Vulnerability index

Browse CVEs

1,244 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
Rustfs CRITICAL 9.8
CVE-2026-22043

RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 through 1.0.0-alpha.78, a flawed `deny_only` short-circuit in…

Mitigation only
Fix from $2,300 2026-01-08
Dify MEDIUM 6.5
CVE-2025-67732

Dify is an open-source LLM app development platform. Prior to version 1.11.0, the API key is exposed in plaintext to the frontend, allowing non-admin…

Fix: 1.11.0+
Fix from $1,600 2026-01-05
Coolify HIGH 8.8
CVE-2025-64420

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions prior to and including v4.0.0…

Fix: 4.0.0+
Fix from $1,950 2026-01-05
Nplatform MEDIUM 5.5
CVE-2025-64122

Insufficiently Protected Credentials vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows Signature Spoofing by Key Theft.This issue …

Fix: after 2.5.1
Fix from $1,600 2026-01-02
Unclassified HIGH 7.5
CVE-2021-47741

ZBL EPON ONU Broadband Router V100R001 contains a privilege escalation vulnerability that allows limited administrative users to elevate access by se…

No fix yet
Fix from $1,950 2025-12-31
Unclassified HIGH 7.5
CVE-2021-47726

NuCom 11N Wireless Router 5.07.90 contains a privilege escalation vulnerability that allows non-privileged users to access administrative credentials…

No fix yet
Fix from $1,950 2025-12-31
Lares Firmware CRITICAL 9.3
CVE-2025-15113

Ksenia Security lares (legacy model) Home Automation version 1.6 contains an unprotected endpoint vulnerability that allows authenticated attackers t…

Mitigation only
Fix from $2,300 2025-12-30
Open Ondemand HIGH 7.6
CVE-2025-66029

Open OnDemand provides remote web access to supercomputers. In versions 4.0.8 and prior, the Apache proxy allows sensitive headers to be passed to or…

Fix: after 4.0.8
Fix from $1,950 2025-12-17
Devops Deploy MEDIUM 6.5
CVE-2025-14148

IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 could allow an authenticated user with LLM integration configuration privileges to recover a previous…

Fix: 8.1.2.4+
Fix from $1,600 2025-12-15
Fineract CRITICAL 9.1
CVE-2025-58130

Insufficiently Protected Credentials vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.11.0. The issue is fixed in ver…

Fix: 1.12.1+
Fix from $2,300 2025-12-12
Qihang Media Web Digital Signage HIGH 7.5
CVE-2020-36896

QiHang Media Web Digital Signage 3.0.9 contains a cleartext credentials vulnerability that allows unauthenticated attackers to access administrative …

No fix yet
Fix from $1,950 2025-12-10
Coldfusion MEDIUM 5.3
CVE-2025-64898

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Insufficiently Protected Credentials vulnerability that could result in l…

Mitigation only
Fix from $1,600 2025-12-10
Rs232\/485 To Wifi Eth \(b\) Firmware MEDIUM 5.7
CVE-2025-63361

Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.002880.0301 was discovered to r…

No fix yet
Fix from $1,600 2025-12-04
Icip 30 Firmware HIGH 7.5
CVE-2025-13187

A security vulnerability has been detected in Intelbras ICIP 2.0.20. Affected is an unknown function of the file /xml/sistema/acessodeusuario.xml. Su…

No fix yet
Fix from $1,950 2025-11-14
Vios HIGH 8.1
CVE-2025-36096

IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 stores NIM private keys used in NIM environments in an insecure way which is susceptible to unauthoriz…

Mitigation only
Fix from $1,950 2025-11-13
Unclassified MEDIUM 6.0
CVE-2025-6571

A 3rd-party component exposed its password in process arguments, allowing for low-privileged users to access it.

Mitigation only
Fix from $1,600 2025-11-11
Unclassified MEDIUM 5.3
CVE-2025-42897

Due to information disclosure vulnerability in anonymous API provided by SAP Business One (SLD), an attacker with normal user access could gain acces…

Mitigation only
Fix from $1,600 2025-11-11
Unclassified MEDIUM 6.5
CVE-2025-12636

The Ubia camera ecosystem fails to adequately secure API credentials, potentially enabling an attacker to connect to backend services. The attacker…

Mitigation only
Fix from $1,600 2025-11-06
Vizair CRITICAL 9.8
CVE-2025-54863

Radiometrics VizAir is vulnerable to exposure of the system's REST API key through a publicly accessible configuration file. This allows attackers to…

Fix: 2025-08+
Fix from $2,300 2025-11-04
Unclassified MEDIUM 6.9
CVE-2025-12461

This vulnerability allows an attacker to access parts of the application that are not protected by any type of access control. The attacker could ac…

Mitigation only
Fix from $1,600 2025-10-29
Unclassified HIGH 7.2
CVE-2025-61482

Improper handling of OTP/TOTP/HOTP values in NetKnights GmbH privacyIDEA Authenticator v.4.3.0 on Android allows local attackers with root access to …

Mitigation only
Fix from $1,950 2025-10-27
Unclassified HIGH 7.8
CVE-2025-54808

Oxford Nanopore Technologies' MinKNOW software at or prior to version 24.11 stores authentication tokens in a file located in the system's temporary …

Mitigation only
Fix from $1,950 2025-10-23
Traveler For Microsoft Outlook MEDIUM 5.5
CVE-2024-42192

HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a credential leakage which could allow an attacker to access other computers or applicati…

Fix: 3.0.14+
Fix from $1,600 2025-10-16
Argo Workflows MEDIUM 6.5
CVE-2025-62157

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Argo Workflows versions prior to 3.6…

Fix: 3.6.12 / 3.7.3+
Fix from $1,600 2025-10-14
Project Center MEDIUM 5.3
CVE-2025-35054

Newforma Info Exchange (NIX) stores credentials used to configure NPCS in 'HKLM\Software\WOW6432Node\Newforma\<version>\Credentials'. The credential…

Fix: after 2024.3
Fix from $1,600 2025-10-09
Unclassified MEDIUM 5.4
CVE-2025-37728

Insufficiently Protected Credentials in the Crowdstrike connector can lead to Crowdstrike credentials being leaked. A malicious user can access cache…

Mitigation only
Fix from $1,600 2025-10-07
Virtual Appliance Application CRITICAL 9.8
CVE-2025-34207

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to 22.0.1049 and Application prior to 20.0.2786 (VA and SaaS deployments) configure…

Fix: 20.0.2786 / 22.0.1049+
Fix from $2,300 2025-09-29
Virtual Appliance Application CRITICAL 9.8
CVE-2025-34196

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application prior to 25.1.1413 (Windows client deployments…

Fix: 25.1.102 / 25.1.1413+
Fix from $2,300 2025-09-29
Dt R002 Firmware HIGH 7.5
CVE-2025-10880

All versions of Dingtian DT-R002 are vulnerable to an Insufficiently Protected Credentials vulnerability that could allow an attacker to extract the …

Mitigation only
Fix from $1,950 2025-09-25
Dt R002 Firmware MEDIUM 5.3
CVE-2025-10879

All versions of Dingtian DT-R002 are vulnerable to an Insufficiently Protected Credentials vulnerability that could allow an attacker to retrieve the…

Mitigation only
Fix from $1,600 2025-09-25