Vulnerability index

Browse CVEs

1,246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
MEDIUM 6.5 CVE-2022-43419 Jenkins Katalon Plugin 1.0.32 and earlier stores API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by u… Katalon 1.0.33+ Fix from $1,6002022-10-19 HIGH 7.8 CVE-2022-22251 On cSRX Series devices software permission issues in the container filesystem and stored files combined with storing passwords in a recoverable forma… Junos 21.2+ Fix from $1,9502022-10-18 MEDIUM 6.5 CVE-2022-28291 Insufficiently Protected Credentials: An authenticated user with debug privileges can retrieve stored Nessus policy credentials from the “nessusd” pr… Nessus No fix yet Fix from $1,6002022-10-17 HIGH 7.5 CVE-2019-14840 A flaw was found in the RHDM, where sensitive HTML form fields like Password has auto-complete enabled which may lead to leak of credentials. Decision Manager No fix yet Fix from $1,9502022-10-17 MEDIUM 5.9 CVE-2022-3206 The Passster WordPress plugin before 3.5.5.5.2 stores the password inside a cookie named "passster" using base64 encoding method which is easy to dec… Passster 3.5.5.5.2+ Fix from $1,6002022-10-17 HIGH 7.5 CVE-2022-31130 Grafana is an open source observability and data visualization platform. Versions of Grafana for endpoints prior to 9.1.8 and 8.5.14 could leak authe… Grafana 8.5.14 / 9.1.8+ Fix from $1,9502022-10-13 HIGH 7.8 CVE-2022-38465 A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl.… Simatic Et 200 Sp Open Controller Cpu 1515sp Pc2 Firmware 2.9.2 / 4.5.0+ Fix from $1,9502022-10-11 HIGH 7.5 CVE-2022-39168 IBM Robotic Process Automation Clients are vulnerable to proxy credentials being exposed in upgrade logs. IBM X-Force ID: 235422. Robotic Process Automation Patch available Fix from $1,9502022-09-29 HIGH 7.5 CVE-2020-15341 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated update_all_realm_license API. Cloudcnm Secumanager No fix yet Fix from $1,9502022-09-29 CRITICAL 9.8 CVE-2020-15347 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the q6xV4aW8bQ4cfD-b password for the axiros account. Cloudcnm Secumanager No fix yet Fix from $2,3002022-09-29 HIGH 7.4 CVE-2022-37193 Chipolo ONE Bluetooth tracker (2020) Chipolo iOS app version 4.13.0 is vulnerable to Incorrect Access Control. Chipolo devices suffer from access rev… Chipolo Mitigation only Fix from $1,9502022-09-27 MEDIUM 6.5 CVE-2022-41255 Jenkins CONS3RT Plugin 1.0.0 and earlier stores Cons3rt API token unencrypted in job config.xml files on the Jenkins controller where it can be viewe… Cons3rt after 1.0.0 Fix from $1,6002022-09-21 MEDIUM 6.5 CVE-2022-39816 In NOKIA 1350 OMS R14.2, Insufficiently Protected Credentials (cleartext administrator password) occur in the edit configuration page. Exploitation r… 1350 Optical Management System Mitigation only Fix from $1,6002022-09-13 CRITICAL 9.9 CVE-2021-36783 A Insufficiently Protected Credentials vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Members, Project Owners and Project… Rancher 2.5.13 / 2.6.4+ Fix from $2,3002022-09-07 CRITICAL 9.8 CVE-2022-34371 Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.3, contain an unprotected transport of credentials v… Emc Powerscale Onefs after 9.4.0.3 Fix from $2,3002022-09-02 MEDIUM 5.5 CVE-2021-39045 IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a local attacker to obtain information due to the autocomplete feature on password input … Cognos Analytics 11.1.7 / 11.2.3+ Fix from $1,6002022-09-01 MEDIUM 6.5 CVE-2022-27560 HCL VersionVault Express exposes administrator credentials. Versionvault Express Mitigation only Fix from $1,6002022-08-30 HIGH 7.8 CVE-2021-20260 A flaw was found in the Foreman project. The Datacenter plugin exposes the password through the API to an authenticated local attacker with view_host… Foreman Mitigation only Fix from $1,9502022-08-26 MEDIUM 5.9 CVE-2021-43767 Odyssey passes to client unencrypted bytes from man-in-the-middle When Odyssey storage is configured to use the PostgreSQL server using 'trust' authe… PostgreSQL 9.6.24 / 10.19+ Fix from $1,6002022-08-25 MEDIUM 6.1 CVE-2022-34837 Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who successfully exploit the vulnerability may add more … Zenon after 8.20 Fix from $1,6002022-08-24 HIGH 8.4 CVE-2022-34838 Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who successfully exploit the vulnerability may add or al… Zenon after 8.20 Fix from $1,9502022-08-24 MEDIUM 6.5 CVE-2022-38663 Jenkins Git Plugin 4.11.4 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log provided by the Git Username… Git after 4.11.4 Fix from $1,6002022-08-23 MEDIUM 6.5 CVE-2022-38665 Jenkins CollabNet Plugins Plugin 2.0.8 and earlier stores a RabbitMQ password unencrypted in its global configuration file on the Jenkins controller … Collabnet after 2.0.8 Fix from $1,6002022-08-23 MEDIUM 6.5 CVE-2020-35992 Fiserv Prologue through 2020-12-16 does not properly protect the database password. If an attacker were to gain access to the configuration file (spe… Prologue after 2020-12-16 Fix from $1,6002022-08-23 HIGH 7.5 CVE-2021-3513 A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. This is due to a wrong error … Keycloak 13.0.0+ Fix from $1,9502022-08-22 CRITICAL 9.8 CVE-2022-30601 Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow an unauthenticated user to potentially enable inf… Standard Manageability Mitigation only Fix from $2,3002022-08-18 MEDIUM 5.5 CVE-2022-30944 Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow a privileged user to potentially enable informati… Standard Manageability Mitigation only Fix from $1,6002022-08-18 HIGH 7.8 CVE-2022-26844 Insufficiently protected credentials in the installation binaries for Intel(R) SEAPI in all versions may allow an authenticated user to potentially e… Single Event Api Mitigation only Fix from $1,9502022-08-18 MEDIUM 5.5 CVE-2022-29507 Insufficiently protected credentials in the Intel(R) Team Blue mobile application in all versions may allow an authenticated user to potentially enab… Team Blue Mitigation only Fix from $1,6002022-08-18 HIGH 7.5 CVE-2022-30296 Insufficiently protected credentials in the Intel(R) Datacenter Group Event iOS application, all versions, may allow an unauthenticated user to poten… Datacenter Group Event Mitigation only Fix from $1,9502022-08-18