Vulnerability index

Browse CVEs

1,246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
Android MEDIUM 6.5
CVE-2017-18695

An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.0) software. Attackers (who control a certain subdomain) …

Mitigation only
Fix from $1,600 2020-04-07
Android HIGH 7.5
CVE-2016-11029

An issue was discovered on Samsung mobile devices with L(5.0/5.1), M(6.0), and N(7.0) software. Attackers can read the password of the Mobile Hotspot…

Mitigation only
Fix from $1,950 2020-04-07
Esoms MEDIUM 6.1
CVE-2019-19096

The Redis data structure component used in ABB eSOMS versions 6.0 to 6.0.2 stores credentials in clear text. If an attacker has file system access, t…

Fix: after 6.0.2
Fix from $1,600 2020-04-02
Webaccess HIGH 7.5
CVE-2019-3942

Advantech WebAccess 8.3.4 does not properly restrict an RPC call that allows unauthenticated, remote users to read files. An attacker can use this vu…

Mitigation only
Fix from $1,950 2020-04-01
Tc7337 Firmware HIGH 7.5
CVE-2020-11449

An issue was discovered on Technicolor TC7337 8.89.17 devices. An attacker can discover admin credentials in the backup file, aka backupsettings.conf.

No fix yet
Fix from $1,950 2020-04-01
Artifactory MEDIUM 6.5
CVE-2020-2164

Jenkins Artifactory Plugin 3.5.0 and earlier stores its Artifactory server password unencrypted in its global configuration file on the Jenkins maste…

Fix: after 3.5.0
Fix from $1,600 2020-03-25
Artifactory HIGH 7.5
CVE-2020-2165

Jenkins Artifactory Plugin 3.6.0 and earlier transmits configured passwords in plain text as part of its global Jenkins configuration form, potential…

Fix: after 3.6.0
Fix from $1,950 2020-03-25
Suitecrm HIGH 7.5
CVE-2019-18785

SuiteCRM 7.10.x prior to 7.10.21 and 7.11.x prior to 7.11.9 mishandles API access tokens and credentials.

Fix: 7.10.21 / 7.11.9+
Fix from $1,950 2020-03-20
Enigma Network Management Solution HIGH 7.5
CVE-2019-16067

NETSAS Enigma NMS 65.0.0 and prior utilises basic authentication over HTTP for enforcing access control to the web application. The use of weak authe…

Fix: after 65.0.0
Fix from $1,950 2020-03-19
Ap2600 I A02 0202n00pd2 Firmware HIGH 7.5
CVE-2019-15653

Comba AP2600-I devices through A02,0202N00PD2 are prone to password disclosure via an insecure authentication mechanism. The HTML source code of the …

No fix yet
Fix from $1,950 2020-03-19
Dsl 2875al Firmware HIGH 7.5
CVE-2019-15655

D-Link DSL-2875AL devices through 1.00.05 are prone to password disclosure via a simple crafted /romfile.cfg request to the web management server. Th…

Fix: after 1.00.05
Fix from $1,950 2020-03-19
Dsl 2875al Firmware HIGH 7.5
CVE-2019-15656

D-Link DSL-2875AL and DSL-2877AL devices through 1.00.05 are prone to information disclosure via a simple crafted request to index.asp on the web man…

Fix: after 1.00.05
Fix from $1,950 2020-03-19
Tiff Server HIGH 7.5
CVE-2020-9324

Aquaforest TIFF Server 4.0 allows Unauthenticated SMB Hash Capture via UNC.

No fix yet
Fix from $1,950 2020-03-18
Cg3700b Firmware CRITICAL 9.8
CVE-2019-13394

The Voo branded NETGEAR CG3700b custom firmware V2.02.03 uses HTTP Basic Authentication over cleartext HTTP.

