Vulnerability index

Browse CVEs

1,246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
Rangeeos MEDIUM 5.5
CVE-2020-16280

Multiple Rangee GmbH RangeeOS 8.0.4 modules store credentials in plaintext including credentials of users for several external facing administrative …

Mitigation only
Fix from $1,600 2020-08-20
Xenmobile Server HIGH 7.5
CVE-2020-8210

Insufficient protection of secrets in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.…

Fix: after 10.8.0
Fix from $1,950 2020-08-17
Data Loss Prevention MEDIUM 5.2
CVE-2020-7307

Unprotected Storage of Credentials vulnerability in McAfee Data Loss Prevention (DLP) for Mac prior to 11.5.2 allows local users to gain access to th…

Fix: 11.3.28 / 11.4.200+
Fix from $1,600 2020-08-13
Data Loss Prevention MEDIUM 5.2
CVE-2020-7306

Unprotected Storage of Credentials vulnerability in McAfee Data Loss Prevention (DLP) for Mac prior to 11.5.2 allows local users to gain access to th…

Fix: 11.3.31 / 11.4.200+
Fix from $1,600 2020-08-13
Pactware MEDIUM 5.5
CVE-2020-9403

In PACTware before 4.1 SP6 and 5.x before 5.0.5.31, passwords are stored in a recoverable format, and may be retrieved by any user with access to the…

Fix: 5.0.5.31+
Fix from $1,600 2020-08-11
Pactware HIGH 7.1
CVE-2020-9404

In PACTware before 4.1 SP6 and 5.x before 5.0.5.31, passwords are stored in an insecure manner, and may be modified by an attacker with no knowledge …

Fix: 5.0.5.31+
Fix from $1,950 2020-08-11
Firefox Mobile MEDIUM 6.5
CVE-2020-15661

A rogue webpage could override the injected WKUserScript used by the logins autofill, this exploit could result in leaking a password for the current…

Fix: 28.0+
Fix from $1,600 2020-08-10
P2p HIGH 8.1
CVE-2020-9525

CS2 Network P2P through 3.x, as used in millions of Internet of Things devices, suffers from an authentication flaw that allows remote attackers to p…

Fix: after 3.0.3a
Fix from $1,950 2020-08-10
42633 Firmware HIGH 8.8
CVE-2020-15058

Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to elevate privileges because the administr…

Mitigation only
Fix from $1,950 2020-08-07
Da 70254 Firmware HIGH 8.8
CVE-2020-15062

DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to elevate privileges because the administr…

Mitigation only
Fix from $1,950 2020-08-07
Tl Ps310u Firmware HIGH 8.8
CVE-2020-15054

TP-Link USB Network Server TL-PS310U devices before 2.079.000.t0210 allow an attacker on the same network to elevate privileges because the administr…

Fix: 2.079.000.t0210+
Fix from $1,950 2020-08-07
Satellite HIGH 8.8
CVE-2020-14334

A flaw was found in Red Hat Satellite 6 which allows privileged attacker to read cache files. These cache credentials could help attacker to gain com…

Mitigation only
Fix from $1,950 2020-07-31
Package Analytics MEDIUM 6.5
CVE-2020-2078

Passwords are stored in plain text within the configuration of SICK Package Analytics software up to and including V04.1.1. An authorized attacker co…

Fix: after 04.1.1
Fix from $1,600 2020-07-29
Openclinic Ga HIGH 7.5
CVE-2020-14489

OpenClinic GA 5.09.02 and 5.89.05b stores passwords using inadequate hashing complexity, which may allow an attacker to recover passwords using known…

Mitigation only
Fix from $1,950 2020-07-29
Unleashed Firmware HIGH 7.5
CVE-2020-13915

Insecure permissions in emfd/libemf in Ruckus Wireless Unleashed through 200.7.10.102.92 allow a remote attacker to overwrite admin credentials via a…

Fix: after 200.7.10.102.92
Fix from $1,950 2020-07-28
Cim 500 HIGH 7.5
CVE-2020-10609

Grundfos CIM 500 v06.16.00 stores plaintext credentials, which may allow sensitive information to be read or allow modification to system settings by…

Mitigation only
Fix from $1,950 2020-07-27
Verify Gateway HIGH 7.8
CVE-2020-4372

IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 179009

Patch available
Fix from $1,950 2020-07-22
Bigfix Platform MEDIUM 6.0
CVE-2020-4095

"BigFix Platform is storing clear text credentials within the system's memory. An attacker who is able to gain administrative privileges can use a pr…

Fix: after 9.5.15
Fix from $1,600 2020-07-16
Sd Wan HIGH 7.8
CVE-2020-3180

A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, local attacker to access an affected device by using an account tha…

Fix: 18.3.6 / 18.4.5+
Fix from $1,950 2020-07-16
Irb140 Firmware CRITICAL 9.8
CVE-2020-10287

The IRC5 family with UAS service enabled comes by default with credentials that can be found on publicly available manuals. ABB considers this a well…

Mitigation only
Fix from $2,300 2020-07-15
Digital Network Architecture Center MEDIUM 6.5
CVE-2020-3391

A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to view sensitive information in cle…

Fix: 1.2.10+
Fix from $1,600 2020-07-02
Nginx Controller HIGH 7.8
CVE-2020-5899

In NGINX Controller 3.0.0-3.4.0, recovery code required to change a user's password is transmitted and stored in the database in plain text, which al…

Fix: after 3.4.0
Fix from $1,950 2020-07-01
Artemis MEDIUM 5.5
CVE-2020-10727

A flaw was found in ActiveMQ Artemis management API from version 2.7.0 up until 2.12.0, where a user inadvertently stores passwords in plaintext in t…

Fix: after 2.12.0
Fix from $1,600 2020-06-26
Bt Ctroms Terminal HIGH 8.1
CVE-2020-14930

An issue was discovered in BT CTROMS Terminal OS Port Portal CT-464. Account takeover can occur because the password-reset feature discloses the veri…

No fix yet
Fix from $1,950 2020-06-19
Mattermost Server HIGH 7.5
CVE-2018-21248

An issue was discovered in Mattermost Server before 5.4.0. It mishandles possession of superfluous authentication credentials.

Fix: 5.4.0+
Fix from $1,950 2020-06-19
Active Management Technology Firmware HIGH 7.5
CVE-2020-0540

Insufficiently protected credentials in Intel(R) AMT versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to pot…

Fix: 11.8.77 / 11.12.77+
Fix from $1,950 2020-06-15
Openshift Container Platform HIGH 7.5
CVE-2020-10752

A flaw was found in the OpenShift API Server, where it failed to sufficiently protect OAuthTokens by leaking them into the logs when an API Server pa…

Patch available
Fix from $1,950 2020-06-12
Openstack Cinder MEDIUM 6.5
CVE-2020-10755

An insecure-credentials flaw was found in all openstack-cinder versions before openstack-cinder 14.1.0, all openstack-cinder 15.x.x versions before o…

Fix: 14.1.0 / 15.2.0+
Fix from $1,600 2020-06-10
Nextgen Dvr Firmware HIGH 8.1
CVE-2020-11681

Castel NextGen DVR v1.0.0 stores and displays credentials for the associated SMTP server in cleartext. Low privileged users can exploit this to creat…

No fix yet
Fix from $1,950 2020-06-04
Phantompdf MEDIUM 5.3
CVE-2018-21237

An issue was discovered in Foxit PhantomPDF before 8.3.7. It allows NTLM credential theft via a GoToE or GoToR action.

Fix: 8.3.7+
Fix from $1,600 2020-06-04