Vulnerability index

Browse CVEs

1,246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
72408a Firmware CRITICAL 9.8
CVE-2020-29054

An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B,…

No fix yet
Fix from $2,300 2020-11-24
Wepresent Wipg 1600w Firmware MEDIUM 6.5
CVE-2020-28330

Barco wePresent WiPG-1600W devices have Unprotected Transport of Credentials. Affected Version(s): 2.5.1.8. An attacker armed with hardcoded API cred…

No fix yet
Fix from $1,600 2020-11-24
Playground Sessions HIGH 7.5
CVE-2020-24227

Playground Sessions v2.5.582 (and earlier) for Windows, stores the user credentials in plain text allowing anyone with access to UserProfiles.sol to …

Fix: after 2.5.582
Fix from $1,950 2020-11-23
Ge 131 Bt 1837836 Firmware HIGH 7.5
CVE-2020-27554

Cleartext Transmission of Sensitive Information vulnerability in BASETech GE-131 BT-1837836 firmware 20180921 exists which could leak sensitive infor…

No fix yet
Fix from $1,950 2020-11-17
Ge 131 Bt 1837836 Firmware MEDIUM 5.5
CVE-2020-27557

Unprotected Storage of Credentials vulnerability in BASETech GE-131 BT-1837836 firmware 20180921 allows local users to gain access to the video strea…

No fix yet
Fix from $1,600 2020-11-17
Oce Colorwave 3500 Firmware CRITICAL 9.8
CVE-2020-26508

The WebTools component on Canon Oce ColorWave 3500 5.1.1.0 devices allows attackers to retrieve stored SMB credentials via the export feature, even t…

Mitigation only
Fix from $2,300 2020-11-16
Nextcloud Server HIGH 8.1
CVE-2020-8259

Insufficient protection of the server-side encryption keys in Nextcloud Server 19.0.1 allowed an attacker to replace the encryption keys.

Fix: 20.0.0+
Fix from $1,950 2020-11-16
Quickassist Technology HIGH 7.8
CVE-2020-12333

Insufficiently protected credentials in the Intel(R) QAT for Linux before version 1.7.l.4.10.0 may allow an authenticated user to potentially enable …

Fix: 1.7.l.4.10.0+
Fix from $1,950 2020-11-12
Endpoint Management Assistant MEDIUM 5.5
CVE-2020-12316

Insufficiently protected credentials in the Intel(R) EMA before version 1.3.3 may allow an authorized user to potentially enable information disclosu…

Fix: 1.3.3+
Fix from $1,600 2020-11-12
Security Key Lifecycle Manager MEDIUM 5.5
CVE-2020-4568

IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, and 4.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID…

Patch available
Fix from $1,600 2020-11-10
Rvtools HIGH 7.5
CVE-2020-27688

RVToolsPasswordEncryption.exe in RVTools 4.0.6 allows users to encrypt passwords to be used in the configuration files. This encryption used a static…

Mitigation only
Fix from $1,950 2020-11-05
Appspider MEDIUM 5.5
CVE-2020-2314

Jenkins AppSpider Plugin 1.0.12 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be …

Fix: after 1.0.12
Fix from $1,600 2020-11-04
Mail Commander MEDIUM 6.5
CVE-2020-2318

Jenkins Mail Commander Plugin for Jenkins-ci Plugin 1.0.0 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller …

Fix: after 1.0.0
Fix from $1,600 2020-11-04
Vmware Lab Manager Slaves MEDIUM 6.5
CVE-2020-2319

Jenkins VMware Lab Manager Slaves Plugin 0.2.8 and earlier stores a password unencrypted in the global config.xml file on the Jenkins controller wher…

Fix: after 0.2.8
Fix from $1,600 2020-11-04
Nextcloud Server HIGH 7.5
CVE-2020-8183

A logic error in Nextcloud Server 19.0.0 caused a plaintext storage of the share password when it was given on the initial create API call.

