Vulnerability index

Browse CVEs

1,249 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
Satellite HIGH 8.8
CVE-2016-9593

foreman-debug before version 1.15.0 is vulnerable to a flaw in foreman-debug's logging. An attacker with access to the foreman log file would be able…

Fix: 1.15.0+
Fix from $1,950 2018-04-16
Vp5208a Firmware CRITICAL 9.8
CVE-2018-10024

ubiQuoss Switch VP5208A creates a bcm_password file at /cgi-bin/ with the user credentials in cleartext when a failed login attempt occurs. The file …

Mitigation only
Fix from $2,300 2018-04-11
Mac Os X HIGH 7.8
CVE-2018-4170

An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "Admin Framework" component. It allows lo…

Fix: 10.13.4+
Fix from $1,950 2018-04-03
Sickrage CRITICAL 9.8
CVE-2018-9160EPSS 76%

SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.

Fix: after 9.2.101
Fix from $2,300 2018-03-31
Dir 601 Firmware HIGH 8.0
CVE-2018-5708EPSS 6%

An issue was discovered on D-Link DIR-601 B1 2.02NA devices. Being on the same local network as, but being unauthenticated to, the administrator's pa…

No fix yet
Fix from $1,950 2018-03-30
Sentry Vision CRITICAL 9.8
CVE-2018-9031

The login interface on TNLSoftSolutions Sentry Vision 3.x devices provides password disclosure by reading an "if(pwd ==" line in the HTML source code…

No fix yet
Fix from $2,300 2018-03-29
Hw0021 Firmware CRITICAL 9.8
CVE-2017-11510

An information leak exists in Wanscam's HW0021 network camera that allows an unauthenticated remote attacker to recover the administrator username an…

No fix yet
Fix from $2,300 2018-03-28
GitLab HIGH 7.2
CVE-2017-0925

Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration API endpoin…

Fix: after 10.3.3
Fix from $1,950 2018-03-21
Coverity HIGH 7.8
CVE-2018-1000104

A plaintext storage of a password vulnerability exists in Jenkins Coverity Plugin 1.10.0 and earlier in CIMInstance.java that allows an attacker with…

Fix: after 1.10.0
Fix from $1,950 2018-03-13
Mydlink\+ HIGH 8.1
CVE-2018-7698

An issue was discovered in D-Link mydlink+ 3.8.5 build 259 for DCS-933L 1.05.04 and DCS-934L 1.05.04 devices. The mydlink+ app sends the username and…

Mitigation only
Fix from $1,950 2018-03-05
Imanager HIGH 7.5
CVE-2017-5189

NetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel, allowing attackers to extrac…

Mitigation only
Fix from $1,950 2018-03-02
Security Guardium Big Data Intelligence HIGH 7.8
CVE-2018-1377

IBM Security Guardium Big Data Intelligence (SonarG) 3.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Forc…

Mitigation only
Fix from $1,950 2018-02-26
Interscan Messaging Security Virtual Appliance HIGH 8.1
CVE-2018-3609EPSS 21%

A vulnerability in the Trend Micro InterScan Messaging Security Virtual Appliance 9.0 and 9.1 management portal could allow an unauthenticated user t…

No fix yet
Fix from $1,950 2018-02-16
Windows 10 HIGH 7.8
CVE-2018-0828

Windows 10 version 1607 and Windows Server 2016 allow an elevation of privilege vulnerability due to how the MultiPoint management account password i…

Patch available
Fix from $1,950 2018-02-15
Igss Mobile MEDIUM 6.7
CVE-2017-9969

An information disclosure vulnerability exists in Schneider Electric's IGSS Mobile application version 3.01 and prior. Passwords are stored in clear …

Fix: after 3.01
Fix from $1,600 2018-02-12
Asuswrt HIGH 8.8
CVE-2017-15656

Password are stored in plaintext in nvram in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt.

