Vulnerability index

Browse CVEs

1,246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
Xiaomi Mi A1 Firmware CRITICAL 9.8
CVE-2018-18698

An issue was discovered on Xiaomi Mi A1 tissot_sprout:8.1.0/OPM1.171019.026/V9.6.4.0.ODHMIFE devices. They store cleartext Wi-Fi passwords in logcat …

Mitigation only
Fix from $2,300 2018-12-24
Dpc2100 Firmware CRITICAL 9.8
CVE-2018-20392

S-A WebSTAR DPC2100 v2.0.2r1256-060303 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.…

No fix yet
Fix from $2,300 2018-12-23
Dwg849 Firmware CRITICAL 9.8
CVE-2018-20394

Thomson DWG849 STC0.01.16, DWG850-4 ST9C.05.25, DWG855 ST80.20.26, and TWG870 STB2.01.36 devices allow remote attackers to discover credentials via i…

No fix yet
Fix from $2,300 2018-12-23
Ming6200 Firmware CRITICAL 9.8
CVE-2018-20395

NETWAVE MNG6200 C4835805jrc12FU121413.cpr devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1…

No fix yet
Fix from $2,300 2018-12-23
Ming2120j Firmware CRITICAL 9.8
CVE-2018-20396

NET&SYS MNG2120J 5.76.1006c and MNG6300 5.83.6305jrc2 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 a…

No fix yet
Fix from $2,300 2018-12-23
Cbc383z Firmware CRITICAL 9.8
CVE-2018-20397

mplus CBC383Z CBC383Z_mplus_MDr026 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.44…

No fix yet
Fix from $2,300 2018-12-23
Cm5100 Firmware CRITICAL 9.8
CVE-2018-20398

Skyworth CM5100 V1.1.0, CM5100-440 V1.2.1, CM5100-511 4.1.0.14, CM5100-GHD00 V1.2.2, and CM5100.g2 4.1.0.17 devices allow remote attackers to discove…

No fix yet
Fix from $2,300 2018-12-23
Sbg901 Firmware CRITICAL 9.8
CVE-2018-20399

Motorola SBG901 SBG901-2.10.1.1-GA-00-581-NOSH, SBG941 SBG941-2.11.0.0-GA-07-624-NOSH, and SVG1202 SVG1202-2.1.0.0-GA-14-LTSH devices allow remote at…

No fix yet
Fix from $2,300 2018-12-23
Dvw2108 Firmware CRITICAL 9.8
CVE-2018-20400

Ubee DVW2108 6.28.1017 and DVW2110 6.28.2012 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.…

No fix yet
Fix from $2,300 2018-12-23
5352 Firmware CRITICAL 9.8
CVE-2018-20401

Zoom 5352 v5.5.8.6Y devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.…

No fix yet
Fix from $2,300 2018-12-23
Bcm93383wrg Firmware CRITICAL 9.8
CVE-2018-20382

Jiuzhou BCM93383WRG 139.4410mp1.3921132mp1.899.004404.004 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1…

No fix yet
Fix from $2,300 2018-12-23
Arris Dg950a Firmware CRITICAL 9.8
CVE-2018-20383

ARRIS DG950A 7.10.145 and DG950S 7.10.145.EURO devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.…

No fix yet
Fix from $2,300 2018-12-23
Ib 8120 W21 Firmware CRITICAL 9.8
CVE-2018-20384

iNovo Broadband IB-8120-W21 139.4410mp1.004200.002 and IB-8120-W21E1 139.4410mp1.3921132mp1.899.004404.004 devices allow remote attackers to discover…

No fix yet
Fix from $2,300 2018-12-23
Cbv38z4ec Firmware CRITICAL 9.8
CVE-2018-20385

CastleNet CBV38Z4EC 125.553mp1.39219mp1.899.007, CBV38Z4ECNIT 125.553mp1.39219mp1.899.005ITT, CBW383G4J 37.556mp5.008, and CBW38G4J 37.553mp1.008 dev…

No fix yet
Fix from $2,300 2018-12-23
Arris Sbg6580 2 Firmware CRITICAL 9.8
CVE-2018-20386

