Vulnerability index

Browse CVEs

1,246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
Ap9630 Firmware CRITICAL 9.8
CVE-2018-7820

A Credentials Management CWE-255 vulnerability exists in the APC UPS Network Management Card 2 AOS v6.5.6, which could cause Remote Monitoring Creden…

Fix: 6.7.2+
Fix from $2,300 2019-09-17
Beaker Builder MEDIUM 5.5
CVE-2019-10398

Jenkins Beaker Builder Plugin 1.9 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could …

Fix: after 1.9
Fix from $1,600 2019-09-12
Teamviewer HIGH 7.8
CVE-2019-11769

An issue was discovered in TeamViewer 14.2.2558. Updating the product as a non-administrative user requires entering administrative credentials into …

Mitigation only
Fix from $1,950 2019-09-11
Knowage HIGH 8.8
CVE-2019-13348

In Knowage through 6.1.1, an authenticated user who accesses the datasources page will gain access to any data source credentials in cleartext, which…

Fix: 6.4+
Fix from $1,950 2019-08-28
Zt610 Firmware HIGH 7.5
CVE-2019-10960

Zebra Industrial Printers All Versions, Zebra printers are shipped with unrestricted end-user access to front panel options. If the option to use a p…

Mitigation only
Fix from $1,950 2019-08-20
Emc Powerconnect 8024 Firmware MEDIUM 6.5
CVE-2019-3753

Dell EMC PowerConnect 8024, 7000, M6348, M6220, M8024 and M8024-K running firmware versions prior to 5.1.15.2 contain a plain-text password storage v…

Fix: 5.1.15.2+
Fix from $1,600 2019-08-20
Gradle CRITICAL 9.8
CVE-2019-15052

The HTTP client in Gradle before 5.6 sends authentication credentials originally destined for the configured host. If that host returns a 30x redirec…

Fix: 5.6+
Fix from $2,300 2019-08-14
Testlink MEDIUM 5.3
CVE-2019-10378

Jenkins TestLink Plugin 3.16 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be view…

Fix: after 3.16
Fix from $1,600 2019-08-07
Cloud Messaging Notification MEDIUM 6.5
CVE-2019-10379

Jenkins Google Cloud Messaging Notification Plugin 1.0 and earlier stores credentials unencrypted in its global configuration file on the Jenkins mas…

Fix: after 1.0
Fix from $1,600 2019-08-07
Eggplant MEDIUM 6.5
CVE-2019-10385

Jenkins eggPlant Plugin 2.2 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by user…

Fix: after 2.2
Fix from $1,600 2019-08-07
Mdc N4090 Firmware CRITICAL 9.8
CVE-2019-14709

A cleartext password storage issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. The file in question is /usr/loc…

Fix: after 6400.0.8.5
Fix from $2,300 2019-08-06
Elasticsearch HIGH 7.8
CVE-2019-3800

CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --c…

Fix: 1.16.0 / 2.1.2+
Fix from $1,950 2019-08-05
Skytap Cloud Ci MEDIUM 6.5
CVE-2019-10366

Jenkins Skytap Cloud CI Plugin 2.06 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be view…

Fix: after 2.06
Fix from $1,600 2019-07-31
Configuration As Code MEDIUM 5.5
CVE-2019-10345

Jenkins Configuration as Code Plugin 1.20 and earlier did not treat the proxy password as a secret to be masked when logging or encrypted for export.

Fix: 1.20+
Fix from $1,600 2019-07-31
M2release MEDIUM 5.5
CVE-2019-10361

Jenkins Maven Release Plugin 0.14.0 and earlier stored credentials unencrypted on the Jenkins master where they could be viewed by users with access …

Fix: after 0.14.0
Fix from $1,600 2019-07-31
Fleet HIGH 7.5
CVE-2019-1020009

Fleet before 2.1.2 allows exposure of SMTP credentials.

