opcenter Execution Core MEDIUM 5.5
CVE-2020-28390

A vulnerability has been identified in Opcenter Execution Core (V8.2), Opcenter Execution Core (V8.3). The application contains an information leakag…

Mitigation only
Fix from $1,600 2021-01-12
Qes HIGH 7.2
CVE-2020-2499

A hard-coded password vulnerability has been reported to affect earlier versions of QES. If exploited, this vulnerability could allow attackers to lo…

Fix: 2.1.1+
Fix from $1,950 2020-12-24
Usg20 Vpn Firmware CRITICAL 9.8
CVE-2020-29583 KEVEPSS 90%

Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can …

Mitigation only
Fix from $2,300 2020-12-22
Symphony \+ Historian HIGH 7.0
CVE-2020-24680

In S+ Operations and S+ Historian, the passwords of internal users (not Windows Users) are encrypted but improperly stored in a database.

Mitigation only
Fix from $1,950 2020-12-22
Ceph HIGH 7.1
CVE-2020-27781

User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open S…

Fix: 14.2.16 / 15.2.8+
Fix from $1,950 2020-12-18
Netcrunch MEDIUM 5.5
CVE-2019-14477

AdRem NetCrunch 10.6.0.4587 has Improper Credential Storage since the internal user database is readable by low-privileged users and passwords in the…

Fix: after 11.0.0.5282
Fix from $1,600 2020-12-16
Netcrunch CRITICAL 9.8
CVE-2019-14480

AdRem NetCrunch 10.6.0.4587 has an Improper Session Handling vulnerability in the NetCrunch web client, which can lead to an authentication bypass or…

Fix: after 11.0.0.5282
Fix from $2,300 2020-12-16
Logo\! 8 Bm Firmware HIGH 7.5
CVE-2020-25235

A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). The password used for authentication for the LOGO! W…

Fix: 8.3+
Fix from $1,950 2020-12-14
3.0t Signa Hdxt Firmware CRITICAL 9.8
CVE-2020-25175

GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.

Mitigation only
Fix from $2,300 2020-12-14
Ecostruxure Geo Scada Expert 2019 HIGH 7.8
CVE-2020-28219

A CWE-522: Insufficiently Protected Credentials vulnerability exists in EcoStruxure Geo SCADA Expert 2019 (Original release and Monthly Updates to Se…

Fix: after 83.7578.1
Fix from $1,950 2020-12-11
V1600d Firmware MEDIUM 5.9
CVE-2020-29380

An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4…

Mitigation only
Fix from $1,600 2020-11-29