Vulnerability index

Browse CVEs

1,246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
Zulip HIGH 7.8
CVE-2019-10476

Jenkins Zulip Plugin 1.1.0 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be view…

Fix: after 1.1.0
Fix from $1,950 2019-10-23
Mattermost Notification MEDIUM 6.5
CVE-2019-10459

Jenkins Mattermost Notification Plugin 2.7.0 and earlier stored webhook URLs containing a secret token unencrypted in its global configuration file a…

Fix: after 2.7.0
Fix from $1,600 2019-10-23
Bitbucket Oauth HIGH 7.8
CVE-2019-10460

Jenkins Bitbucket OAuth Plugin 0.9 and earlier stored credentials unencrypted in the global config.xml configuration file on the Jenkins master where…

Fix: after 0.9
Fix from $1,950 2019-10-23
Dynatrace Application Monitoring HIGH 7.8
CVE-2019-10461

Jenkins Dynatrace Application Monitoring Plugin 2.1.3 and earlier stored credentials unencrypted in its global configuration file on the Jenkins mast…

Fix: after 2.1.3
Fix from $1,950 2019-10-23
Sonar Gerrit MEDIUM 6.5
CVE-2019-10467

Jenkins Sonar Gerrit Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Exten…

Fix: after 2.3
Fix from $1,600 2019-10-23
Server CRITICAL 9.8
CVE-2019-17393

The Customer's Tomedo Server in Version 1.7.3 communicates to the Vendor Tomedo Server via HTTP (in cleartext) that can be sniffed by unauthorized ac…

No fix yet
Fix from $2,300 2019-10-18
Reactor Netty HIGH 8.6
CVE-2019-11284

Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones. A remote unauthenticated malicious u…

Fix: 0.8.11+
Fix from $1,950 2019-10-17
Thinvnc CRITICAL 9.8
CVE-2019-17662EPSS 97%

ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exists even when authentication …

No fix yet
Fix from $2,300 2019-10-16
Extensive Testing HIGH 8.8
CVE-2019-10448

Jenkins Extensive Testing Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with …

Mitigation only
Fix from $1,950 2019-10-16
Infinite Design MEDIUM 6.5
CVE-2019-17356

The Infinite Design application 3.4.12 for Android sends a username and password via TCP without any encryption during login, as demonstrated by snif…

No fix yet
Fix from $1,600 2019-10-15
Pdf Xchange Editor MEDIUM 6.5
CVE-2019-17497EPSS 6%

Tracker PDF-XChange Editor before 8.0.330.0 has an NTLM SSO hash theft vulnerability using crafted FDF or XFDF files (a related issue to CVE-2018-499…

Fix: 8.0.330.0+
Fix from $1,600 2019-10-11
Explorer 710 Firmware CRITICAL 9.8
CVE-2019-9533

The root password of the Cobham EXPLORER 710 is the same for all versions of firmware up to and including v1.08. This could allow an attacker to reve…

Mitigation only
Fix from $2,300 2019-10-10
Sbr Carrier MEDIUM 5.5
CVE-2019-0072

An Unprotected Storage of Credentials vulnerability in the identity and access management certificate generation procedure allows a local attacker to…

Mitigation only
Fix from $1,600 2019-10-09
Gitlab Logo MEDIUM 5.5
CVE-2019-10429

Jenkins GitLab Logo Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users wi…

Fix: after 1.0.3
Fix from $1,600 2019-09-25
Data Theorem Mobile App Security MEDIUM 6.5
CVE-2019-10413

Jenkins Data Theorem: CI/CD Plugin 1.3 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be v…

Fix: after 1.3
Fix from $1,600 2019-09-25
Git Changelog MEDIUM 6.5
CVE-2019-10414

Jenkins Git Changelog Plugin 2.17 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be viewed…

Fix: after 2.17
Fix from $1,600 2019-09-25
Violation Comments To Gitlab MEDIUM 6.5
CVE-2019-10415

Jenkins Violation Comments to GitLab Plugin 2.28 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master wh…

Fix: after 2.28
Fix from $1,600 2019-09-25
Violation Comments To Gitlab MEDIUM 6.5
CVE-2019-10416

Jenkins Violation Comments to GitLab Plugin 2.28 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they …

Fix: after 2.28
Fix from $1,600 2019-09-25
Vfabric Application Director MEDIUM 5.5
CVE-2019-10419

Jenkins vFabric Application Director Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be v…

Fix: after 1.3
Fix from $1,600 2019-09-25
Assembla MEDIUM 5.5
CVE-2019-10420

Jenkins Assembla Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with …

Fix: after 1.4
Fix from $1,600 2019-09-25
Call Remote Job MEDIUM 6.5
CVE-2019-10422

Jenkins Call Remote Job Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Ex…

Fix: after 1.0.21
Fix from $1,600 2019-09-25
Codescan MEDIUM 5.5
CVE-2019-10423

Jenkins CodeScan Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with …

Fix: after 0.11
Fix from $1,600 2019-09-25
Eloyente MEDIUM 5.5
CVE-2019-10424

Jenkins elOyente Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with …

Fix: after 1.3
Fix from $1,600 2019-09-25
Google Calendar MEDIUM 6.5
CVE-2019-10425

Jenkins Google Calendar Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Ex…

Fix: after 0.4
Fix from $1,600 2019-09-25
Gem Publisher MEDIUM 5.5
CVE-2019-10426

Jenkins Gem Publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users …

Fix: after 1.0
Fix from $1,600 2019-09-25
Ontap Select Deploy Administration Utility CRITICAL 9.8
CVE-2019-5505

ONTAP Select Deploy administration utility versions 2.2 through 2.12.1 transmit credentials in plaintext.

Fix: after 2.12.1
Fix from $2,300 2019-09-24
X11dai N Firmware CRITICAL 10.0
CVE-2019-16649

On Supermicro H11, H12, M11, X9, X10, and X11 products, a combination of encryption and authentication problems in the virtual media service allows c…

Mitigation only
Fix from $2,300 2019-09-21
Service Manager MEDIUM 6.5
CVE-2019-11663

Clear text credentials are used to access managers app in Tomcat in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, …

Fix: after 9.62
Fix from $1,600 2019-09-18
Service Manager MEDIUM 6.5
CVE-2019-11664

Clear text password in browser in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60…

Fix: after 9.62
Fix from $1,600 2019-09-18
Vcenter Server HIGH 7.7
CVE-2019-5534

VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains an information disclosure vulnerability where Vi…

No fix yet
Fix from $1,950 2019-09-18