Fix: after 2.1.1
Fix from $1,950 2019-07-29
Credentials Binding MEDIUM 6.5
CVE-2019-1010241

Jenkins Credentials Binding Plugin Jenkins 1.17 is affected by: CWE-257: Storing Passwords in a Recoverable Format. The impact is: Authenticated user…

No fix yet
Fix from $1,600 2019-07-19
Shift HIGH 7.5
CVE-2019-8932

Redbrick Shift through 3.4.3 allows an attacker to extract authentication tokens of services (such as Gmail, Outlook, etc.) used in the application.

Fix: after 3.4.3
Fix from $1,950 2019-07-17
Aquarius Cms CRITICAL 9.8
CVE-2019-1010308

Aquaverde GmbH Aquarius CMS prior to version 4.1.1 is affected by: Incorrect Access Control. The impact is: The access to the log file is not restric…

Fix: 4.1.1+
Fix from $2,300 2019-07-15
Adc V522ir Firmware HIGH 7.8
CVE-2019-9657

Alarm.com ADC-V522IR 0100b9 devices have Incorrect Access Control, a different issue than CVE-2018-19588. This occurs because of incorrect protection…

No fix yet
Fix from $1,950 2019-07-11
Mashup Portlets HIGH 8.8
CVE-2019-10347

Jenkins Mashup Portlets Plugin stored credentials unencrypted on the Jenkins master where they can be viewed by users with access to the master file …

Fix: after 1.0.9
Fix from $1,950 2019-07-11
Dropbox HIGH 7.8
CVE-2019-12171

Dropbox.exe (and QtWebEngineProcess.exe in the Web Helper) in the Dropbox desktop application 71.4.108.0 store cleartext credentials in memory upon s…

No fix yet
Fix from $1,950 2019-07-08
Fcm Mb40 Firmware CRITICAL 9.8
CVE-2019-13400

Dynacolor FCM-MB40 v1.2.0.0 use /etc/appWeb/appweb.pass to store administrative web-interface credentials in cleartext. These credentials can be retr…

No fix yet
Fix from $2,300 2019-07-08
Intellij Idea CRITICAL 9.8
CVE-2019-9823

In several JetBrains IntelliJ IDEA versions, creating remote run configurations of JavaEE application servers leads to saving a cleartext record of t…

Fix: 2018.1.8 / 2018.2.8+
Fix from $2,300 2019-07-03
Intellij Idea HIGH 8.1
CVE-2019-9872

In several versions of JetBrains IntelliJ IDEA Ultimate, creating run configurations for cloud application servers leads to saving a cleartext unencr…

Fix: 2018.1.8 / 2018.2.8+
Fix from $1,950 2019-07-03
Intellij Idea CRITICAL 9.8
CVE-2019-9873

In several versions of JetBrains IntelliJ IDEA Ultimate, creating Task Servers configurations leads to saving a cleartext unencrypted record of the s…

Fix: 2019.1+
Fix from $2,300 2019-07-03
Hub HIGH 7.2
CVE-2019-12847

In JetBrains Hub versions earlier than 2018.4.11298, the audit events for SMTPSettings show a cleartext password to the admin user. It is only releva…

Fix: 2018.4.11298+
Fix from $1,950 2019-07-03
Calamares HIGH 7.5
CVE-2019-13179

Calamares versions 3.1 through 3.2.10 copies a LUKS encryption keyfile from /crypto_keyfile.bin (mode 0600 owned by root) to /boot within a globally …

Fix: after 3.2.10
Fix from $1,950 2019-07-02
Linear Emerge Essential Firmware CRITICAL 9.8
CVE-2019-7260EPSS 7%

Linear eMerge E3-Series devices have Cleartext Credentials in a Database.

Fix: after 1.00-06
Fix from $2,300 2019-07-02
Linear Emerge 50p Firmware CRITICAL 9.8
CVE-2019-7271

Nortek Linear eMerge 50P/5000P devices have Default Credentials.

Fix: after 4.6.07
Fix from $2,300 2019-07-01