Vulnerability index

Browse CVEs

1,246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
Watson Studio Local MEDIUM 5.5
CVE-2019-4335

IBM Watson Studio Local 1.2.3 stores key files in the user's home directory which could be obtained by another local user. IBM X-Force ID: 161413.

Patch available
Fix from $1,600 2019-12-30
Omnivista 4760 HIGH 7.5
CVE-2019-20047

An issue was discovered on Alcatel-Lucent OmniVista 4760 devices, and 8770 devices before 4.1.2. An incorrect web server configuration allows a remot…

Fix: 4.1.12+
Fix from $1,950 2019-12-27
Rakuma MEDIUM 6.5
CVE-2019-6024

Rakuma App for Android version 7.15.0 and earlier, and for iOS version 7.16.4 and earlier allows an attacker to bypass authentication and obtain the …

Fix: after 7.16.4
Fix from $1,600 2019-12-26
Zxcloud Goldendata Vap CRITICAL 9.8
CVE-2019-3431

All versions up to V4.01.01.02 of ZTE ZXCLOUD GoldenData VAP product have encryption problems vulnerability. Attackers could sniff unencrypted accoun…

Mitigation only
Fix from $2,300 2019-12-23
Rsa Identity Governance And Lifecycle CRITICAL 9.8
CVE-2019-18572

The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain an Improper Authentication vulnera…

Mitigation only
Fix from $2,300 2019-12-18
Hgb10r 02 Firmware HIGH 7.5
CVE-2019-19890

An issue was discovered on Humax Wireless Voice Gateway HGB10R-2 20160817_1855 devices. Admin credentials are sent over cleartext HTTP.

No fix yet
Fix from $1,950 2019-12-18
Weibo MEDIUM 5.5
CVE-2019-16572

Jenkins Weibo Plugin 1.0.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed…

Fix: after 1.0.1
Fix from $1,600 2019-12-17
Redgate Sql Change Automation MEDIUM 6.5
CVE-2019-16557

Jenkins Redgate SQL Change Automation Plugin 2.0.3 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where the…

Fix: after 2.0.3
Fix from $1,600 2019-12-17
Rundeck MEDIUM 6.5
CVE-2019-16556

Jenkins Rundeck Plugin 3.6.5 and earlier stores credentials unencrypted in its global configuration file and in job config.xml files on the Jenkins m…

Fix: after 3.6.5
Fix from $1,600 2019-12-17
Satellite MEDIUM 5.5
CVE-2014-0241

rubygem-hammer_cli_foreman: File /etc/hammer/cli.modules.d/foreman.yml world readable

Mitigation only
Fix from $1,600 2019-12-13
Keystone HIGH 8.8
CVE-2019-19687

OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API. Any user with a role on a project is able to list any c…

Patch available
Fix from $1,950 2019-12-09
Ie Sw Pl09m 5gc 4gt Firmware CRITICAL 9.8
CVE-2019-16672

An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 dev…

Fix: after 3.4.4
Fix from $2,300 2019-12-06
Ie Sw Pl09m 5gc 4gt Firmware MEDIUM 6.5
CVE-2019-16673

An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 dev…

Fix: after 3.4.4
Fix from $1,600 2019-12-06
Debian Linux HIGH 7.5
CVE-2013-2106

webauth before 4.6.1 has authentication credential disclosure

Fix: 4.6.1+
Fix from $1,950 2019-12-03
Vcalendar MEDIUM 5.5
CVE-2012-5527

Claws Mail vCalendar plugin: credentials exposed on interface

No fix yet
Fix from $1,600 2019-11-25
Openshift Container Platform MEDIUM 5.9
CVE-2019-10214

The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Con…

Patch available
Fix from $1,600 2019-11-25
Ansible MEDIUM 6.5
CVE-2019-10206

ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by …

Fix: 2.6.19 / 2.7.13+
Fix from $1,600 2019-11-22
Nexus 543 Firmware HIGH 7.5
CVE-2013-3313

The Loftek Nexus 543 IP Camera stores passwords in cleartext, which allows remote attackers to obtain sensitive information via an HTTP GET request t…

No fix yet
Fix from $1,950 2019-11-21
Anchore Container Image Scanner MEDIUM 6.5
CVE-2019-16542

Jenkins Anchore Container Image Scanner Plugin 1.0.19 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where …

Fix: after 1.0.19
Fix from $1,600 2019-11-21
Spira Importer MEDIUM 5.5
CVE-2019-16543

Jenkins Spira Importer Plugin 3.2.2 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can …

Fix: after 3.2.2
Fix from $1,600 2019-11-21
Jenkins Qmetry For Jira HIGH 8.8
CVE-2019-16544

Jenkins QMetry for JIRA - Test Management Plugin 1.12 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where …

Fix: after 1.12
Fix from $1,950 2019-11-21
Media Server MEDIUM 6.5
CVE-2018-21031

Tautulli versions 2.1.38 and below allows remote attackers to bypass intended access control in Plex Media Server because the X-Plex-Token is mishand…

No fix yet
Fix from $1,600 2019-11-18
Advanced Threat Defense HIGH 7.8
CVE-2019-3663

Unprotected Storage of Credentials vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows local attacker to gain access to the roo…

Fix: 4.8+
Fix from $1,950 2019-11-14
Windows 10 CRITICAL 9.9
CVE-2019-1384EPSS 6%

A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages.To exploit this vulnerabi…

Patch available
Fix from $2,300 2019-11-12
Fedora MEDIUM 5.5
CVE-2010-4178

MySQL-GUI-tools (mysql-administrator) leaks passwords into process list after with launch of mysql text console

Mitigation only
Fix from $1,600 2019-11-06
Clearpass CRITICAL 9.8
CVE-2016-4401

Aruba ClearPass Policy Manager before 6.5.7 and 6.6.x before 6.6.2 allows attackers to obtain database credentials.

Fix: 6.5.7 / 6.6.2+
Fix from $2,300 2019-11-06
Cloudforms MEDIUM 5.5
CVE-2013-4423

CloudForms stores user passwords in recoverable format

Mitigation only
Fix from $1,600 2019-11-04
PostgreSQL HIGH 7.0
CVE-2019-10210

Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via superuser writing password to unprotected temporar…

Fix: 9.4.24 / 9.5.19+
Fix from $1,950 2019-10-29
Security Guardium Big Data Intelligence MEDIUM 5.5
CVE-2019-4307

IBM Security Guardium Big Data Intelligence (SonarG) 4.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Forc…

Patch available
Fix from $1,600 2019-10-29
Smartrtu Firmware CRITICAL 9.8
CVE-2019-14929

An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Stored cleartext password…

Fix: after 3.0
Fix from $2,300 2019-10-28