Vulnerability index

Browse CVEs

1,246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
R500 Firmware MEDIUM 6.5
CVE-2019-13054

The Logitech R500 presentation clicker allows attackers to determine the AES key, leading to keystroke injection. On Windows, any text may be injecte…

No fix yet
Fix from $1,600 2019-06-29
Spring Security HIGH 7.3
CVE-2019-11272

Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPasswordEncoder. If an appli…

Fix: 4.2.13+
Fix from $1,950 2019-06-26
Spectrum Protect Plus MEDIUM 6.5
CVE-2019-4385

IBM Spectrum Protect Plus 10.1.2 may display the vSnap CIFS password in the IBM Spectrum Protect Plus Joblog. This can result in an attacker gaining …

Fix: after 10.1.2.303
Fix from $1,600 2019-06-19
Bosh HIGH 7.8
CVE-2019-11271

Cloud Foundry BOSH 270.x versions prior to v270.1.1, contain a BOSH Director that does not properly redact credentials when configured to use a MySQL…

Fix: 270.1.1+
Fix from $1,950 2019-06-19
Cloud Private MEDIUM 5.5
CVE-2019-4239

IBM MQ Advanced Cloud Pak (IBM Cloud Private 1.0.0 through 3.0.1) stores user credentials in plain in clear text which can be read by a local user. I…

Fix: after 3.0.1
Fix from $1,600 2019-06-14
V Server CRITICAL 9.8
CVE-2019-3947

Fuji Electric V-Server before 6.0.33.0 stores database credentials in project files as plaintext. An attacker that can gain access to the project fil…

Fix: 6.0.33.0+
Fix from $2,300 2019-06-12
Scalance X 200 Firmware MEDIUM 5.5
CVE-2019-6567

A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All Versions < V5.2.4), SCALANCE X-200IRT switch fam…

Fix: 5.2.4+
Fix from $1,600 2019-06-12
Python CRITICAL 9.8
CVE-2019-10160EPSS 5%

A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.…

Fix: 2.7.17 / 3.5.8+
Fix from $2,300 2019-06-07
Command Center Rx HIGH 8.8
CVE-2019-6452

Kyocera Command Center RX TASKalfa4501i and TASKalfa5052ci allows remote attackers to abuse the Test button in the machine address book to obtain a c…

No fix yet
Fix from $1,950 2019-06-06
Solar Data Recorder CRITICAL 9.8
CVE-2019-11367

An issue was discovered in AUO Solar Data Recorder before 1.3.0. The web portal uses HTTP Basic Authentication and provides the account and password …

Fix: 1.3.0+
Fix from $2,300 2019-06-03
Pcoweb Card Firmware HIGH 8.8
CVE-2019-11369EPSS 8%

An issue was discovered in Carel pCOWeb prior to B1.2.4. In /config/pw_changeusers.html the device stores cleartext passwords, which may allow sensit…

No fix yet
Fix from $1,950 2019-06-03
Citectscada HIGH 7.8
CVE-2019-10981

In Vijeo Citect 7.30 and 7.40, and CitectSCADA 7.30 and 7.40, a vulnerability has been identified that may allow an authenticated local user access t…

Patch available
Fix from $1,950 2019-05-31
Influxdb HIGH 8.8
CVE-2019-10329

Jenkins InfluxDB Plugin 1.21 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they can be view…

Fix: after 1.21
Fix from $1,950 2019-05-31
Traefik HIGH 7.5
CVE-2019-12452

types/types.go in Containous Traefik 1.7.x through 1.7.11, when the --api flag is used and the API is publicly reachable and exposed without sufficie…

Fix: after 1.7.11
Fix from $1,950 2019-05-29
Spectrum Control MEDIUM 5.9
CVE-2019-4138

IBM Tivoli Storage Productivity Center 5.2.13 through 5.3.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to…

Fix: after 5.3.2.0
Fix from $1,600 2019-05-29
Halo Home HIGH 7.1
CVE-2019-5625

The Android mobile application Halo Home before 1.11.0 stores OAuth authentication and refresh access tokens in a clear text file. This file persists…

No fix yet
Fix from $1,950 2019-05-22
Bluecats Reveal HIGH 7.8
CVE-2019-5626

The Android mobile application BlueCats Reveal before 3.0.19 stores the username and password in a clear text file. This file persists until the user…

Fix: 3.0.19+
Fix from $1,950 2019-05-22
Bc Reveal HIGH 7.8
CVE-2019-5627

The iOS mobile application BlueCats Reveal before 5.14 stores the username and password in the app cache as base64 encoded strings, i.e. clear text. …

Fix: 5.14+
Fix from $1,950 2019-05-22
Debian Linux CRITICAL 9.8
CVE-2019-12046

LemonLDAP::NG -2.0.3 has Incorrect Access Control.

No fix yet
Fix from $2,300 2019-05-22
Cockpit Ovirt HIGH 7.8
CVE-2019-10139

During HE deployment via cockpit-ovirt, cockpit-ovirt generates an ansible variable file `/var/lib/ovirt-hosted-engine-setup/cockpit/ansibleVarFileXX…

Mitigation only
Fix from $1,950 2019-05-17
Windows 10 HIGH 7.8
CVE-2019-0881

An elevation of privilege vulnerability exists when the Windows Kernel improperly handles key enumeration, aka 'Windows Kernel Elevation of Privilege…

Patch available
Fix from $1,950 2019-05-16
Logo\!8 Bm Firmware HIGH 7.5
CVE-2019-10921

A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Unencrypted storage of passwords in the project coul…

Fix: 8.3+
Fix from $1,950 2019-05-14
Better Banking MEDIUM 6.8
CVE-2019-8350

The Simple - Better Banking application 2.45.0 through 2.45.3 (fixed in 2.46.0) for Android was affected by an information disclosure vulnerability t…

Fix: after 2.45.3
Fix from $1,600 2019-05-13
Eyedisk MEDIUM 6.8
CVE-2019-11885

eyeDisk implements the unlock feature by sending a cleartext password. The password can be discovered by sniffing USB traffic or by sending a 06 05 5…

No fix yet
Fix from $1,600 2019-05-12
Calendar MEDIUM 5.5
CVE-2019-11820

Information exposure through process environment vulnerability in Synology Calendar before 2.3.3-0620 allows local users to obtain credentials via cm…

Fix: 2.3.3-0620+
Fix from $1,600 2019-05-09
Am 100 Firmware HIGH 7.8
CVE-2019-3938

Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 stores usernames, passwords, and other configuration options in the file gener…

No fix yet
Fix from $1,950 2019-04-30
Twitter HIGH 8.8
CVE-2019-10313

Jenkins Twitter Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with a…

Fix: after 0.7
Fix from $1,950 2019-04-30
Aqua Microscanner HIGH 8.8
CVE-2019-10316

Jenkins Aqua MicroScanner Plugin 1.0.5 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they c…

Fix: after 1.0.5
Fix from $1,950 2019-04-30
Azure Ad HIGH 8.8
CVE-2019-10318

Jenkins Azure AD Plugin 0.3.3 and earlier stored the client secret unencrypted in the global config.xml configuration file on the Jenkins master wher…

Fix: after 0.3.3
Fix from $1,950 2019-04-30
Runasspc HIGH 7.8
CVE-2019-10239

Robotronic RunAsSpc 3.7.0.0 protects stored credentials insufficiently, which allows locally authenticated attackers (under the same user context) to…

No fix yet
Fix from $1,950 2019-04-24