No fix yet
Fix from $2,300 2020-03-13
Load Balancer Adc Firmware MEDIUM 6.5
CVE-2019-5648

Authenticated, administrative access to a Barracuda Load Balancer ADC running unpatched firmware <= v6.4 allows one to edit the LDAP service configur…

Fix: after 6.4
Fix from $1,600 2020-03-12
Mb3170 Firmware HIGH 7.5
CVE-2019-9104

An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB31…

Fix: after 4.0
Fix from $1,950 2020-03-11
Sandisk X600 Sd9tb8w 128g Firmware HIGH 7.5
CVE-2019-10705

Western Digital SanDisk X600 devices in certain configurations, a vulnerability in the access control mechanism of the drive may allow data to be dec…

Mitigation only
Fix from $1,950 2020-03-10
Sandisk X600 Sd9tb8w 128g Firmware MEDIUM 6.3
CVE-2019-10706

Western Digital SanDisk SanDisk X300, X300s, X400, and X600 devices: The firmware update authentication method relies on a symmetric HMAC digest. The…

Mitigation only
Fix from $1,600 2020-03-10
Sandisk X600 Sd9tb8w 128g Firmware MEDIUM 5.5
CVE-2019-11686

Western Digital SanDisk X300, X300s, X400, and X600 devices: A vulnerability in the wear-leveling algorithm of the drive may cause cryptographically …

Mitigation only
Fix from $1,600 2020-03-10
Zephyr Enterprise Test Management MEDIUM 5.5
CVE-2020-2145

Jenkins Zephyr Enterprise Test Management Plugin 1.9.1 and earlier stores its Zephyr password in plain text on the Jenkins master file system.

Fix: after 1.9.1
Fix from $1,600 2020-03-09
Reactor Netty MEDIUM 5.9
CVE-2020-5404

The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorrectly, leading to a credentia…

Fix: after 0.9.4
Fix from $1,600 2020-03-03
Ubuntu Linux MEDIUM 6.5
CVE-2020-6794

If a user saved passwords before Thunderbird 60 and then later set a master password, an unencrypted copy of these passwords is still accessible. Thi…

Fix: 68.5.0+
Fix from $1,600 2020-03-02
Safari MEDIUM 6.5
CVE-2020-3841

The issue was addressed with improved UI handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, Safari 13.0.5. A local user may unknowingly s…

Fix: 13.0.5 / 13.3.1+
Fix from $1,600 2020-02-27
Capi Release MEDIUM 6.5
CVE-2020-5400

Cloud Foundry Cloud Controller (CAPI), versions prior to 1.91.0, logs properties of background jobs when they are run, which may include sensitive in…

Fix: 1.91.0 / 12.33.0+
Fix from $1,600 2020-02-27
Ansible MEDIUM 5.5
CVE-2014-4659

Ansible before 1.5.5 sets 0644 permissions for sources.list, which might allow local users to obtain sensitive credential information in opportunisti…

Fix: 1.5.5+
Fix from $1,600 2020-02-20
Ansible MEDIUM 5.5
CVE-2014-4660

Ansible before 1.5.5 constructs filenames containing user and password fields on the basis of deb lines in sources.list, which might allow local user…

Fix: 1.5.5+
Fix from $1,600 2020-02-20
Eagle Tester MEDIUM 6.5
CVE-2020-2129

Jenkins Eagle Tester Plugin 1.0.9 and earlier stores a password unencrypted in its global configuration file on the Jenkins master where it can be vi…

Fix: after 1.0.9
Fix from $1,600 2020-02-12
Harvest Scm MEDIUM 6.5
CVE-2020-2130

Jenkins Harvest SCM Plugin 0.5.1 and earlier stores a password unencrypted in its global configuration file on the Jenkins master where it can be vie…

Fix: after 0.5.1
Fix from $1,600 2020-02-12
Harvest Scm MEDIUM 6.5
CVE-2020-2131

Jenkins Harvest SCM Plugin 0.5.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins master where they can be viewed by u…

Fix: after 0.5.1
Fix from $1,600 2020-02-12
Parasoft Environment Manager MEDIUM 6.5
CVE-2020-2132

Jenkins Parasoft Environment Manager Plugin 2.14 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can…

Fix: after 2.14
Fix from $1,600 2020-02-12