Vulnerability index

Browse CVEs

1,244 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
CRITICAL 9.8 CVE-2023-48010 STMicroelectronics SPC58 is vulnerable to Missing Protection Mechanism for Alternate Hardware Interface. Code running as Supervisor on the SPC58 Powe… Mitigation only Fix from $2,3002024-12-05 HIGH 7.5 CVE-2024-51546 Credentials Disclosure vulnerabilities allow access to on board project back-up bundles.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEX… Aspect Ent 12 Firmware 3.08.03+ Fix from $1,9502024-12-05 CRITICAL 9.8 CVE-2024-51545 Username Enumeration vulnerabilities allow access to application level username add, delete, modify and list functions.  Affected products: ABB ASP… Aspect Ent 12 Firmware 3.08.03+ Fix from $2,3002024-12-05 MEDIUM 6.5 CVE-2024-42457 A vulnerability in Veeam Backup & Replication allows users with certain operator roles to expose saved credentials by leveraging a combination of met… Veeam Backup \& Replication 12.3.0.310+ Fix from $1,6002024-12-04 CRITICAL 9.0 CVE-2019-17082 Insufficiently Protected Credentials vulnerability in OpenText™ AccuRev allows Authentication Bypass. When installed on a Linux or Solaris system th… Mitigation only Fix from $2,3002024-11-26 MEDIUM 5.7 CVE-2024-11703 On Android, Firefox may have inadvertently allowed viewing saved passwords without the required device PIN authentication. This vulnerability affects… Firefox 133.0+ Fix from $1,6002024-11-26 MEDIUM 6.3 CVE-2024-6749 Seth Fogie, member of the AXIS Camera Station Pro Bug Bounty Program, has found that the Incident report feature may expose sensitive credentials on … Mitigation only Fix from $1,6002024-11-26 MEDIUM 5.5 CVE-2024-47142 AIPHONE IXG SYSTEM IXG-2C7 firmware Ver.2.03 and earlier and IXG-2C7-L firmware Ver.2.03 and earlier contain an issue with insufficiently protected c… Mitigation only Fix from $1,6002024-11-22 MEDIUM 6.5 CVE-2024-39290 Insufficiently protected credentials issue exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent unauthenticated attacker may obtain sensiti… Mitigation only Fix from $1,6002024-11-22 MEDIUM 6.5 CVE-2021-1232 A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to read arb… Catalyst Sd Wan Manager Mitigation only Fix from $1,6002024-11-18 CRITICAL 9.1 CVE-2022-45157 A vulnerability has been identified in the way that Rancher stores vSphere's CPI (Cloud Provider Interface) and CSI (Container Storage Interface) cre… Mitigation only Fix from $2,3002024-11-13 HIGH 8.0 CVE-2024-51240 An issue in the luci-mod-rpc package in OpenWRT Luci LTS allows for privilege escalation from an admin account to root via the JSON-RPC-API, which is… Mitigation only Fix from $1,9502024-11-05 MEDIUM 6.8 CVE-2024-34885 Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to read SMTP accounts pass… Bitrix24 No fix yet Fix from $1,6002024-11-04 HIGH 7.5 CVE-2023-50310 IBM CICS Transaction Gateway for Multiplatforms 9.2 and 9.3 transmits or stores authentication credentials, but it uses an insecure method that is su… Cics Transaction Gateway Mitigation only Fix from $1,9502024-10-23 HIGH 8.4 CVE-2024-43812 Kieback & Peter's DDC4000 series has an insufficiently protected credentials vulnerability, which may allow an unauthenticated attacker with access t… Mitigation only Fix from $1,9502024-10-22 HIGH 7.8 CVE-2024-9677 The insufficiently protected credentials vulnerability in the CLI command of the USG FLEX H series uOS firmware version V1.21 and earlier versions co… Uos 1.30+ Fix from $1,9502024-10-22 CRITICAL 9.8 CVE-2024-44000EPSS 82% Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Authentication Bypass.This issue … Litespeed Cache 6.5.0.1+ Fix from $2,3002024-10-20 HIGH 8.2 CVE-2024-7755 The EWON FLEXY 202 transmits credentials using a weak encoding method base64. An attacker who is present in the network can sniff the traffic and dec… Mitigation only Fix from $1,9502024-10-17 HIGH 8.7 CVE-2024-49396 The affected product is vulnerable due to insufficiently protected credentials, which may allow an attacker to impersonate Elvaco and send false info… Mitigation only Fix from $1,9502024-10-17 MEDIUM 5.5 CVE-2024-20462 A vulnerability in the web-based management interface of Cisco ATA 190 Series Multiplatform Analog Telephone Adapter firmware could allow an authenti… Ata 191 Firmware 11.2.5 / 12.0.2+ Fix from $1,6002024-10-16 MEDIUM 6.5 CVE-2024-47161 In JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST API Teamcity 2024.07.3+ Fix from $1,6002024-10-08 HIGH 7.5 CVE-2024-47805 Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentials using… Credentials 1371.1373.v4eb_fa_b_7161e9 / 1380.va_435002fa_924+ Fix from $1,9502024-10-02 MEDIUM 5.7 CVE-2024-34542 Advantech ADAM-5630 shares user credentials plain text between the device and the user source device during the login process. Adam 5630 Firmware 2.5.2+ Fix from $1,6002024-09-27 MEDIUM 5.7 CVE-2024-37187 Advantech ADAM-5550 share user credentials with a low level of encryption, consisting of base 64 encoding. Adam 5550 Firmware Mitigation only Fix from $1,6002024-09-27 MEDIUM 6.5 CVE-2024-9014EPSS 10% pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially ob… Pgadmin 4 8.12+ Fix from $1,6002024-09-23 MEDIUM 5.5 CVE-2024-40703 IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and IBM Cognos Analytics Reports for iOS 11.0.0.7 could … Cognos Analytics 12.0.3+ Fix from $1,6002024-09-22 MEDIUM 5.3 CVE-2024-47162 In JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports page Youtrack 2024.3.44799+ Fix from $1,6002024-09-19 CRITICAL 9.1 CVE-2024-8986 The grafana plugin SDK bundles build metadata into the binaries it compiles; this metadata includes the repository URI for the plugin being built, as… Mitigation only Fix from $2,3002024-09-19 HIGH 7.5 CVE-2024-8777 OMFLOW from The SYSCOM Group has an information leakage vulnerability, allowing unauthorized remote attackers to read arbitrary system configurations… Omflow 1.2.1.3+ Fix from $1,9502024-09-16 HIGH 8.1 CVE-2024-31415 The Eaton Foreseer software provides the feasibility for the user to configure external servers for multiple purposes such as network management, use… Foreseer Electrical Power Monitoring System 7.8.600+ Fix from $1,9502024-09-13