Fix: 18.0.6 / 19.0.1+
Fix from $1,950 2020-11-02
Unifi Meshing Access Point Firmware HIGH 7.5
CVE-2020-27888

An issue was discovered on Ubiquiti UniFi Meshing Access Point UAP-AC-M 4.3.21.11325 and UniFi Controller 6.0.28 devices. Cached credentials are not …

Mitigation only
Fix from $1,950 2020-10-27
Bluedata Epic MEDIUM 6.5
CVE-2020-7196

The HPE BlueData EPIC Software Platform version 4.0 and HPE Ezmeral Container Platform 5.0 use an insecure method of handling sensitive Kerberos pass…

Fix: after 4.0
Fix from $1,600 2020-10-26
Junos MEDIUM 6.5
CVE-2020-1688

On Juniper Networks SRX Series and NFX Series, a local authenticated user with access to the shell may obtain the Web API service private key that is…

Mitigation only
Fix from $1,600 2020-10-16
Junos MEDIUM 6.3
CVE-2020-1669

The Juniper Device Manager (JDM) container, used by the disaggregated Junos OS architecture on Juniper Networks NFX350 Series devices, stores passwor…

Mitigation only
Fix from $1,600 2020-10-16
Ubuntu Linux MEDIUM 6.1
CVE-2020-15157

In containerd (an industry-standard container runtime) before version 1.2.14 there is a credential leaking vulnerability. If a container image manife…

Fix: 1.2.14+
Fix from $1,600 2020-10-16
Duo Network Gateway MEDIUM 6.3
CVE-2020-3483

Duo has identified and fixed an issue with the Duo Network Gateway (DNG) product in which some customer-provided SSL certificates and private keys we…

Fix: after 1.5.7
Fix from $1,600 2020-10-14
Fineract HIGH 7.5
CVE-2018-20243

The implementation of POST with the username and password in the URL parameters exposed the credentials. More infomration is available in fineract ji…

Fix: after 1.3.0
Fix from $1,950 2020-10-13
Nats.deno HIGH 7.5
CVE-2020-26149

NATS nats.js before 2.0.0-209, nats.ws before 1.0.0-111, and nats.deno before 1.0.0-9 allow credential disclosure from a client to a server.

Fix: 1.0.0-9 / 1.0.0-111+
Fix from $1,950 2020-09-30
Brocade Sannav CRITICAL 9.8
CVE-2019-16211

Brocade SANnav versions before v2.1.0, contain a Plaintext Password Storage vulnerability.

Fix: 2.1.0+
Fix from $2,300 2020-09-25
Continuous Delivery MEDIUM 5.5
CVE-2020-7945

Local registry credentials were included directly in the CD4PE deployment definition, which could expose these credentials to users who should not ha…

Mitigation only
Fix from $1,600 2020-09-18
Bladecenter Advanced Management Module Firmware MEDIUM 6.1
CVE-2020-8339

A cross-site scripting inclusion (XSSI) vulnerability was reported in the legacy IBM BladeCenter Advanced Management Module (AMM) web interface prior…

Fix: 3.68n+
Fix from $1,600 2020-09-15
Simatic S7 300 Cpu 312 Firmware MEDIUM 6.5
CVE-2020-15791

A vulnerability has been identified in SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions), SIMATIC S7-400 CPU fa…

Mitigation only
Fix from $1,600 2020-09-09
Asyncos MEDIUM 6.5
CVE-2020-3547

A vulnerability in the web-based management interface of Cisco AsyncOS software for Cisco Email Security Appliance (ESA), Cisco Content Security Mana…

Fix: after 13.6.1-193
Fix from $1,600 2020-09-04
Zxiptv Firmware CRITICAL 9.1
CVE-2020-6874

A ZTE product is impacted by the cryptographic issues vulnerability. The encryption algorithm is not properly used, so remote attackers could use thi…

Mitigation only
Fix from $2,300 2020-09-01
Guardium Data Encryption MEDIUM 6.5
CVE-2019-4697

IBM Security Guardium Data Encryption (GDE) 3.0.0.2 stores user credentials in plain in clear text which can be read by an authenticated user. IBM X-…

Fix: 1.7.0+
Fix from $1,600 2020-08-26