Vulnerability index

Browse CVEs

1,244 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
MEDIUM 6.5 CVE-2023-43777 Eaton easySoft software is used to program easy controllers and displays for configuring, programming and defining parameters for all the intelligent… Easysoft 8.01+ Fix from $1,6002023-10-17 MEDIUM 5.5 CVE-2023-27315 SnapGathers versions prior to 4.9 are susceptible to a vulnerability which could allow a local authenticated attacker to discover plaintext domain … Snapgathers 4.9+ Fix from $1,6002023-10-12 HIGH 8.2 CVE-2022-44757 BigFix Insights for Vulnerability Remediation (IVR) uses weak cryptography that can lead to credential exposure. An attacker could gain access to se… Bigfix Insights For Vulnerability Remediation 2.0.3+ Fix from $1,9502023-10-11 MEDIUM 5.3 CVE-2022-44758 BigFix Insights/IVR fixlet uses improper credential handling within certain fixlet content. An attacker can gain access to information that is not e… Bigfix Insights For Vulnerability Remediation 2.0.3+ Fix from $1,6002023-10-11 HIGH 7.5 CVE-2023-44158 Sensitive information disclosure due to insufficient token field masking. The following products are affected: Acronis Cyber Protect 15 (Linux, Windo… Cyber Protect 15+ Fix from $1,9502023-09-27 MEDIUM 5.5 CVE-2023-1633 A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining acce… Openstack Platform Mitigation only Fix from $1,6002023-09-24 HIGH 8.8 CVE-2023-43633 On boot, the Pillar eve container checks for the existence and content of “/config/GlobalConfig/global.json”. If the file exists, it overrides the e… Eve 8.6.0 / 9.5.0+ Fix from $1,9502023-09-21 HIGH 8.8 CVE-2023-43634 When sealing/unsealing the “vault” key, a list of PCRs is used, which defines which PCRs are used. In a previous project, CYMOTIVE found that the co… Eve 8.6.0 / 9.5.0+ Fix from $1,9502023-09-21 HIGH 8.8 CVE-2023-43631 On boot, the Pillar eve container checks for the existence and content of “/config/authorized_keys”. If the file is present, and contains a supporte… Edge Virtualization Engine 8.6.0 / 9.5.0+ Fix from $1,9502023-09-21 HIGH 8.8 CVE-2023-43630 PCR14 is not in the list of PCRs that seal/unseal the “vault” key, but due to the change that was implemented in commit “7638364bc0acf8b5c481b5ce5fea… Edge Virtualization Engine 9.5.0+ Fix from $1,9502023-09-20 HIGH 8.8 CVE-2023-43635 Vault Key Sealed With SHA1 PCRs The measured boot solution implemented in EVE OS leans on a PCR locking mechanism. Different parts of the syst… Edge Virtualization Engine 9.5.0+ Fix from $1,9502023-09-20 MEDIUM 5.5 CVE-2022-47561 The web application stores credentials in clear text in the "admin.xml" file, which can be accessed without logging into the website, which could all… Ekorccp Firmware Mitigation only Fix from $1,6002023-09-20 CRITICAL 9.8 CVE-2023-25531 NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause insufficient protection of credentials. A successful exploit of thi… Dgx H100 Firmware 23.08.18+ Fix from $2,3002023-09-20 HIGH 7.5 CVE-2023-25532 NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause insufficient protection of credentials. A successful exploit of thi… Dgx H100 Firmware 23.08.18+ Fix from $1,9502023-09-20 MEDIUM 5.5 CVE-2023-41010 Insecure Permissions vulnerability in Sichuan Tianyi Kanghe Communication Co., Ltd China Telecom Tianyi Home Gateway v.TEWA-700G allows a local attac… Tewa 700g Firmware No fix yet Fix from $1,6002023-09-14 MEDIUM 5.5 CVE-2023-32338 IBM Sterling Secure Proxy and IBM Sterling External Authentication Server 6.0.3 and 6.1.0 stores user credentials in plain clear text which can be re… Sterling External Authentication Server Mitigation only Fix from $1,6002023-09-05 CRITICAL 9.8 CVE-2022-45611 An issue was discovered in Fresenius Kabi PharmaHelp 5.1.759.0 allows attackers to gain escalated privileges via via capture of user login informatio… Pharmahelp Firmware Mitigation only Fix from $2,3002023-08-22 HIGH 7.5 CVE-2023-40173 Social media skeleton is an uncompleted/framework social media project implemented using a php, css ,javascript and html. Prior to version 1.0.5 Soci… Social Media Skeleton 1.0.5+ Fix from $1,9502023-08-18 MEDIUM 6.5 CVE-2023-31492EPSS 8% Zoho ManageEngine ADManager Plus version 7182 and prior disclosed the default passwords for the account restoration of unauthorized domains to the au… Manageengine Admanager Plus 7.1+ Fix from $1,6002023-08-17 MEDIUM 6.5 CVE-2023-40347 Jenkins Maven Artifact ChoiceListProvider (Nexus) Plugin 1.14 and earlier does not set the appropriate context for credentials lookup, allowing attac… Maven Artifact Choicelistprovider \(nexus\) after 1.14 Fix from $1,6002023-08-16 MEDIUM 6.5 CVE-2023-40345 Jenkins Delphix Plugin 3.0.2 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Overall/Read permission… Delphix after 3.0.2 Fix from $1,6002023-08-16 MEDIUM 5.5 CVE-2023-4327 Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user … Raid Controller Web Interface Mitigation only Fix from $1,6002023-08-15 MEDIUM 5.5 CVE-2023-4328 Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user… Raid Controller Web Interface Mitigation only Fix from $1,6002023-08-15 CRITICAL 9.8 CVE-2023-20965 In processMessageImpl of ClientModeImpl.java, there is a possible credential disclosure in the TOFU flow due to a logic error in the code. This could… Android Patch available Fix from $2,3002023-08-14 CRITICAL 9.8 CVE-2023-36082 An isssue in GatesAIr Flexiva FM Transmitter/Exiter Fax 150W allows a remote attacker to gain privileges via the LDAP and SMTP credentials. Flexiva Fax 150w Firmware Mitigation only Fix from $2,3002023-08-03 MEDIUM 6.5 CVE-2022-4926 Insufficient policy enforcement in Intents in Google Chrome on Android prior to 109.0.5414.119 allowed a remote attacker to bypass same origin policy… Chrome 109.0.5414.119+ Fix from $1,6002023-07-29 HIGH 7.5 CVE-2023-35067 Plaintext Storage of a Password vulnerability in Infodrom Software E-Invoice Approval System allows Read Sensitive Strings Within an Executable. Thi… E Invoice Approval System 20230701+ Fix from $1,9502023-07-25 HIGH 8.8 CVE-2023-37362 Weintek Weincloud v0.13.6 could allow an attacker to abuse the registration functionality to login with testing credentials to the official websi… Weincloud Mitigation only Fix from $1,9502023-07-19 HIGH 7.5 CVE-2023-31824 An issue found in DERICIA Co. Ltd, DELICIA v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token in … Delicia No fix yet Fix from $1,9502023-07-13 CRITICAL 9.8 CVE-2023-34128 Tomcat application credentials are hardcoded in SonicWall GMS and Analytics configuration file. This issue affects GMS: 9.3.2-SP1 and earlier version… Analytics 9.3.2+ Fix from $2,3002023-07-13