Vulnerability index

Browse CVEs

1,246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
Applatix MEDIUM 6.5
CVE-2020-2133

Jenkins Applatix Plugin 1.1 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users w…

Fix: after 1.1
Fix from $1,600 2020-02-12
Azure Ad MEDIUM 5.3
CVE-2020-2119

Jenkins Azure AD Plugin 1.1.2 and earlier transmits configured credentials in plain text as part of the global Jenkins configuration form, potentiall…

Fix: after 1.1.2
Fix from $1,600 2020-02-12
S3 Publisher HIGH 7.5
CVE-2020-2114

Jenkins S3 publisher Plugin 0.11.4 and earlier transmits configured credentials in plain text as part of the global Jenkins configuration form, poten…

Fix: after 0.11.4
Fix from $1,950 2020-02-12
C More Ea9 Rhi Firmware CRITICAL 9.8
CVE-2020-6969

It is possible to unmask credentials and other sensitive information on “unprotected” project files, which may allow an attacker to remotely access t…

Fix: 6.53+
Fix from $2,300 2020-02-05
Dir 100 Firmware CRITICAL 9.8
CVE-2013-7055EPSS 7%

D-Link DIR-100 4.03B07 has PPTP and poe information disclosure

No fix yet
Fix from $2,300 2020-02-04
Dir 100 Firmware CRITICAL 9.8
CVE-2013-7052EPSS 25%

D-Link DIR-100 4.03B07: security bypass via an error in the cliget.cgi script

No fix yet
Fix from $2,300 2020-02-04
Mfc 9970cdw Firmware HIGH 7.5
CVE-2013-2672

Brother MFC-9970CDW devices with firmware 0D allow cleartext submission of passwords.

No fix yet
Fix from $1,950 2020-02-03
Prtg Network Monitor MEDIUM 5.5
CVE-2019-19119

An issue was discovered in PRTG 7.x through 19.4.53. Due to insufficient access control on local registry keys for the Core Server Service, a non-adm…

Fix: after 19.4.53.
Fix from $1,600 2020-02-03
Lastpass MEDIUM 6.8
CVE-2013-5113

LastPass prior to 2.5.1 has an insecure PIN implementation.

Fix: 2.5.1+
Fix from $1,600 2020-01-31
Teamcity HIGH 7.5
CVE-2020-7909

In JetBrains TeamCity before 2019.1.5, some server-stored passwords could be shown via the web UI.

Fix: 2019.1.5+
Fix from $1,950 2020-01-30
Fedora HIGH 7.5
CVE-2014-2581

Smb4K before 1.1.1 allows remote attackers to obtain credentials via vectors related to the cuid option in the "Additional options" line edit.

Fix: 1.1.1+
Fix from $1,950 2020-01-28
Sos Webpages CRITICAL 9.8
CVE-2014-3445EPSS 5%

backup.php in HandsomeWeb SOS Webpages before 1.1.12 does not require knowledge of the cleartext password, which allows remote attackers to bypass au…

Fix: 1.1.12+
Fix from $2,300 2020-01-28
Web Viewpoint T0320 MEDIUM 5.5
CVE-2019-19539

An issue was discovered in Idelji Web ViewPoint H01ABO-H01BY and L01ABP-L01ABZ, Web ViewPoint Plus H01AAG-H01AAQ and L01AAH-L01AAR, and Web ViewPoint…

Mitigation only
Fix from $1,600 2020-01-27
A3002ru Firmware HIGH 7.5
CVE-2019-19823EPSS 6%

A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords in flash …

Fix: after 2019-12-12
Fix from $1,950 2020-01-27
Apexpro Telemetry Server Firmware CRITICAL 10.0
CVE-2020-6961

In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X,…

Fix: after 4.2
Fix from $2,300 2020-01-24
D20me Firmware HIGH 7.5
CVE-2012-6663EPSS 9%

General Electric D20ME devices are not properly configured and reveal plaintext passwords.

No fix yet
Fix from $1,950 2020-01-23
Easyinstall HIGH 7.5
CVE-2019-19898

In IXP EasyInstall 6.2.13723, there are cleartext credentials in network communication on TCP port 20050 when using the Administrator console remotel…

No fix yet
Fix from $1,950 2020-01-23
Unleashed CRITICAL 9.8
CVE-2019-19843

Incorrect access control in the web interface in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote credential fetch via an unauthentica…

Fix: 9.10.2.0.84 / 9.12.3.0.136+
Fix from $2,300 2020-01-22
Bac A1616bc Firmware CRITICAL 9.8
CVE-2020-7233

KMS Controls BAC-A1616BC BACnet devices have a cleartext password of snowman in the BACKDOOR_NAME variable in the BC_Logon.swf file.

No fix yet
Fix from $2,300 2020-01-19
Password Manager MEDIUM 5.5
CVE-2019-19696

A RootCA vulnerability found in Trend Micro Password Manager for Windows and macOS exists where the localhost.key of RootCA.crt might be improperly a…

Fix: after 5.0.1047
Fix from $1,600 2020-01-18
Cxf HIGH 7.5
CVE-2019-12423EPSS 6%

Apache CXF ships with a OpenId Connect JWK Keys service, which allows a client to obtain the public keys in JWK format, which can then be used to ver…

Fix: 3.2.12 / 3.3.5+
Fix from $1,950 2020-01-16
Grand Ma300 Firmware CRITICAL 9.8
CVE-2014-5381EPSS 7%

Grand MA 300 allows a brute-force attack on the PIN.

No fix yet
Fix from $2,300 2020-01-13
Manageengine Eventlog Analyzer HIGH 7.5
CVE-2014-6039EPSS 69%

ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability. Fixed version 10 Build 10000.

Fix: after 9.9
Fix from $1,950 2020-01-13
Campaign Enterprise HIGH 7.5
CVE-2012-3823

Arial Campaign Enterprise before 11.0.551 stores passwords in clear text and these may be retrieved.

Fix: 11.0.551+
Fix from $1,950 2020-01-10
Qradar Security Information And Event Manager HIGH 7.8
CVE-2019-4508

IBM QRadar SIEM 7.3.0 through 7.3.3 uses weak credential storage in some instances which could be decrypted by a local attacker. IBM X-Force ID: 1644…

Fix: after 7.3.3
Fix from $1,950 2020-01-10
Status2k CRITICAL 9.8
CVE-2014-5093

Status2k does not remove the install directory allowing credential reset.

No fix yet
Fix from $2,300 2020-01-10
Fortisiem MEDIUM 6.5
CVE-2019-6700

An information exposure vulnerability in the external authentication profile form of FortiSIEM 5.2.2 and earlier may allow an authenticated attacker …

Fix: 5.2.5+
Fix from $1,600 2020-01-07
Cgi An Anlyzer HIGH 7.5
CVE-2019-5990

Access analysis CGI An-Analyzer released in 2019 June 24 and earlier allow remote attackers to obtain a login password via HTTP referer.

Fix: after 2019-06-24
Fix from $1,950 2020-01-06
Netscaler Sdx Firmware HIGH 7.5
CVE-2013-3620

Hardcoded WSMan credentials in Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before 3.15 (…

Fix: 3.12 / 3.15+
Fix from $1,950 2020-01-02
Quay MEDIUM 6.3
CVE-2019-10205

A flaw was found in the way Red Hat Quay stores robot account tokens in plain text. An attacker able to perform database queries in the Red Hat Quay …

Mitigation only
Fix from $1,600 2020-01-02