Vulnerability index

Browse CVEs

1,249 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
Smartserver 1 Firmware CRITICAL 9.8
CVE-2018-8851

Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The dev…

Fix: 4.11.007+
Fix from $2,300 2018-07-24
Core I3 MEDIUM 6.7
CVE-2017-5704

Platform sample code firmware included with 4th Gen Intel Core Processor, 5th Gen Intel Core Processor, 6th Gen Intel Core Processor, and 7th Gen Int…

Mitigation only
Fix from $1,600 2018-07-10
Aws Codepipeline HIGH 7.8
CVE-2018-1000401

Jenkins project Jenkins AWS CodePipeline Plugin version 0.36 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSCodePipe…

Fix: after 0.36
Fix from $1,950 2018-07-09
Aws Codedeploy HIGH 7.8
CVE-2018-1000403

Jenkins project Jenkins AWS CodeDeploy Plugin version 1.19 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSCodeDeploy…

Fix: after 1.19
Fix from $1,950 2018-07-09
Aws Codebuild HIGH 7.8
CVE-2018-1000404

Jenkins project Jenkins AWS CodeBuild Plugin version 0.26 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSClientFacto…

Fix: after 0.26
Fix from $1,950 2018-07-09
MongoDB HIGH 7.0
CVE-2017-2665

The skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /etc/skyring/skyring.conf file…

Mitigation only
Fix from $1,950 2018-07-06
Powermedia Xms HIGH 7.8
CVE-2018-11634

Plaintext Storage of Passwords in the administrative console in Dialogic PowerMedia XMS before 3.5 SU2 allows local users to access the web applicati…

Fix: after 3.5
Fix from $1,950 2018-07-03
Powermedia Xms HIGH 8.1
CVE-2018-11639

Plaintext Storage of Passwords within Cookies in /var/www/xms/application/controllers/verifyLogin.php in the administrative console in Dialogic Power…

Fix: after 3.5
Fix from $1,950 2018-07-03
Imps110 1 Firmware HIGH 8.8
CVE-2018-7782

In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, authenticated users can view passwords…

Fix: 3.29.69+
Fix from $1,950 2018-07-03
Discovery CRITICAL 9.8
CVE-2018-11746

In Puppet Discovery prior to 1.2.0, when running Discovery against Windows hosts, WinRM connections can fall back to using basic auth over insecure c…

Fix: 1.2.0+
Fix from $2,300 2018-07-03
Enterprise Suite HIGH 7.8
CVE-2018-13014

Storing password in recoverable format in safensec.com (SysWatch service) in SAFE'N'SEC SoftControl/SafenSoft SysWatch, SoftControl/SafenSoft TPSecur…

Fix: 4.4.2+
Fix from $1,950 2018-06-29
Twincat MEDIUM 5.9
CVE-2017-16718

Beckhoff TwinCAT 3 supports communication over ADS. ADS is a protocol for industrial automation in protected environments. This protocol uses user co…

No fix yet
Fix from $1,600 2018-06-27
Z\/os Connector HIGH 7.2
CVE-2018-1000608

A exposure of sensitive information vulnerability exists in Jenkins z/OS Connector Plugin 1.2.6.1 and earlier in SCLMSCM.java that allows an attacker…

Fix: after 1.2.6.1
Fix from $1,950 2018-06-26
Configuration As Code HIGH 8.8
CVE-2018-1000610

A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in DataBoundConfigurator.java,…

Mitigation only
Fix from $1,950 2018-06-26
Momentum Axel 720p Firmware MEDIUM 6.7
CVE-2018-12260

An issue was discovered on Momentum Axel 720P 5.1.8 devices. The root password can be obtained in cleartext by issuing the command 'showKey' from the…

No fix yet
Fix from $1,600 2018-06-12
Ovirt HIGH 7.8
CVE-2018-1075

ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one choo…

Fix: 4.2.3+
Fix from $1,950 2018-06-12
Safari HIGH 8.8
CVE-2018-4190

An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is aff…

Fix: 7.5 / 11.1.1+
Fix from $1,950 2018-06-08
Prime Collaboration HIGH 7.8
CVE-2018-0335

A vulnerability in the web portal authentication process of Cisco Prime Collaboration Provisioning could allow an unauthenticated, local attacker to …

Mitigation only
Fix from $1,950 2018-06-07
Ip Gateway Firmware CRITICAL 9.8
CVE-2017-7933

In ABB IP GATEWAY 3.39 and prior, some configuration files contain passwords stored in plain-text, which may allow an attacker to gain unauthorized a…

Fix: after 3.39
Fix from $2,300 2018-06-06
Scroll Medical Air Systems Firmware CRITICAL 9.8
CVE-2018-7510

In the web application in BeaconMedaes TotalAlert Scroll Medical Air Systems running software versions prior to 4107600010.23, passwords are presente…

Fix: 4107600010.23+
Fix from $2,300 2018-06-06
Ftp Server CRITICAL 9.8
CVE-2018-11544

The Olive Tree Ftp Server application 1.32 for Android has Insecure Data Storage because a username and password are stored in the /data/data/com.the…

No fix yet
Fix from $2,300 2018-05-29
Scroll Medical Air Systems Firmware CRITICAL 9.8
CVE-2018-7518

In TotalAlert Web Application in BeaconMedaes Scroll Medical Air Systems prior to v4107600010.23, an attacker with network access to the integrated w…

Fix: 4107600010.23+
Fix from $2,300 2018-05-24
Email Encryption Gateway HIGH 7.0
CVE-2018-10355

An authentication weakness vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to recover user passwords on vulnerable …

Fix: after 5.5
Fix from $1,950 2018-05-23
Printeron HIGH 7.0
CVE-2018-10327

PrinterOn Enterprise 4.1.3 stores the Active Directory bind credentials using base64 encoding, which allows local users to obtain credentials for a d…

No fix yet
Fix from $1,950 2018-05-17
Edr 810 Firmware HIGH 8.8
CVE-2017-12123

An exploitable clear text transmission of password vulnerability exists in the web server and telnet functionality of Moxa EDR-810 V4.1 build 1703031…

No fix yet
Fix from $1,950 2018-05-14
Easy Hosting Control Panel HIGH 7.8
CVE-2018-6618

Easy Hosting Control Panel (EHCP) v0.37.12.b allows attackers to obtain sensitive information by leveraging cleartext password storage.

No fix yet
Fix from $1,950 2018-05-11
Enterprise Virtualization HIGH 7.2
CVE-2018-1074

ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentials, includ…

Fix: after 4.1.11.1
Fix from $1,950 2018-04-26
Dosewise HIGH 8.8
CVE-2017-9654

The Philips DoseWise Portal web-based application versions 1.1.7.333 and 2.1.1.3069 stores login credentials in clear text within backend system file…

Mitigation only
Fix from $1,950 2018-04-24
Cognos Business Intelligence HIGH 7.0
CVE-2017-1764

IBM Cognos Business Intelligence 10.2, 10.2.1, 10.2.1.1, and 10.2.2, under specialized circumstances, could expose plain text credentials to a local …

No fix yet
Fix from $1,950 2018-04-23
Ipecs Nms HIGH 8.8
CVE-2018-10286EPSS 7%

The Ericsson-LG iPECS NMS A.1Ac web application discloses sensitive information such as the NMS admin credentials and the PostgreSQL database credent…

No fix yet
Fix from $1,950 2018-04-22