Vulnerability index

Browse CVEs

1,246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
CRITICAL 9.8 CVE-2022-32518 A CWE-522: Insufficiently Protected Credentials vulnerability exists that could result in unwanted access to a DCE instance when performed over a net… Data Center Expert 7.9.0+ Fix from $2,3002023-01-30 CRITICAL 9.8 CVE-2022-32519 A CWE-257: Storing Passwords in a Recoverable Format vulnerability exists that could result in unwanted access to a DCE instance when performed over … Data Center Expert 7.9.0+ Fix from $2,3002023-01-30 CRITICAL 9.8 CVE-2022-32520 A CWE-522: Insufficiently Protected Credentials vulnerability exists that could result in unwanted access to a DCE instance when performed over a net… Data Center Expert 7.9.0+ Fix from $2,3002023-01-30 CRITICAL 9.8 CVE-2022-46967 An access control issue in Revenue Collection System v1.0 allows unauthenticated attackers to view the contents of /admin/DBbackup/ directory. Revenue Collection System No fix yet Fix from $2,3002023-01-26 CRITICAL 9.8 CVE-2022-4693 The User Verification WordPress plugin before 1.0.94 was affected by an Auth Bypass security vulnerability. To bypass authentication, we only need to… User Verification 1.0.94+ Fix from $2,3002023-01-23 HIGH 7.5 CVE-2022-38469 An unauthorized user with network access and the decryption key could decrypt sensitive data, such as usernames and passwords. Proficy Historian 2023+ Fix from $1,9502023-01-18 HIGH 7.6 CVE-2022-23538 github.com/sylabs/scs-library-client is the Go client for the Singularity Container Services (SCS) Container Library Service. When the scs-library-cl… Singularity Container Services Library Patch available Fix from $1,9502023-01-17 HIGH 7.5 CVE-2022-41859 In freeradius, the EAP-PWD function compute_password_element() leaks information about the password which allows an attacker to substantially reduce … Freeradius 3.0.0+ Fix from $1,9502023-01-17 HIGH 7.5 CVE-2021-36204 Under some circumstances an Insufficiently Protected Credentials vulnerability in Johnson Controls Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 an… Metasys Application And Data Server 10.1.6 / 11.0.3+ Fix from $1,9502023-01-13 MEDIUM 5.5 CVE-2016-15014 A vulnerability has been found in CESNET theme-cesnet up to 1.x on ownCloud and classified as problematic. Affected by this vulnerability is an unkno… Theme Cesnet 2.0.0+ Fix from $1,6002023-01-07 HIGH 7.5 CVE-2022-2967 Prosys OPC UA Simulation Server version prior to v5.3.0-64 and UA Modbus Server versions 1.4.18-5 and prior do not sufficiently protect credentials, … Ua Modbus Server 1.4.20 / 5.4.0+ Fix from $1,9502023-01-03 MEDIUM 6.5 CVE-2022-22458 IBM Security Verify Governance, Identity Manager 10.0.1 stores user credentials in plain clear text which can be read by a remote authenticated user.… Security Verify Governance Patch available Fix from $1,6002022-12-22 MEDIUM 6.5 CVE-2022-4612 A vulnerability has been found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome and classified as problematic. This vulnerab… Passwordstate 9.5+ Fix from $1,6002022-12-19 MEDIUM 5.7 CVE-2022-46142 Affected devices store the CLI user passwords encrypted in flash memory. Attackers with physical access to the device could retrieve the file and dec… Ruggedcom Rm1224 Lte\(4g\) Eu Firmware Mitigation only Fix from $1,6002022-12-13 MEDIUM 5.5 CVE-2022-4312 A cleartext storage of sensitive information vulnerability exists in PcVue versions 8.10 through 15.2.3. This could allow an unauthorized user with a… Pcvue after 15.2.3 Fix from $1,6002022-12-12 MEDIUM 5.5 CVE-2022-29839 Insufficiently Protected Credentials vulnerability in the remote backups application on Western Digital My Cloud devices that could allow an attacker… My Cloud Os 5.25.124+ Fix from $1,6002022-12-09 HIGH 7.5 CVE-2022-37783 All Craft CMS versions between 3.0.0 and 3.7.32 disclose password hashes of users who authenticate using their E-Mail address or username in Anti-CSR… Craft Cms after 3.7.32 Fix from $1,9502022-12-05 MEDIUM 6.4 CVE-2022-46155 Airtable.js is the JavaScript client for Airtable. Prior to version 0.11.6, Airtable.js had a misconfigured build script in its source package. When … Airtable 0.11.6+ Fix from $1,6002022-11-29 MEDIUM 5.5 CVE-2022-41732 IBM Maximo Mobile 8.7 and 8.8 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 237407. Maximo Application Suite Mitigation only Fix from $1,6002022-11-28 MEDIUM 6.5 CVE-2022-29833 Insufficiently Protected Credentials vulnerability in Mitsubishi Electric Corporation GX Works3 versions 1.015R and later allows a remote unauthentic… Gx Works3 after 1.086q Fix from $1,6002022-11-25 MEDIUM 6.5 CVE-2022-41933 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When the `reset a forgotten password` featur… Xwiki 13.10.8 / 14.4.3+ Fix from $1,6002022-11-23 MEDIUM 6.5 CVE-2022-45392 Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier stores passwords unencrypted in job config.xml files on the Jenkins cont… Ns Nd Integration Performance Publisher 4.8.0.146+ Fix from $1,6002022-11-15 MEDIUM 6.5 CVE-2022-45384 Jenkins Reverse Proxy Auth Plugin 1.7.3 and earlier stores the LDAP manager password unencrypted in the global config.xml file on the Jenkins control… Reverse Proxy Auth 1.7.4+ Fix from $1,6002022-11-15 CRITICAL 9.8 CVE-2022-37109EPSS 49% patrickfuller camp up to and including commit bbd53a256ed70e79bd8758080936afbf6d738767 is vulnerable to Incorrect Access Control. Access to the passw… Camp 2022-07-21+ Fix from $2,3002022-11-14 HIGH 8.8 CVE-2022-26341 Insufficiently protected credentials in software in Intel(R) AMT SDK before version 16.0.4.1, Intel(R) EMA before version 1.7.1 and Intel(R) MC befor… Active Management Technology Software Development Kit 1.7.1 / 2.3.2+ Fix from $1,9502022-11-11 MEDIUM 6.5 CVE-2022-38121 UPSMON PRO configuration file stores user password in plaintext under public user directory. A remote attacker with general user privilege can access… Upsmon Pro Mitigation only Fix from $1,6002022-11-10 MEDIUM 6.1 CVE-2022-36077 The Electron framework enables writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions prior to 21.0.0-beta.1, 20.0.1… Electron 18.3.7 / 19.0.11+ Fix from $1,6002022-11-08 MEDIUM 6.5 CVE-2022-3781 Dashlane password and Keepass Server password in My Account Settings  are not encrypted in the database in Devolutions Remote Desktop Manager 2022.2.… Devolutions Server 2022.2.27 / 2022.3.2+ Fix from $1,6002022-11-01 MEDIUM 5.5 CVE-2022-3644 The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the… Ansible Automation Platform No fix yet Fix from $1,6002022-10-25 HIGH 7.5 CVE-2022-41575 A credential-exposure vulnerability in the support-bundle mechanism in Gradle Enterprise 2022.3 through 2022.3.3 allows remote attackers to access a … Enterprise 2022.3.3+ Fix from $1,9502022-10-21