Vulnerability index

Browse CVEs

1,246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
Phantompdf MEDIUM 5.3
CVE-2018-21239

An issue was discovered in Foxit Reader and PhantomPDF before 9.2. It allows NTLM credential theft via a GoToE or GoToR action.

Fix: 9.2+
Fix from $1,600 2020-06-04
Ip Office MEDIUM 5.5
CVE-2020-7030

A sensitive information disclosure vulnerability was discovered in the web interface component of IP Office that may potentially allow a local user t…

Fix: after 11.0.4.2
Fix from $1,600 2020-06-04
Project Inheritance MEDIUM 6.5
CVE-2020-2198

Jenkins Project Inheritance Plugin 19.08.02 and earlier does not redact encrypted secrets in the 'getConfigAsXML' API URL when transmitting job confi…

Fix: after 19.08.02
Fix from $1,600 2020-06-03
Lexiglot HIGH 7.8
CVE-2014-8938

Lexiglot through 2014-11-20 allows local users to obtain sensitive information by listing a process because the username and password are on the comm…

Fix: after 2014-11-20
Fix from $1,950 2020-06-01
Cmfive HIGH 7.5
CVE-2014-9702

system/classes/DbPDO.php in Cmfive through 2015-03-15, when database connectivity malfunctions, allows remote attackers to obtain sensitive informati…

Fix: after 2015-03-15
Fix from $1,950 2020-06-01
Jetselect MEDIUM 6.5
CVE-2019-13023

An issue was discovered in all versions of Bond JetSelect. Within the JetSelect Application, the web interface hides RADIUS secrets, WPA passwords, a…

Mitigation only
Fix from $1,600 2020-05-14
Signond MEDIUM 5.5
CVE-2014-1423

signond before 8.57+15.04.20141127.1-0ubuntu1, as used in Ubuntu Touch, did not properly restrict applications from querying oath tokens due to incor…

Fix: 8.57+
Fix from $1,600 2020-05-07
Wn530hg4 Firmware HIGH 7.5
CVE-2020-10972

An issue was discovered where a page is exposed that has the current administrator password in cleartext in the source code of the page. No authentic…

Mitigation only
Fix from $1,950 2020-05-07
Remote Kiln Control CRITICAL 9.8
CVE-2019-18868

Blaauw Remote Kiln Control through v3.00r4 allows an unauthenticated attacker to access MySQL credentials in cleartext in /engine/db.inc, /lang/nl.ba…

Fix: after 3.0.0
Fix from $2,300 2020-05-07
Credentials Binding MEDIUM 6.5
CVE-2020-2181

Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets in the build log when the build contains no …

Fix: after 1.22
Fix from $1,600 2020-05-06
Control M\/agent HIGH 7.5
CVE-2019-19218

BMC Control-M/Agent 7.0.00.000 has Insecure Password Storage.

Mitigation only
Fix from $1,950 2020-04-30
Rukovoditel MEDIUM 5.3
CVE-2020-11821

In Rukovoditel 2.5.2, users' passwords and usernames are stored in a cookie with URL encoding, base64 encoding, and hashing. Thus, an attacker can ea…

No fix yet
Fix from $1,600 2020-04-27
Testlink HIGH 7.5
CVE-2020-12273

In TestLink 1.9.20, a crafted login.php viewer parameter exposes cleartext credentials.

Patch available
Fix from $1,950 2020-04-27
Urbancode Deploy MEDIUM 5.5
CVE-2019-4668

IBM UrbanCode Deploy (UCD) 7.0.4.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 171250.

Fix: 7.0.4.0+
Fix from $1,600 2020-04-23
Tg\/s3.2 Firmware MEDIUM 5.5
CVE-2019-19105

The backup function in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway saves the current settings and configuration of the ap…

Mitigation only
Fix from $1,600 2020-04-22
D6220 Firmware HIGH 7.8
CVE-2017-18777

Certain NETGEAR devices are affected by administrative password disclosure. This affects D6220 before V1.0.0.28, D6400 before V1.0.0.60, D8500 before…

Fix: 1.0.0.28 / 1.0.0.60+
Fix from $1,950 2020-04-22
Git HIGH 7.5
CVE-2020-11008

Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. This b…

Fix: 2.17.5 / 2.18.4+
Fix from $1,950 2020-04-21
R6700 Firmware HIGH 7.8
CVE-2017-18843

Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects R6700v2 before 1.1.0.38, R6800 before 1.1.0.38, and D7…

Fix: 1.0.1.50 / 1.1.0.38+
Fix from $1,950 2020-04-20
R6700 Firmware HIGH 7.8
CVE-2017-18844

Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects R6700v2 before 1.1.0.38, R6800 before 1.1.0.38, and D7…

Fix: 1.0.1.50 / 1.1.0.38+
Fix from $1,950 2020-04-20
R6700 Firmware HIGH 7.8
CVE-2017-18845

Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects R6700v2 before 1.1.0.38 and R6800 before 1.1.0.38.

Fix: 1.1.0.38+
Fix from $1,950 2020-04-20
Enterprise Developer HIGH 8.8
CVE-2020-9523

Insufficiently protected credentials vulnerability on Micro Focus enterprise developer and enterprise server, affecting all version prior to 4.0 Patc…

Fix: after 3.0
Fix from $1,950 2020-04-17
Winbox MEDIUM 5.5
CVE-2020-5721

MikroTik WinBox 3.22 and below stores the user's cleartext password in the settings.cfg.viw configuration file when the Keep Password field is set an…

Fix: after 3.22
Fix from $1,600 2020-04-15
Git HIGH 7.5
CVE-2020-5260EPSS 10%

Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. Git us…

Fix: 2.17.4 / 2.18.3+
Fix from $1,950 2020-04-14
Businessobjects Business Intelligence Platform CRITICAL 9.8
CVE-2020-6195

SAP Business Objects Business Intelligence Platform (CMC), version 4.1, 4.2, shows cleartext password in the response, leading to Information Disclos…

Mitigation only
Fix from $2,300 2020-04-14
Pycharm HIGH 7.5
CVE-2020-11694

In JetBrains PyCharm 2019.2.5 and 2019.3 on Windows, Apple Notarization Service credentials were included. This is fixed in 2019.2.6 and 2019.3.3.

No fix yet
Fix from $1,950 2020-04-10
Tanzu Application Service For Vms MEDIUM 6.5
CVE-2020-5406

VMware Tanzu Application Service for VMs, 2.6.x versions prior to 2.6.18, 2.7.x versions prior to 2.7.11, and 2.8.x versions prior to 2.8.5, includes…

Fix: 2.6.18 / 2.7.11+
Fix from $1,600 2020-04-10
Snmpc Online HIGH 7.5
CVE-2020-11555

An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It allows remote attackers to obtain sensitive credential information…

Fix: 2020-01-28+
Fix from $1,950 2020-04-09
Snmpc Online HIGH 7.5
CVE-2020-11557

An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It includes the username and password values in cleartext within each…

Fix: 2020-01-28+
Fix from $1,950 2020-04-09
Ejbca HIGH 7.2
CVE-2020-11629

An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. The External Command Certificate Validator, which allows administrators to u…

Fix: 6.15.2.6 / 7.3.1.2+
Fix from $1,950 2020-04-08
Express Invoice HIGH 7.8
CVE-2020-11560

NCH Express Invoice 7.25 allows local users to discover the cleartext password by reading the configuration file.

No fix yet
Fix from $1,950 2020-04-07