Fix: after 3.0.0.4.380.7743
Fix from $1,950 2018-01-31
Cognos Analytics HIGH 7.8
CVE-2017-1779

IBM Cognos Analytics 11.0 could store cached credentials locally that could be obtained by a local user. IBM X-Force ID: 136824.

Patch available
Fix from $1,950 2018-01-29
Build Publisher HIGH 7.8
CVE-2017-1000387

Jenkins Build-Publisher plugin version 1.21 and earlier stores credentials to other Jenkins instances in the file hudson.plugins.build_publisher.Buil…

Fix: after 1.21
Fix from $1,950 2018-01-26
Ellipse HIGH 8.8
CVE-2017-16731

An Unprotected Transport of Credentials issue was discovered in ABB Ellipse 8.3 through Ellipse 8.9 released prior to December 2017 (including Ellips…

Fix: after 8.9.0
Fix from $1,950 2017-12-20
Pr115 204 P Rs Firmware CRITICAL 9.8
CVE-2017-17106EPSS 15%

Credentials for Zivif PR115-204-P-RS V2.3.4.2103 Webcams can be obtained by an unauthenticated remote attacker using a standard web /cgi-bin/hi3510/p…

No fix yet
Fix from $2,300 2017-12-19
Dir 130 Firmware CRITICAL 9.8
CVE-2017-3192EPSS 39%

D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 do not sufficiently protect administrator credentials. The tools_admin.asp pag…

Mitigation only
Fix from $2,300 2017-12-16
Intellispace Cardiovascular HIGH 7.2
CVE-2017-14111

The workstation logging function in Philips IntelliSpace Cardiovascular (ISCV) 2.3.0 and earlier and Xcelera R4.1L1 and earlier records domain authen…

Fix: after 2.3.0
Fix from $1,950 2017-11-17
Psftpd MEDIUM 5.3
CVE-2017-15272

The PSFTPd 10.0.4 Build 729 server stores its configuration inside PSFTPd.dat. This file is a Microsoft Access Database and can be extracted. The app…

No fix yet
Fix from $1,600 2017-11-15
Bundesliga Manager HIGH 8.1
CVE-2017-14711

The Kickbase GmbH "Kickbase Bundesliga Manager" app before 2.2.1 -- aka kickbase-bundesliga-manager/id678241305 -- for iOS is vulnerable to a credent…

Fix: 2.2.1+
Fix from $1,950 2017-11-13
Sera HIGH 7.8
CVE-2017-15918

Sera 1.2 stores the user's login password in plain text in their home directory. This makes privilege escalation trivial and also exposes the user an…

No fix yet
Fix from $1,950 2017-11-01
Ssh CRITICAL 9.8
CVE-2017-1000245

The SSH Plugin stores credentials which allow jobs to access remote servers via the SSH protocol. User passwords and passphrases for encrypted SSH ke…

Fix: after 2.4
Fix from $2,300 2017-11-01
Service Framework HIGH 8.1
CVE-2017-3760

The Lenovo Service Framework Android application uses a set of nonsecure credentials when performing integrity verification of downloaded application…

Patch available
Fix from $1,950 2017-10-17
Nuc7i7bnh Firmware HIGH 8.4
CVE-2017-5700

Insufficient protection of password storage in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and be…

Patch available
Fix from $1,950 2017-10-11
Lvis 3me Firmware HIGH 7.5
CVE-2017-13998

An Insufficiently Protected Credentials issue was discovered in LOYTEC LVIS-3ME versions prior to 6.2.0. The application does not sufficiently protec…

Fix: after 6.1.1
Fix from $1,950 2017-10-05
Bigfix Security Compliance Analytics HIGH 7.8
CVE-2017-1201

IBM BigFix Compliance Analytics 1.9.79 (TEMA SUAv1 SCA SCM) stores user credentials in clear text which can be read by a local user. IBM X-Force ID: …

Mitigation only
Fix from $1,950 2017-10-05