Vulnerability index

Browse CVEs

1,244 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
HIGH 7.5 CVE-2023-50291 Insufficiently Protected Credentials vulnerability in Apache Solr. This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.3.… Solr 8.11.3 / 9.3.0+ Fix from $1,9502024-02-09 HIGH 7.1 CVE-2024-24595 Allegro AI’s open-source version of ClearML stores passwords in plaintext within the MongoDB instance, resulting in a compromised server leaking all … Clearml Mitigation only Fix from $1,9502024-02-05 MEDIUM 5.5 CVE-2024-21869 In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the affected product stores plaintext credentials in various places. This may al… Rapid Scada after 5.8.4 Fix from $1,6002024-02-02 HIGH 7.5 CVE-2023-29055 In Apache Kylin version 2.0.0 to 4.0.3, there is a Server Config web interface that displays the content of file 'kylin.properties', that may contain… Kylin 4.0.4+ Fix from $1,9502024-01-29 MEDIUM 6.5 CVE-2024-22432 Networker 19.9 and all prior versions contains a Plain-text Password stored in temporary config file during backup duration in NMDA MySQL Database ba… Networker after 19.9 Fix from $1,6002024-01-25 MEDIUM 5.5 CVE-2023-6573 HPE OneView may have a missing passphrase during restore. Oneview 8.70+ Fix from $1,6002024-01-23 HIGH 7.5 CVE-2023-49106 Missing Password Field Masking vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Agent component).This issue affects Hitachi … Device Manager 8.8.5-04+ Fix from $1,9502024-01-16 MEDIUM 5.9 CVE-2023-50125 A default engineer password set on the Hozard alarm system (Alarmsysteem) v1.0 allows an attacker to bring the alarm system to a disarmed state. Alarm System Mitigation only Fix from $1,6002024-01-11 MEDIUM 5.3 CVE-2023-29447 An insufficiently protected credentials vulnerability in KEPServerEX could allow an adversary to capture user credentials as the web server uses basi… Kepware Kepserverex after 8.5 Fix from $1,6002024-01-10 HIGH 7.5 CVE-2023-6421 The Download Manager WordPress plugin before 3.2.83 does not protect file download's passwords, leaking it upon receiving an invalid one. Download Manager 3.2.83+ Fix from $1,9502024-01-01 MEDIUM 6.5 CVE-2022-39820 In Network Element Manager in NOKIA NFM-T R19.9, an Unprotected Storage of Credentials vulnerability occurs under /root/RestUploadManager.xml.DRC and… Network Functions Manager For Transport No fix yet Fix from $1,6002023-12-25 MEDIUM 5.3 CVE-2023-47741 IBM i 7.3, 7.4, 7.5, IBM i Db2 Mirror for i 7.4 and 7.5 web browser clients may leave clear-text passwords in browser memory that can be viewed using… Db2 Mirror For I Patch available Fix from $1,6002023-12-18 MEDIUM 6.7 CVE-2023-50770 Jenkins OpenId Connect Authentication Plugin 2.6 and earlier stores a password of a local user account used as an anti-lockout feature in a recoverab… Openid after 2.6 Fix from $1,6002023-12-13 CRITICAL 9.8 CVE-2023-47577 An issue discovered in Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 allows for unauthorized password changes due to no check for current password. Rely Pcie Firmware Mitigation only Fix from $2,3002023-12-13 HIGH 7.5 CVE-2018-16153 An issue was discovered in Apereo Opencast 4.x through 10.x before 10.6. It sends system digest credentials during authentication attempts to arbitra… Opencast 10.6+ Fix from $1,9502023-12-12 MEDIUM 5.5 CVE-2023-47722 IBM API Connect V10.0.5.3 and V10.0.6.0 stores user credentials in browser cache which can be read by a local user. IBM X-Force ID: 271912. Api Connect Mitigation only Fix from $1,6002023-12-09 HIGH 7.2 CVE-2023-32268 Exposure of Proxy Administrator Credentials An authenticated administrator equivalent Filr user can access the credentials of proxy administrators. Filr 23.2.1+ Fix from $1,9502023-12-06 MEDIUM 6.5 CVE-2023-49280 XWiki Change Request is an XWiki application allowing to request changes on a wiki without publishing directly the changes. Change request allows to … Change Request 1.10+ Fix from $1,6002023-12-04 MEDIUM 6.8 CVE-2023-24047 An Insecure Credential Management issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges via use of w… Ac21000 G6 Firmware Mitigation only Fix from $1,6002023-12-04 MEDIUM 5.5 CVE-2023-44300 Dell DM5500 5.14.0.0, contain a Plain-text Password Storage Vulnerability in the appliance. A local attacker with privileges could potentially exploi… Powerprotect Data Manager Dm5500 Firmware after 5.14.0.0 Fix from $1,6002023-12-04 MEDIUM 6.5 CVE-2023-49653 Jenkins Jira Plugin 3.11 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission t… Jira after 3.11 Fix from $1,6002023-11-29 HIGH 7.5 CVE-2023-6254 A Vulnerability in OTRS AgentInterface and ExternalInterface allows the reading of plain text passwords which are send back to the client in the serv… Otrs after 8.0.37 Fix from $1,9502023-11-27 HIGH 7.5 CVE-2023-44303 RVTools, Version 3.9.2 and above, contain a sensitive data exposure vulnerability in the password encryption utility (RVToolsPasswordEncryption.exe) … Rvtools 4.5.0+ Fix from $1,9502023-11-24 MEDIUM 6.5 CVE-2023-41676 An exposure of sensitive information to an unauthorized actor [CWE-200] in FortiSIEM version 7.0.0 and before 6.7.5 may allow an attacker with acces… Fortisiem after 6.7.5 Fix from $1,6002023-11-14 MEDIUM 6.5 CVE-2020-17477 Incorrect LDAP ACLs in ucs-school-ldap-acls-master in UCS@school before 4.4v5-errata allow remote teachers, staff, and school administrators to read … Ucs\@school after 4.4 Fix from $1,6002023-10-26 HIGH 7.5 CVE-2023-43905 Incorrect access control in writercms v1.1.0 allows attackers to directly obtain backend account passwords via unspecified vectors. Writercms Mitigation only Fix from $1,9502023-10-26 MEDIUM 6.5 CVE-2023-46651 Jenkins Warnings Plugin 10.5.0 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permis… Warnings after 10.5.0 Fix from $1,6002023-10-25 MEDIUM 5.5 CVE-2023-46115 Tauri is a framework for building binaries for all major desktop platforms. This advisory is not describing a vulnerability in the Tauri code base it… Tauri 2.0.0+ Fix from $1,6002023-10-20 HIGH 7.5 CVE-2023-5552 A password disclosure vulnerability in the Secure PDF eXchange (SPX) feature allows attackers with full email access to decrypt PDFs in Sophos Firewa… Firewall after 19.5.3 Fix from $1,9502023-10-18 CRITICAL 9.8 CVE-2023-27132 TSplus Remote Work 16.0.0.0 places a cleartext password on the "var pass" line of the HTML source code for the secure single sign-on web portal. NOTE… Tsplus Remote Work after 16.0.0.0 Fix from $2,3002023-10-17