Vulnerability index

Browse CVEs

1,244 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
Credentials Binding HIGH 7.3
CVE-2025-53650

Jenkins Credentials Binding Plugin 687.v619cb_15e923f and earlier does not properly mask (i.e., replace with asterisks) credentials present in except…

Fix: after 687.689.v1a_f775332fc
Fix from $1,950 2025-07-09
Statistics Gatherer MEDIUM 6.5
CVE-2025-53654

Jenkins Statistics Gatherer Plugin 2.0.3 and earlier stores the AWS Secret Key unencrypted in its global configuration file on the Jenkins controller…

Fix: after 2.0.3
Fix from $1,600 2025-07-09
Unclassified MEDIUM 6.4
CVE-2025-24508

Extraction of Account Connectivity Credentials (ACCs) from the IT Management Agent secure storage

Mitigation only
Fix from $1,600 2025-07-07
Nsclient\+\+ HIGH 7.8
CVE-2025-34078

A local privilege escalation vulnerability exists in NSClient++ 0.5.2.35 when both the web interface and ExternalScripts features are enabled. The co…

No fix yet
Fix from $1,950 2025-07-02
Unclassified MEDIUM 5.7
CVE-2025-34062

An information disclosure vulnerability exists in OneLogin AD Connector versions prior to 6.1.5 via the /api/adc/v4/configuration endpoint. An attack…

Mitigation only
Fix from $1,600 2025-07-01
Unclassified MEDIUM 6.8
CVE-2025-6081

Insufficiently Protected Credentials in LDAP in Konica Minolta bizhub 227 Multifunction printers version GCQ-Y3 or earlier allows an attacker can rec…

Mitigation only
Fix from $1,600 2025-07-01
Unclassified HIGH 8.1
CVE-2024-49364

tiny-secp256k1 is a tiny secp256k1 native/JS wrapper. Prior to version 1.1.7, a private key can be extracted on signing a malicious JSON-stringifiabl…

Patch available
Fix from $1,950 2025-07-01
Unclassified MEDIUM 6.8
CVE-2024-51984

An authenticated attacker can reconfigure the target device to use an external service (such as LDAP or FTP) controlled by the attacker. If an existi…

Mitigation only
Fix from $1,600 2025-06-25
M300 Firmware MEDIUM 5.3
CVE-2025-6526

A vulnerability, which was classified as problematic, has been found in 70mai M300 up to 20250611. This issue affects some unknown processing of the …

Fix: after 2025-06-11
Fix from $1,600 2025-06-23
Unclassified MEDIUM 5.5
CVE-2025-35941

A password is exposed locally.

No fix yet
Fix from $1,600 2025-06-11
011209 Sip Emergency Intercom Firmware HIGH 7.5
CVE-2025-30183

CyberData 011209 Intercom does not properly store or protect web server admin credentials.

Fix: 22.0.1+
Fix from $1,950 2025-06-09
Unclassified MEDIUM 5.3
CVE-2024-47081

Requests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific m…

Patch available
Fix from $1,600 2025-06-09
Cognos Controller MEDIUM 6.5
CVE-2025-33079

IBM Controller 11.0.0, 11.0.1, and 11.1.0 application could allow an authenticated user to obtain sensitive credentials that may be inadvertently inc…

Mitigation only
Fix from $1,600 2025-05-27
Pacs Server MEDIUM 6.5
CVE-2025-3480

MedDream WEB DICOM Viewer Cleartext Transmission of Credentials Information Disclosure Vulnerability. This vulnerability allows network-adjacent atta…

Mitigation only
Fix from $1,600 2025-05-22
Unclassified HIGH 8.7
CVE-2025-3079

A passback vulnerability which relates to office/small office multifunction printers and laser printers.

No fix yet
Fix from $1,950 2025-05-20
Unclassified HIGH 8.7
CVE-2025-3078

A passback vulnerability which relates to production printers and office multifunction printers.

