Vulnerability index

Browse CVEs

1,246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
MEDIUM 5.5 CVE-2022-29959 Emerson OpenBSI through 2022-04-29 mishandles credential storage. It is an engineering environment for the ControlWave and Bristol Babcock line of RT… Openbsi 5.9+ Fix from $1,6002022-08-16 MEDIUM 6.8 CVE-2022-36307 The AirVelocity 1500 prints SNMP credentials on its physically accessible serial port during boot. This was fixed in AirVelocity 1500 software versio… Airvelocity 1500 Firmware after 15.18.00.2511 Fix from $1,6002022-08-16 CRITICAL 9.1 CVE-2022-36308 Airspan AirVelocity 1500 web management UI displays SNMP credentials in plaintext on software versions older than 15.18.00.2511, and stores SNMPv3 cr… Airvelocity 1500 Firmware after 15.18.00.2511 Fix from $2,3002022-08-16 MEDIUM 5.9 CVE-2022-22983 VMware Workstation (16.x prior to 16.2.4) contains an unprotected storage of credentials vulnerability. A malicious actor with local user privileges … Workstation 16.2.4+ Fix from $1,6002022-08-10 MEDIUM 6.5 CVE-2022-33169 IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to insufficiently protected credentials for users created via a bulk upload. … Robotic Process Automation after 21.0.3 Fix from $1,6002022-08-01 MEDIUM 5.0 CVE-2021-27785 HCL Commerce's Remote Store server could allow a local attacker to obtain sensitive personal information. The vulnerability requires the victim to fi… Hcl Commerce after 9.1.10 Fix from $1,6002022-07-30 CRITICAL 9.8 CVE-2021-22640 An attacker can decrypt the Ovarro TBox login password by communication capture and brute force attacks. Twinsoft 1.46 / 12.4+ Fix from $2,3002022-07-28 MEDIUM 6.5 CVE-2022-36901 Jenkins HTTP Request Plugin 1.15 and earlier stores HTTP Request passwords unencrypted in its global configuration file on the Jenkins controller whe… Http Request after 1.15 Fix from $1,6002022-07-27 HIGH 7.5 CVE-2022-1766 Anchore Enterprise anchorectl version 0.1.4 improperly stored credentials when generating a Software Bill of Materials. anchorectl will add the crede… Anchore 0.1.5 / 4.0.1+ Fix from $1,9502022-07-20 MEDIUM 6.5 CVE-2022-27544 BigFix Web Reports authorized users may see SMTP credentials in clear text. Bigfix Platform after 10.0.6 Fix from $1,6002022-07-19 HIGH 7.5 CVE-2022-22998 Implemented protections on AWS credentials that were not properly protected. My Cloud Home Duo Firmware 8.5.1-102+ Fix from $1,9502022-07-12 MEDIUM 5.5 CVE-2022-1794 The CODESYS OPC DA Server prior V3.5.18.20 stores PLC passwords as plain text in its configuration file so that it is visible to all authorized Micro… Opc Da Server 3.5.18.20+ Fix from $1,6002022-07-11 CRITICAL 9.8 CVE-2022-35411EPSS 46% rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header is sent. In other words, altho… Rpc.py after 0.6.0 Fix from $2,3002022-07-08 MEDIUM 5.5 CVE-2022-27548 HCL Launch stores user credentials in plain clear text which can be read by a local user. Hcl Launch Mitigation only Fix from $1,6002022-07-06 MEDIUM 5.5 CVE-2022-23725 PingID Windows Login prior to 2.8 does not properly set permissions on the Windows Registry entries used to store sensitive API keys under some circu… Pingid Integration For Windows Login 2.8+ Fix from $1,6002022-06-30 MEDIUM 6.5 CVE-2022-34816 Jenkins HPE Network Virtualization Plugin 1.0 stores passwords unencrypted in its global configuration file on the Jenkins controller where they can … Hpe Network Virtualization Mitigation only Fix from $1,6002022-06-30 MEDIUM 6.5 CVE-2022-34805 Jenkins Skype notifier Plugin 1.1.0 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can… Skype Notifier after 1.1.0 Fix from $1,6002022-06-30 MEDIUM 6.5 CVE-2022-34806 Jenkins Jigomerge Plugin 0.9 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by u… Jigomerge after 0.9 Fix from $1,6002022-06-30 MEDIUM 6.5 CVE-2022-34807 Jenkins Elasticsearch Query Plugin 1.2 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it … Elasticsearch Query after 1.2 Fix from $1,6002022-06-30 MEDIUM 6.5 CVE-2022-34809 Jenkins RQM Plugin 2.8 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by… Rqm after 2.8 Fix from $1,6002022-06-30 CRITICAL 9.8 CVE-2022-31887 Marval MSM v14.19.0.12476 has a 0-Click Account Takeover vulnerability which allows an attacker to change any user's password in the organization, th… Marval Msm No fix yet Fix from $2,3002022-06-28 MEDIUM 6.1 CVE-2022-31085 LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior t… Debian Linux 8.0+ Fix from $1,6002022-06-27 MEDIUM 6.5 CVE-2022-2221 Information Exposure vulnerability in My Account Settings of Devolutions Remote Desktop Manager before 2022.1.8 allows authenticated users to access … Remote Desktop Manager 2022.1.8+ Fix from $1,6002022-06-27 MEDIUM 6.5 CVE-2022-28167 Brocade SANnav before Brocade SANvav v. 2.2.0.2 and Brocade SANanv v.2.1.1.8 logs the Brocade Fabric OS switch password in plain text in asyncjobsche… Sannav 2.1.1.8 / 2.2.0.2+ Fix from $1,6002022-06-27 CRITICAL 9.1 CVE-2022-2103 An attacker with weak credentials could access the TCP port via an open FTP port, allowing an attacker to read sensitive files and write to remotely … Sepcos Control And Protection Relay Firmware 1.23.21 / 1.24.8+ Fix from $2,3002022-06-24 MEDIUM 6.5 CVE-2022-1666 The default password for the web application’s root user (the vendor’s private account) was weak and the MD5 hash was used to crack the password usin… Sepcos Control And Protection Relay Firmware 1.23.21 / 1.24.8+ Fix from $1,6002022-06-24 MEDIUM 6.5 CVE-2022-34213 Jenkins Squash TM Publisher (Squash4Jenkins) Plugin 1.0.0 and earlier stores passwords unencrypted in its global configuration file on the Jenkins co… Squash Tm Publisher after 1.0.0 Fix from $1,6002022-06-23 MEDIUM 6.5 CVE-2022-34199 Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they c… Convertigo Mobile Platform after 1.1 Fix from $1,6002022-06-23 MEDIUM 6.5 CVE-2022-34202 Jenkins EasyQA Plugin 1.0 and earlier stores user passwords unencrypted in its global configuration file on the Jenkins controller where they can be … Easyqa after 1.0 Fix from $1,6002022-06-23 MEDIUM 5.9 CVE-2022-21184 An information disclosure vulnerability exists in the License registration functionality of Bachmann Visutec GmbH Atvise 3.5.4, 3.6 and 3.7. A plaint… Atvise Mitigation only Fix from $1,6002022-06-17