Vulnerability index

Browse CVEs

1,246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
HIGH 7.5 CVE-2023-31824 An issue found in DERICIA Co. Ltd, DELICIA v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token in … Delicia No fix yet Fix from $1,9502023-07-13 CRITICAL 9.8 CVE-2023-34128 Tomcat application credentials are hardcoded in SonicWall GMS and Analytics configuration file. This issue affects GMS: 9.3.2-SP1 and earlier version… Analytics 9.3.2+ Fix from $2,3002023-07-13 MEDIUM 6.5 CVE-2023-37951 Jenkins mabl Plugin 0.0.46 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission… Mabl after 0.0.46 Fix from $1,6002023-07-12 MEDIUM 5.5 CVE-2023-36266 An issue was discovered in Keeper Password Manager for Desktop version 16.10.2 (fixed in 17.2), and the KeeperFill Browser Extensions version 16.5.4 … Keeper No fix yet Fix from $1,6002023-07-12 MEDIUM 6.5 CVE-2023-35348 Active Directory Federation Service Security Feature Bypass Vulnerability Windows Server 2016 Patch available Fix from $1,6002023-07-11 MEDIUM 5.5 CVE-2023-36476 calamares-nixos-extensions provides Calamares branding and modules for NixOS, a distribution of GNU/Linux. Users of calamares-nixos-extensions versio… Calamares Nixos Extensions 0.3.13+ Fix from $1,6002023-06-29 HIGH 7.5 CVE-2020-18406 An issue was discovered in cmseasy v7.0.0 that allows user credentials to be sent in clear text due to no encryption of form data. Cmseasy No fix yet Fix from $1,9502023-06-27 HIGH 7.5 CVE-2023-28857 Apereo CAS is an open source multilingual single sign-on solution for the web. Apereo CAS can be configured to use authentication based on client X50… Central Authentication Service 6.5.9.1 / 6.6.6+ Fix from $1,9502023-06-27 MEDIUM 5.5 CVE-2023-35789 An issue was discovered in the C AMQP client library (aka rabbitmq-c) through 0.13.0 for RabbitMQ. Credentials can only be entered on the command lin… Rabbitmq C after 0.13.0 Fix from $1,6002023-06-16 HIGH 7.3 CVE-2022-47376 The Alaris Infusion Central software, versions 1.1 to 1.3.2, may contain a recoverable password after the installation. No patient health data is sto… Alaris Infusion Central after 1.3.2 Fix from $1,9502023-06-13 MEDIUM 5.9 CVE-2023-33620 GL.iNET GL-AR750S-Ext firmware v3.215 uses an insecure protocol in its communications which allows attackers to eavesdrop via a man-in-the-middle att… Gl Ar750s Firmware No fix yet Fix from $1,6002023-06-13 CRITICAL 9.8 CVE-2023-26204 A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 al… Fortisiem after 6.7.5 Fix from $2,3002023-06-13 HIGH 7.5 CVE-2023-29168 The local Vuforia web application does not support HTTPS, and federated credentials are passed via basic authentication. Vuforia Studio 9.9+ Fix from $1,9502023-06-07 HIGH 7.5 CVE-2023-22862 IBM Aspera Connect 4.2.5 and IBM Aspera Cargo 4.2.5 transmits authentication credentials, but it uses an insecure method that is susceptible to unaut… Aspera Cargo 4.2.6+ Fix from $1,9502023-06-05 HIGH 8.8 CVE-2023-25740 After downloading a Windows <code>.scf</code> script from the local filesystem, an attacker could supply a remote path that would lead to unexpected … Firefox 110.0+ Fix from $1,9502023-06-02 MEDIUM 6.5 CVE-2023-31187 Avaya IX Workforce Engagement v15.2.7.1195 - CWE-522: Insufficiently Protected Credentials Ix Workforce Engagement No fix yet Fix from $1,6002023-05-30 MEDIUM 6.5 CVE-2023-32687 tgstation-server is a toolset to manage production BYOND servers. Starting in version 4.7.0 and prior to 5.12.1, instance users with the list chat bo… Tgstation Server 5.12.1+ Fix from $1,6002023-05-29 HIGH 7.5 CVE-2023-33263 In WFTPD 3.25, usernames and password hashes are stored in an openly viewable wftpd.ini configuration file within the WFTPD directory. NOTE: this is … Wftpd No fix yet Fix from $1,9502023-05-25 MEDIUM 6.5 CVE-2023-1763 Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS … Ij Network Tool after 4.7.5 Fix from $1,6002023-05-17 HIGH 7.5 CVE-2023-33000 Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.149 and earlier does not mask credentials displayed on the configuration form, increasin… Ns Nd Integration Performance Publisher after 4.8.0.149 Fix from $1,9502023-05-16 MEDIUM 5.3 CVE-2022-47880 An Information disclosure vulnerability in /be/rpc.php in Jedox GmbH Jedox 2020.2.5 allow remote, authenticated users with permissions to modify data… Jedox No fix yet Fix from $1,6002023-05-12 MEDIUM 6.5 CVE-2022-40685 Insufficiently protected credentials in the Intel(R) DCM software before version 5.0.1 may allow an authenticated user to potentially enable informat… Data Center Manager 5.0.1+ Fix from $1,6002023-05-10 HIGH 8.8 CVE-2023-20046 A vulnerability in the key-based SSH authentication feature of Cisco StarOS Software could allow an authenticated, remote attacker to elevate privile… Staros 21.22.14 / 21.23.31+ Fix from $1,9502023-05-09 MEDIUM 5.9 CVE-2023-31136 PostgresNIO is a Swift client for PostgreSQL. Any user of PostgresNIO prior to version 1.14.2 connecting to servers with TLS enabled is vulnerable to… Postgresnio 1.14.2+ Fix from $1,6002023-05-09 MEDIUM 5.9 CVE-2023-28764 SAP BusinessObjects Platform - versions 420, 430, Information design tool transmits sensitive information as cleartext in the binaries over the netwo… Businessobjects Mitigation only Fix from $1,6002023-05-09 HIGH 7.5 CVE-2023-24506 Milesight NCR/camera version 71.8.0.6-r5 exposes credentials through an unspecified request. Ncr\/camera Firmware Mitigation only Fix from $1,9502023-05-08 HIGH 7.5 CVE-2023-2335 Plaintext Password in Registry vulnerability in 42gears surelock windows surelockwinsetupv2.40.0.Exe on Windows (Registery modules) allows Retrieve… Surelock after 2.40.0 Fix from $1,9502023-04-27 CRITICAL 9.8 CVE-2023-1778 This vulnerability exists in GajShield Data Security Firewall firmware versions prior to v4.28 (except v4.21) due to insecure default credentials whi… Data Security Firewall Firmware 4.21 / 4.28+ Fix from $2,3002023-04-27 HIGH 7.5 CVE-2023-30846 typed-rest-client is a library for Node Rest and Http Clients with typings for use with TypeScript. Users of the typed-rest-client library version 1.… Typed Rest Client 1.8.0+ Fix from $1,9502023-04-26 HIGH 8.1 CVE-2023-26567 Sangoma FreePBX 1805 through 2302 (when obtained as a ,.ISO file) places AMPDBUSER, AMPDBPASS, AMPMGRUSER, and AMPMGRPASS in the list of global varia… Freepbx Linux 7 Mitigation only Fix from $1,9502023-04-26