Mitigation only
Fix from $1,950 2025-05-20
Active Backup For Microsoft 365 MEDIUM 6.5
CVE-2025-4679

A vulnerability in Synology Active Backup for Microsoft 365 allows remote authenticated attackers to obtain sensitive information via unspecified vec…

Mitigation only
Fix from $1,600 2025-05-16
Sterling Partner Engagement Manager HIGH 7.5
CVE-2025-33093

IBM Sterling Partner Engagement Manager 6.1.0, 6.2.0, 6.2.2 JWT secret is stored in public Helm Charts and is not stored as a Kubernetes secret.

Mitigation only
Fix from $1,950 2025-05-07
Unclassified HIGH 7.1
CVE-2025-46820

phpgt/Dom provides access to modern DOM APIs. Versions of phpgt/Dom prior to 4.1.8 expose the GITHUB_TOKEN in the Dom workflow run artifact. The ci.y…

Patch available
Fix from $1,950 2025-05-06
Router Firmware MEDIUM 6.5
CVE-2025-2772

BEC Technologies Multiple Routers Insufficiently Protected Credentials Information Disclosure Vulnerability. This vulnerability allows network-adjace…

Mitigation only
Fix from $1,600 2025-04-23
Unclassified MEDIUM 6.9
CVE-2025-32963

MinIO Operator STS is a native IAM Authentication for Kubernetes. Prior to version 7.1.0, if no audiences are provided for the `spec.audiences` field…

Patch available
Fix from $1,600 2025-04-22
Fm\/dab\/tv Transmitter Web Management System HIGH 7.5
CVE-2025-28228

A credential exposure vulnerability in Electrolink 500W, 1kW, 2kW Medium DAB Transmitter Web v01.09, v01.08, v01.07, and Display v1.4, v1.2 allows un…

No fix yet
Fix from $1,950 2025-04-18
Unclassified CRITICAL 9.3
CVE-2025-22372

Insufficiently Protected Credentials vulnerability in SicommNet BASEC on SaaS allows Password Recovery. Passwords are either stored in plain text usi…

Mitigation only
Fix from $2,300 2025-04-14
Azure Local Cluster MEDIUM 5.5
CVE-2025-26628

Insufficiently protected credentials in Azure Local Cluster allows an authorized attacker to disclose information locally.

Fix: 2411.2+
Fix from $1,600 2025-04-08
Unclassified HIGH 8.5
CVE-2025-2908

The exposure of credentials in the call forwarding configuration module in MeetMe products in versions prior to 2024-09 allows an attacker to gain ac…

Mitigation only
Fix from $1,950 2025-03-28
Unclassified CRITICAL 9.0
CVE-2025-2311

Incorrect Use of Privileged APIs, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in Sechard Info…

Mitigation only
Fix from $2,300 2025-03-20
Unclassified CRITICAL 9.1
CVE-2025-25650

An issue in the storage of NFC card data in Dorset DG 201 Digital Lock H5_433WBSK_v2.2_220605 allows attackers to produce cloned NFC cards to bypass …

Mitigation only
Fix from $2,300 2025-03-17
Devolutions Server HIGH 7.5
CVE-2025-2277

Exposure of password in web-based SSH authentication component in Devolutions Server 2024.3.13 and earlier allows a user to unadvertently leak his SS…

Fix: 2025.1.3.0+
Fix from $1,950 2025-03-13
Automation MEDIUM 5.3
CVE-2025-27926

In Nintex Automation 5.6 and 5.7 before 5.8, the K2 SmartForms Designer folder has configuration files (web.config) containing passwords that are rea…

Fix: 5.8+
Fix from $1,600 2025-03-10
Sterling File Gateway MEDIUM 5.3
CVE-2024-47109

IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 UI could disclosure the installation path of the server which could aid…

Fix: 6.1.2.7 / 6.2.0.4+
Fix from $1,600 2025-03-10