Vulnerability index

Browse CVEs

1,244 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
HIGH 8.5 CVE-2024-28981 Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.8, including 8.3.x, discloses database passwords when searchi… Mitigation only Fix from $1,9502024-09-12 MEDIUM 5.5 CVE-2024-20489 A vulnerability in the storage method of the PON Controller configuration file could allow an authenticated, local attacker with low privileges to ob… Ios Xr Mitigation only Fix from $1,6002024-09-11 HIGH 8.8 CVE-2024-40710 A series of related high-severity vulnerabilities, the most notable enabling remote code execution (RCE) as the service account and extraction of sen… Veeam Backup \& Replication 12.2.0.334+ Fix from $1,9502024-09-07 HIGH 8.8 CVE-2023-49233 Insufficient access checks in Visual Planning Admin Center 8 before v.1 Build 240207 allow attackers in possession of a non-administrative Visual Pla… No fix yet Fix from $1,9502024-09-03 MEDIUM 6.8 CVE-2024-31800 Authentication Bypass in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to gain a privileged command shell via the U… Gncc C2 Firmware No fix yet Fix from $1,6002024-08-15 HIGH 7.5 CVE-2024-7813 A vulnerability, which was classified as problematic, has been found in SourceCodester Prison Management System 1.0. This issue affects some unknown … Prison Management System No fix yet Fix from $1,9502024-08-15 MEDIUM 6.5 CVE-2024-39818 Protection mechanism failure for some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct information disclosure via network acce… Workplace Desktop 5.17.13 / 6.0.0+ Fix from $1,6002024-08-14 HIGH 8.1 CVE-2024-36460 The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain text. Zabbix after 6.4.15 Fix from $1,9502024-08-12 CRITICAL 9.1 CVE-2024-6118 A Plaintext Storage of a Password vulnerability in ebooknote function in Hamastar MeetingHub Paperless Meetings 2021 allows remote attackers to obtai… Meetinghub Paperless Meetings Mitigation only Fix from $2,3002024-08-05 HIGH 7.5 CVE-2024-7389 The Forminator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.29.1 via class-forminator… Forminator 1.29.2+ Fix from $1,9502024-08-02 HIGH 7.4 CVE-2024-6492 Exposure of Sensitive Information in edge browser session proxy feature in Devolutions Remote Desktop Manager 2024.2.14.0 and earlier on Windows allo… Remote Desktop Manager 2024.2.15.0+ Fix from $1,9502024-07-16 MEDIUM 5.5 CVE-2024-39733 IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 stores user credentials in plain clear text which can be read by a local user. IBM X-For… Datacap Mitigation only Fix from $1,6002024-07-14 HIGH 7.5 CVE-2024-38453 The Avalara for Salesforce CPQ app before 7.0 for Salesforce allows attackers to read an API key. NOTE: the current version is 11 as of mid-2024. Mitigation only Fix from $1,9502024-07-03 HIGH 8.8 CVE-2023-41926 The webserver utilizes basic authentication for its user login to the configuration interface. As encryption is disabled on port 80, it enables poten… Mitigation only Fix from $1,9502024-07-02 MEDIUM 5.3 CVE-2024-39878 In JetBrains TeamCity before 2024.03.3 private key could be exposed via testing GitHub App Connection Teamcity 2024.03.3+ Fix from $1,6002024-07-01 MEDIUM 5.3 CVE-2024-39879 In JetBrains TeamCity before 2024.03.3 application token could be exposed in EC2 Cloud Profile settings Teamcity 2024.03.3+ Fix from $1,6002024-07-01 HIGH 7.5 CVE-2024-38505 In JetBrains YouTrack before 2024.2.34646 user access token was sent to the third-party site Youtrack 2024.2.34646+ Fix from $1,9502024-06-18 HIGH 8.5 CVE-2024-38282 Utilizing default credentials, an attacker is able to log into the camera's operating system which could allow changes to be made to the operations o… Mitigation only Fix from $1,9502024-06-13 HIGH 7.0 CVE-2024-38285 Logs storing credentials are insufficiently protected and can be decoded through the use of open source tools. Mitigation only Fix from $1,9502024-06-13 MEDIUM 6.5 CVE-2024-26330 An issue was discovered in Kape CyberGhostVPN 8.4.3.12823 on Windows. After a successful logout, user credentials remain in memory while the process … Mitigation only Fix from $1,6002024-06-11 MEDIUM 5.5 CVE-2024-35208 A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server stored the password… Sinec Traffic Analyzer 1.2+ Fix from $1,6002024-06-11 HIGH 7.5 CVE-2024-37051 GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 202… Aqua 2023.1.3 / 2023.1.6+ Fix from $1,9502024-06-10 HIGH 8.1 CVE-2024-5657 The CraftCMS plugin Two-Factor Authentication in versions 3.3.1, 3.3.2 and 3.3.3 discloses the password hash of the currently authenticated user afte… Two Factor Authentication 3.3.4+ Fix from $1,9502024-06-06 HIGH 7.5 CVE-2024-36127 apko is an apk-based OCI image builder. apko exposures HTTP basic auth credentials from repository and keyring URLs in log output. This vulnerability… Patch available Fix from $1,9502024-06-03 CRITICAL 9.4 CVE-2024-5176 Insufficiently Protected Credentials vulnerability in Baxter Welch Allyn Configuration Tool may allow Remote Services with Stolen Credentials.This is… Mitigation only Fix from $2,3002024-05-31 MEDIUM 6.5 CVE-2024-33849 ci solution CI-Out-of-Office Manager through 6.0.0.77 uses a Hard-coded Cryptographic Key. Mitigation only Fix from $1,6002024-05-28 MEDIUM 5.5 CVE-2024-35192 Trivy is a security scanner. Prior to 0.51.2, if a malicious actor is able to trigger Trivy to scan container images from a crafted malicious registr… Patch available Fix from $1,6002024-05-20 CRITICAL 9.8 CVE-2024-36081 Westermo EDW-100 devices through 2024-05-03 allow an unauthenticated user to download a configuration file containing a cleartext password. NOTE: thi… Mitigation only Fix from $2,3002024-05-19 MEDIUM 6.7 CVE-2024-23583 An attacker could potentially intercept credentials via the task manager and perform unauthorized access to the Client Deploy Tool on Windows systems. Bigfix Platform 9.5.25 / 10.0.12+ Fix from $1,6002024-05-17 HIGH 7.6 CVE-2024-27109 Insufficiently protected credentials in GE HealthCare EchoPAC products Mitigation only Fix from $1,9502024-05-14