Vulnerability index

Browse CVEs

1,249 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
Tivoli Storage Manager HIGH 7.8
CVE-2017-1378

IBM Spectrum Protect 7.1 and 8.1 (formerly Tivoli Storage Manager) disclosed unencrypted login credentials to Vmware vCenter in the application trace…

Patch available
Fix from $1,950 2017-10-05
Security Identity Manager HIGH 7.8
CVE-2017-1362

IBM Security Identity Manager Adapters 6.0 and 7.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: …

Patch available
Fix from $1,950 2017-09-25
Dir 850l Firmware HIGH 8.1
CVE-2017-14418

The D-Link NPAPI extension, as used in conjunction with D-Link DIR-850L REV. B (with firmware through FW208WWb02) devices, sends the cleartext admin …

No fix yet
Fix from $1,950 2017-09-13
Scan To Network CRITICAL 9.8
CVE-2017-13771

Lexmark Scan To Network (SNF) 3.2.9 and earlier stores network configuration credentials in plaintext and transmits them in requests, which allows re…

Fix: after 3.2.9
Fix from $2,300 2017-09-07
X Pack MEDIUM 5.3
CVE-2017-8446

The Reporting feature in X-Pack in versions prior to 5.5.2 and standalone Reporting plugin versions versions prior to 2.4.6 had an impersonation vuln…

Fix: after 5.5.1
Fix from $1,600 2017-08-18
PostgreSQL HIGH 8.8
CVE-2017-7547EPSS 6%

PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attackers to re…

Mitigation only
Fix from $1,950 2017-08-16
Vcenter Server CRITICAL 9.8
CVE-2017-4923

VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure vulnerability. This issue may allow plaintext credentials to be obtain…

Patch available
Fix from $2,300 2017-08-01
Coaxdata Gateway 1gbps Firmware CRITICAL 9.8
CVE-2017-6532

Televes COAXDATA GATEWAY 1Gbps devices doc-wifi-hgw_v1.02.0014 4.20 have cleartext credentials in /mib.db.

Mitigation only
Fix from $2,300 2017-07-20
Dt8x Firmware CRITICAL 9.8
CVE-2017-11349

dataTaker DT8x dEX 1.72.007 allows remote attackers to compose programs or schedules, for purposes such as sending e-mail messages or making outbound…

No fix yet
Fix from $2,300 2017-07-17
Websphere Mq HIGH 8.1
CVE-2017-1337

IBM WebSphere MQ 9.0.1 and 9.0.2 Java/JMS application can incorrectly transmit user credentials in plain text. IBM X-Force ID: 126245.

Mitigation only
Fix from $1,950 2017-07-10
Ultra Services Framework CRITICAL 9.8
CVE-2017-6709

A vulnerability in the AutoVNF tool for the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to access administrative c…

Fix: after 5.0.2
Fix from $2,300 2017-07-06
Websphere Message Broker MEDIUM 5.5
CVE-2017-1207

IBM WebSphere Message Broker stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 123777.

Mitigation only
Fix from $1,600 2017-07-05
Hg100r Firmware CRITICAL 9.8
CVE-2017-7315

An issue was discovered on Humax Digital HG100R 2.0.6 devices. To download the backup file it's not necessary to use credentials, and the router cred…

No fix yet
Fix from $2,300 2017-07-04
Sitefinity CRITICAL 9.8
CVE-2017-9248 KEVEPSS 75%

Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web…

Fix: 10.0.6412.0+
Fix from $2,300 2017-07-03
Modicon M241 Firmware CRITICAL 9.8
CVE-2017-6028

An Insufficiently Protected Credentials issue was discovered in Schneider Electric Modicon PLCs Modicon M241, all firmware versions, and Modicon M251…

Fix: after 4.0.3.20
Fix from $2,300 2017-06-30
Airlink Raven Xe Firmware HIGH 7.5
CVE-2017-6046

An Insufficiently Protected Credentials issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT,…

Mitigation only
Fix from $1,950 2017-06-30
Multilin Sr 750 Feeder Protection Relay Firmware CRITICAL 9.8
CVE-2017-7905

A Weak Cryptography for Passwords issue was discovered in General Electric (GE) Multilin SR 750 Feeder Protection Relay, firmware versions prior to V…

Fix: after 6.0
Fix from $2,300 2017-06-30
Tpm2.0 Tools HIGH 7.5
CVE-2017-7524

tpm2-tools versions before 1.1.1 are vulnerable to a password leak due to transmitting password in plaintext from client to server when generating HM…

Fix: after 1.1.0
Fix from $1,950 2017-06-27
One Key HIGH 7.5
CVE-2017-3214

The Milwaukee ONE-KEY Android mobile application stores the master token in plaintext in the apk binary.

Mitigation only
Fix from $1,950 2017-06-20
Photo Station HIGH 7.8
CVE-2017-9552

A design flaw in authentication in Synology Photo Station 6.0-2528 through 6.7.1-3419 allows local users to obtain credentials via cmdline. Synology …

Mitigation only
Fix from $1,950 2017-06-13
Ultra Services Platform MEDIUM 5.5
CVE-2017-6694

A vulnerability in the Virtual Network Function Manager's (VNFM) logging function of Cisco Ultra Services Platform could allow an authenticated, loca…

Mitigation only
Fix from $1,600 2017-06-13
Easy Chat Server HIGH 7.5
CVE-2017-9557

register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1 allows remote attackers to discover passwords by sending the username parameter in …

Fix: after 3.1
Fix from $1,950 2017-06-12
B305hw2 Firmware CRITICAL 9.8
CVE-2017-8837

Cleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_…

Patch available
Fix from $2,300 2017-06-05
Oncell G3110 Hspa Firmware CRITICAL 9.8
CVE-2017-7913

A Plaintext Storage of a Password issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3110-HSDPA…

Fix: after 1.4
Fix from $2,300 2017-05-29
Backhaul Radios HIGH 7.5
CVE-2017-9136

An issue was discovered on Mimosa Client Radios before 2.2.3. In the device's web interface, there is a page that allows an attacker to use an unsani…

Fix: after 2.2.1
Fix from $1,950 2017-05-21
PostgreSQL HIGH 7.5
CVE-2017-7486EPSS 6%

PostgreSQL versions 8.4 - 9.6 are vulnerable to information leak in pg_user_mappings view which discloses foreign server passwords to any user having…

Mitigation only
Fix from $1,950 2017-05-12
Dh Ipc Hdbw23a0rn Zs Firmware CRITICAL 9.8
CVE-2017-7925EPSS 51%

A Password in Configuration File issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XX…

Patch available
Fix from $2,300 2017-05-06
Struxureware Data Center Expert MEDIUM 6.8
CVE-2017-8371

Schneider Electric StruxureWare Data Center Expert before 7.4.0 uses cleartext RAM storage for passwords, which might allow remote attackers to obtai…

Fix: after 7.3.1
Fix from $1,600 2017-04-30
Ked Password Manager HIGH 7.5
CVE-2017-8296

kedpm 0.5 and 1.0 creates a history file in ~/.kedpm/history that is written in cleartext. All of the commands performed in the password manager are …

Patch available
Fix from $1,950 2017-04-27
Wireless Ip Camera \(p2p\) Firmware HIGH 7.5
CVE-2017-8222

Wireless IP Camera (P2P) WIFICAM devices have an "Apple Production IOS Push Services" private RSA key and certificate stored in /system/www/pem/ck.pe…

No fix yet
Fix from $1,950 2017-04-25