Vulnerability index

Browse CVEs

1,249 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
Wireless Ip Camera \(p2p\) Firmware CRITICAL 9.8
CVE-2017-8225EPSS 18%

On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is not correctly checked. An attacker can bypass authentic…

No fix yet
Fix from $2,300 2017-04-25
Dnalims HIGH 8.1
CVE-2017-6528

An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is affected by plaintext password storage (the /home/dna/spool/.pfile file).

No fix yet
Fix from $1,950 2017-03-09
Cimplicity MEDIUM 6.7
CVE-2016-9360

An issue was discovered in General Electric (GE) Proficy HMI/SCADA iFIX Version 5.8 SIM 13 and prior versions, Proficy HMI/SCADA CIMPLICITY Version 9…

Fix: after 9.0
Fix from $1,600 2017-02-13
Xl Web Ii Controller CRITICAL 9.8
CVE-2017-5139

An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. Any user i…

Mitigation only
Fix from $2,300 2017-02-13
Xl Web Ii Controller CRITICAL 9.8
CVE-2017-5140

An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. Password i…

Mitigation only
Fix from $2,300 2017-02-13
Security Access Manager For Web 8.0 Firmware MEDIUM 5.5
CVE-2015-5013

The IBM Security Access Manager appliance includes configuration files that contain obfuscated plaintext-passwords which authenticated users can acce…

Patch available
Fix from $1,600 2017-02-08
Keystonemiddleware HIGH 7.5
CVE-2015-7546

The identity service in OpenStack Identity (Keystone) before 2015.1.3 (Kilo) and 8.0.x before 8.0.2 (Liberty) and keystonemiddleware (formerly python…

Fix: 8.0.2+
Fix from $1,950 2016-02-03
Owncloud Client MEDIUM 5.0
CVE-2015-5955

ownCloud iOS app before 3.4.4 does not properly switch state between multiple instances, which might allow remote instance administrators to obtain s…

Fix: 3.4.4+
Fix from $1,600 2015-10-29
Struxureware Building Expert Multi Purpose Management MEDIUM 5.0
CVE-2015-3962

Schneider Electric StruxureWare Building Expert MPM before 2.15 does not use encryption for the client-server data stream, which allows remote attack…

Fix: 2.15+
Fix from $1,600 2015-09-18
Security Appscan MEDIUM 5.5
CVE-2014-4806

The installation process in IBM Security AppScan Enterprise 8.x before 8.6.0.2 iFix 003, 8.7.x before 8.7.0.1 iFix 003, 8.8.x before 8.8.0.1 iFix 002…

Fix: 8.6.0.2 / 8.7.0.1+
Fix from $1,600 2014-08-29
Windows 7 HIGH 8.8
CVE-2014-1812 KEVEPSS 65%

The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Window…

Patch available
Fix from $1,950 2014-05-14
Rslogix 5000 Design And Configuration Software MEDIUM 6.9
CVE-2014-0755

Rockwell Automation RSLogix 5000 7 through 20.01, and 21.0, does not properly implement password protection for .ACD files (aka project files), which…

Mitigation only
Fix from $1,600 2014-02-05
Fedora MEDIUM 6.5
CVE-2013-4222

OpenStack Identity (Keystone) Folsom, Grizzly 2013.1.3 and earlier, and Havana before havana-3 does not properly revoke user tokens when a tenant is …

Fix: after 2013.1.3
Fix from $1,600 2013-09-30
Niagara Ax MEDIUM 5.0
CVE-2012-3025

The default configuration of Tridium Niagara AX Framework through 3.6 uses a cleartext base64 format for transmission of credentials in cookies, whic…

Fix: after 3.6
Fix from $1,600 2012-08-16
Niagara Ax HIGH 7.8
CVE-2012-4028

Tridium Niagara AX Framework does not properly store credential data, which allows context-dependent attackers to bypass intended access restrictions…

Mitigation only
Fix from $1,950 2012-07-16
Extcalendar CRITICAL 9.8
CVE-2007-0681EPSS 5%

profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without providing the original password, …

Fix: after 2
Fix from $2,300 2007-02-03
Newsworld CRITICAL 9.8
CVE-2005-3435

admin_news.php in Archilles Newsworld up to 1.3.0 allows attackers to bypass authentication by obtaining the password hash for another user, for exam…

Fix: after 1.3.0
Fix from $2,300 2005-11-02
Script Center News Update CRITICAL 9.8
CVE-2000-0944EPSS 11%

CGI Script Center News Update 1.1 does not properly validate the original news administration password during a password change operation, which allo…

No fix yet
Fix from $2,300 2000-12-19
Ssh HIGH 8.4
CVE-1999-0013

Stolen credentials from SSH clients via ssh-agent program, allowing other local users to access remote accounts belonging to the ssh-agent user.

Mitigation only
Fix from $1,950 1998-01-22