ARRIS SBG6580-2 D30GW-SEAEAGLE-1.5.2.5-GA-00-NOSH devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and i…

No fix yet
Fix from $2,300 2018-12-23
Bcw700j Firmware CRITICAL 9.8
CVE-2018-20387

Bnmux BCW700J 5.20.7, BCW710J 5.30.6a, and BCW710J2 5.30.16 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1…

No fix yet
Fix from $2,300 2018-12-23
Cm 6200un Firmware CRITICAL 9.8
CVE-2018-20388

Comtrend CM-6200un 123.447.007 and CM-6300n 123.553mp1.005 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.…

No fix yet
Fix from $2,300 2018-12-23
Dcm 604 Firmware CRITICAL 9.8
CVE-2018-20389

D-Link DCM-604 DCM604_C1_ViaCabo_1.04_20130606 and DCM-704 EU_DCM-704_1.10 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4…

No fix yet
Fix from $2,300 2018-12-23
Cg2001 An22a Firmware CRITICAL 9.8
CVE-2018-20390

Kaonmedia CG2001-AN22A 1.2.1, CG2001-UDBNA 3.0.8, and CG2001-UN2NA 3.0.8 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.449…

No fix yet
Fix from $2,300 2018-12-23
Cbw700n Firmware CRITICAL 9.8
CVE-2018-20391

TEKNOTEL CBW700N 81.447.392110.729.024 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.…

No fix yet
Fix from $2,300 2018-12-23
Kibana CRITICAL 9.8
CVE-2018-17245

Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are used when generating PDF report…

Fix: after 6.4.2
Fix from $2,300 2018-12-20
Copay Bitcoin Wallet CRITICAL 9.8
CVE-2018-1000851

Copay Bitcoin Wallet version 5.01 to 5.1.0 included. contains a Other/Unknown vulnerability in wallet private key storage that can result in Users' p…

Fix: after 5.1.0
Fix from $2,300 2018-12-20
Opendental MEDIUM 5.3
CVE-2018-15717

Open Dental before version 18.4 stores user passwords as base64 encoded MD5 hashes.

Fix: 18.4+
Fix from $1,600 2018-12-12
Sftp\/scp Server CRITICAL 9.8
CVE-2018-16791

In SolarWinds SFTP/SCP Server through 2018-09-10, the configuration file is world readable and writable, and stores user passwords in an insecure man…

Fix: after 20180910
Fix from $2,300 2018-12-05
Umptool MEDIUM 6.8
CVE-2018-19795

ChipsBank UMPTool saves the password to the NAND with a simple substitution cipher, which allows attackers to get full access when having physical ac…

No fix yet
Fix from $1,600 2018-12-03
Ismartalarm MEDIUM 6.8
CVE-2018-16222

Cleartext Storage of credentials in the iSmartAlarmData.xml configuration file in the iSmartAlarm application through 2.0.8 for Android allows an att…

Fix: after 2.0.8
Fix from $1,600 2018-11-20
Qbeecam CRITICAL 9.8
CVE-2018-16223

Insecure Cryptographic Storage of credentials in com.vestiacom.qbeecamera_preferences.xml in the QBee Cam application through 1.0.5 for Android allow…

Fix: after 1.0.5
Fix from $2,300 2018-11-20
I5 Application Firmware CRITICAL 9.8
CVE-2018-19078

An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The response to an ONVIF medi…

No fix yet
Fix from $2,300 2018-11-07
Circarlife Firmware CRITICAL 9.8
CVE-2018-17922

Circontrol CirCarLife all versions prior to 4.3.1, the PAP credentials of the device are stored in clear text in a log file that is accessible withou…

Fix: 4.3.1+
Fix from $2,300 2018-11-02
Vgo Firmware CRITICAL 9.8
CVE-2018-8858

If an attacker has access to the firmware from the VGo Robot (Versions 3.0.3.52164 and 3.0.3.53662. Prior versions may also be affected) they may be …

Fix: after 3.0.3.52164
Fix from $2,300 2018-10-30