Vulnerability index

Browse CVEs

1,246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
Vmg3312 B10b Firmware CRITICAL 9.8
CVE-2018-18754

ZyXEL VMG3312-B10B 1.00(AAPP.7) devices have a backdoor root account with the tTn3+Z@!Sr0O+ password hash in the etc/default.cfg file.

Mitigation only
Fix from $2,300 2018-10-29
Purevpn HIGH 7.8
CVE-2018-18656

The PureVPN client before 6.1.0 for Windows stores Login Credentials (username and password) in cleartext. The location of such files is %PROGRAMDATA…

Fix: 6.1.0+
Fix from $1,950 2018-10-26
Secure Remote Services HIGH 7.8
CVE-2018-11079

Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains a Plaintext Password Storage vulnerability. Database credentials are stored i…

Fix: 3.32.00.08+
Fix from $1,950 2018-10-18
Enterprise Linux Desktop MEDIUM 5.5
CVE-2018-12383

If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is…

No fix yet
Fix from $1,600 2018-10-18
Dwr 116 Firmware CRITICAL 9.8
CVE-2018-10824EPSS 12%

An issue was discovered on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L through 1.02, DWR-512 through 2.02, DWR-712 through 2.02, DWR…

Fix: after 2.02
Fix from $2,300 2018-10-17
Fcj Firmware CRITICAL 9.8
CVE-2018-17900

Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The web application improperly protects credentials which …

Mitigation only
Fix from $2,300 2018-10-12
Bigfix Platform HIGH 7.8
CVE-2017-1231

IBM BigFix Platform 9.5 - 9.5.9 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 123910.

Fix: after 9.5.9
Fix from $1,950 2018-10-12
Infocad Fm HIGH 7.5
CVE-2018-13789

An issue was discovered in Descor Infocad FM before 3.1.0.0. An unauthenticated web service allows the retrieval of files on the web server and on re…

Fix: 3.1.0.0+
Fix from $1,950 2018-10-10
Requests HIGH 7.5
CVE-2018-18074EPSS 7%

The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect…

Fix: 2.20.0+
Fix from $1,950 2018-10-09
Dir 809 A1 Firmware CRITICAL 9.8
CVE-2018-14081

An issue was discovered on D-Link DIR-809 A1 through 1.09, A2 through 1.11, and Guest Zone through 1.09 devices. Device passwords, such as the admin …

Fix: after 1.11
Fix from $2,300 2018-10-09
Verba Collaboration Compliance And Quality Management Platform MEDIUM 6.5
CVE-2018-17871

Verba Collaboration Compliance and Quality Management Platform before 9.2.1.5545 has Incorrect Access Control.

Fix: 9.2.1.5545+
Fix from $1,600 2018-10-04
Scx 6545x Firmware CRITICAL 9.8
CVE-2018-17969

Samsung SCX-6545X V2.00.03.01 03-23-2012 devices allows remote attackers to discover cleartext credentials via iso.3.6.1.4.1.236.11.5.11.81.10.1.5.0 …

No fix yet
Fix from $2,300 2018-10-03
Cisco Ios MEDIUM 5.5
CVE-2018-11752

Previous releases of the Puppet cisco_ios module output SSH session debug information including login credentials to a world readable file on every r…

Fix: 0.4.0+
Fix from $1,600 2018-10-02
Device Manager HIGH 7.8
CVE-2018-11748

Previous releases of the Puppet device_manager module creates configuration files containing credentials that are world readable. This issue has been…

Fix: 2.7.0+
Fix from $1,950 2018-10-02
Security Guardium HIGH 7.8
CVE-2018-1498

IBM Security Guardium EcoSystem 10.5 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 141223.

Mitigation only
Fix from $1,950 2018-10-02
Telegram Desktop CRITICAL 9.8
CVE-2018-17613

Telegram Desktop (aka tdesktop) 1.3.16 alpha, when "Use proxy" is enabled, sends credentials and application data in cleartext over the SOCKS5 protoc…

Mitigation only
Fix from $2,300 2018-09-28
Open Charge Point Protocol CRITICAL 9.8
CVE-2018-16669

An issue was discovered in CIRCONTROL Open Charge Point Protocol (OCPP) before 1.5.0, as used in CirCarLife, PowerStudio, and other products. Due to …

Fix: 1.5.0+
Fix from $2,300 2018-09-18
Synaman HIGH 7.8
CVE-2018-10814

Synametrics SynaMan 4.0 build 1488 uses cleartext password storage for SMTP credentials.

No fix yet
Fix from $1,950 2018-09-14
Squash Tm HIGH 7.2
CVE-2018-16987

Squash TM through 1.18.0 presents the cleartext passwords of external services in the administration panel, as demonstrated by a ta-server-password f…

Fix: after 1.18.0
Fix from $1,950 2018-09-13
Homeputer Cl Studio Fur Homematic HIGH 8.1
CVE-2017-17691

Homeputer CL Studio fur HomeMatic 4.0 Rel 160808 and earlier uses cleartext to exchange the username and password between server and client instances…

Fix: 4.0+
Fix from $1,950 2018-09-07
Thermal Management Center Firmware CRITICAL 9.8
CVE-2017-16714

In Ice Qube Thermal Management Center versions prior to version 4.13, passwords are stored in plaintext in a file that is accessible without authenti…

Fix: 4.13+
Fix from $2,300 2018-09-06
Project Portfolio Management HIGH 7.5
CVE-2018-13822

Unprotected storage of credentials in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows attackers to access sensi…

Fix: after 14.3
Fix from $1,950 2018-08-30
Ubuntu Linux HIGH 8.1
CVE-2018-1139

A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A ma…

Fix: 4.7.9 / 4.8.4+
Fix from $1,950 2018-08-22
Mycarelink 24952 Patient Monitor Firmware MEDIUM 5.2
CVE-2018-10622

Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials for …

Mitigation only
Fix from $1,600 2018-08-10
Security Identity Governance And Intelligence HIGH 7.5
CVE-2017-1411

IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 does not require that users should have strong passwords by default, which mak…

Patch available
Fix from $1,950 2018-08-06
Emc Networker HIGH 8.8
CVE-2018-11050

Dell EMC NetWorker versions between 9.0 and 9.1.1.8 through 9.2.1.3, and the version 18.1.0.1 contain a Clear-Text authentication over network vulner…

Fix: after 9.2.1.3
Fix from $1,950 2018-08-01
Big Ip Controller HIGH 8.8
CVE-2018-5543

The F5 BIG-IP Controller for Kubernetes 1.0.0-1.5.0 (k8s-bigip-crtl) passes BIG-IP username and password as command line parameters, which may lead t…

Fix: after 1.5.0
Fix from $1,950 2018-07-31
Smartserver 1 Firmware CRITICAL 9.8
CVE-2018-8851

Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The dev…

Fix: 4.11.007+
Fix from $2,300 2018-07-24
Core I3 MEDIUM 6.7
CVE-2017-5704

Platform sample code firmware included with 4th Gen Intel Core Processor, 5th Gen Intel Core Processor, 6th Gen Intel Core Processor, and 7th Gen Int…

Mitigation only
Fix from $1,600 2018-07-10
Aws Codepipeline HIGH 7.8
CVE-2018-1000401

Jenkins project Jenkins AWS CodePipeline Plugin version 0.36 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSCodePipe…

Fix: after 0.36
Fix from $1,950 2018-07-09