Vulnerability index

Browse CVEs

1,244 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
Indoor Connect 8855 Firmware HIGH 7.5
CVE-2025-40838

Ericsson Indoor Connect 8855 contains a vulnerability where server-side security can be bypassed in the client which if exploited can lead to unautho…

Fix: 2025.q2+
Fix from $1,950 2025-09-25
Unclassified MEDIUM 6.9
CVE-2025-10360

In Puppet Enterprise versions 2025.4.0 and 2025.5, the encryption key used for encrypting content in the Infra Assistant database was not excluded fr…

Mitigation only
Fix from $1,600 2025-09-24
Unclassified MEDIUM 5.3
CVE-2025-54467

When a Java command with password parameters is executed and terminated by NeuVector for Process rule violation the password will appear in the NeuVe…

Mitigation only
Fix from $1,600 2025-09-17
Nvdebug CRITICAL 9.8
CVE-2025-23342

The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to gain access to a privileged account . A successful exploit of this vulner…

Fix: 1.7.0+
Fix from $2,300 2025-09-09
Unclassified HIGH 8.8
CVE-2025-42933

When a user logs in via SAP Business One native client, the SLD backend service fails to enforce proper encryption of certain APIs. This leads to exp…

Mitigation only
Fix from $1,950 2025-09-09
Unclassified HIGH 8.8
CVE-2025-41682

An authenticated, low-privileged attacker can obtain credentials stored on the charge controller including the manufacturer password.

Mitigation only
Fix from $1,950 2025-09-08
Unclassified CRITICAL 9.4
CVE-2025-58366

Onyxia is a data science environment for kubernetes. In versions 4.6.0 through 4.8.0, Onyxia-API leaked the credentials of private helm repositories …

Patch available
Fix from $2,300 2025-09-05
Unclassified MEDIUM 5.1
CVE-2025-55739

api is a module for FreePBX@, which is an open source GUI that controls and manages Asterisk© (PBX). In versions lower than 15.0.13, 16.0.2 through 1…

Patch available
Fix from $1,600 2025-09-05
Unclassified MEDIUM 6.9
CVE-2025-57806

Local Deep Research is an AI-powered research assistant for deep, iterative research. Versions 0.2.0 through 0.6.7 stored confidential information, i…

Patch available
Fix from $1,600 2025-09-03
E3 Supervisory Controller Firmware CRITICAL 9.8
CVE-2025-6519

E3 Site Supervisor (firmware version < 2.31F01) has a default admin user "ONEDAY" with a daily generated password. An attacker can predictably genera…

Fix: 2.31f01+
Fix from $2,300 2025-09-02
E3 Supervisory Controller Firmware CRITICAL 9.8
CVE-2025-52549

E3 Site Supervisor Control (firmware version < 2.31F01) generates the root linux password on each boot. An attacker can generate the root linux passw…

Fix: 2.31f01+
Fix from $2,300 2025-09-02
E3 Supervisory Controller Firmware HIGH 7.5
CVE-2025-52545

E3 Site Supervisor Control (firmware version < 2.31F01) RCI service contains an API call to read users info, which returns all usernames and password…

Fix: 2.31f01+
Fix from $1,950 2025-09-02
Smart Deploy CRITICAL 9.8
CVE-2025-52095

An issue in PDQ Smart Deploy V.3.0.2040 allows an attacker to escalate privileges via the Credential encryption routines in SDCommon.dll

Fix: 3.0.2046+
Fix from $2,300 2025-08-22
Unclassified CRITICAL 9.8
CVE-2025-55306

GenX_FX is an advance IA trading platform that will focus on forex trading. A vulnerability was identified in the GenX FX backend where API keys and …

Mitigation only
Fix from $2,300 2025-08-19
Sante Pacs Server HIGH 7.5
CVE-2025-54156

The Sante PACS Server Web Portal sends credential information without encryption.

Fix: 4.2.3+
Fix from $1,950 2025-08-18
Simatic Rtls Locating Manager HIGH 7.8
CVE-2025-40751

A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.3). Affected SIMATIC RTLS Locating Manager Report Clients do …

Fix: 3.3+
Fix from $1,950 2025-08-12
Control M\/server HIGH 7.8
CVE-2025-48709

BMC Control-M/Server 9.0.21.300 displays cleartext database credentials in process lists and logs. An authenticated attacker with shell access could …

Mitigation only
Fix from $1,950 2025-08-07
Directory Manager MEDIUM 5.3
CVE-2025-54394

Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 has Insufficiently Protected Credentials for requests to remote Ex…

Fix: 11.1.25162.02+
Fix from $1,600 2025-08-07
Himmelblau HIGH 7.1
CVE-2025-54882

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. In versions 0.8.0 through 0.9.21 and 1.0.0-beta through 1.1.0, Himme…

Fix: 0.9.22 / 1.2.0+
Fix from $1,950 2025-08-07
Unclassified MEDIUM 6.9
CVE-2025-54876

The Janssen Project is an open-source identity and access management (IAM) platform. In versions 1.9.0 and below, Janssen stores passwords in plainte…

Patch available
Fix from $1,600 2025-08-06
Digital Delivery MEDIUM 5.3
CVE-2025-38739

Dell Digital Delivery, versions prior to 5.6.1.0, contains an Insufficiently Protected Credentials vulnerability. A remote unauthenticated attacker c…

Fix: 5.6.1.0+
Fix from $1,600 2025-08-04
Glpi MEDIUM 6.5
CVE-2025-53008

GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features,…

Fix: 10.0.19+
Fix from $1,600 2025-07-30
Sandboxie MEDIUM 5.5
CVE-2025-54422

Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. In versions 1.16.1 and below, a critical se…

Fix: 1.16.2+
Fix from $1,600 2025-07-29
Unclassified CRITICAL 9.8
CVE-2025-54428

RevelaCode is an AI-powered faith-tech project that decodes biblical verses, prophecies and global events into accessible language. In versions below…

Patch available
Fix from $2,300 2025-07-28
Opencast MEDIUM 6.5
CVE-2025-54380

Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to version 17.6, Opencast would inco…

Fix: 17.6+
Fix from $1,600 2025-07-26
Unclassified HIGH 8.7
CVE-2025-34139

A vulnerability exists in Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud that could allow an…

Mitigation only
Fix from $1,950 2025-07-25
Bl Ac3600 Firmware HIGH 7.5
CVE-2025-7565

A vulnerability, which was classified as critical, was found in LB-LINK BL-AC3600 up to 1.0.22. This affects the function geteasycfg of the file /cgi…

Fix: after 1.0.22
Fix from $1,950 2025-07-14
Applitools Eyes MEDIUM 5.3
CVE-2025-53743

Jenkins Applitools Eyes Plugin 1.16.5 and earlier does not mask Applitools API keys displayed on the job configuration form, increasing the potential…

Fix: 1.16.6+
Fix from $1,600 2025-07-09
Dead Man\'s Snitch MEDIUM 5.3
CVE-2025-53667

Jenkins Dead Man's Snitch Plugin 0.1 does not mask Dead Man's Snitch tokens displayed on the job configuration form, increasing the potential for att…

Mitigation only
Fix from $1,600 2025-07-09
Nouvola Divecloud MEDIUM 6.5
CVE-2025-53671

Jenkins Nouvola DiveCloud Plugin 1.08 and earlier does not mask DiveCloud API Keys and Credentials Encryption Keys displayed on the job configuration…

Fix: after 1.08
Fix from $1,600 2025-07-09