Vulnerability index

Browse CVEs

1,246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
HIGH 7.5 CVE-2020-28865 An issue was discovered in PowerJob through 3.2.2, allows attackers to change arbitrary user passwords via the id parameter to /appinfo/save. Powerjob after 3.2.2 Fix from $1,9502022-06-16 HIGH 7.5 CVE-2022-31044 Rundeck is an open source automation service with a web console, command line tools and a WebAPI. The Key Storage converter plugin mechanism was not … Rundeck Mitigation only Fix from $1,9502022-06-15 HIGH 7.5 CVE-2022-30587 Gradle Enterprise through 2022.2.2 has Incorrect Access Control that leads to information disclosure. Gradle Enterprise 2022.2.3+ Fix from $1,9502022-06-06 HIGH 7.5 CVE-2022-22396 Credentials are printed in clear text in the IBM Spectrum Protect Plus 10.1.0.0 through 10.1.9.3 virgo log file in certain cases. Credentials could b… Spectrum Protect Plus 10.1.10+ Fix from $1,9502022-06-06 HIGH 7.8 CVE-2022-22557 PowerStore contains Plain-Text Password Storage Vulnerability in PowerStore X & T environments running versions 2.0.0.x and 2.0.1.x A locally authent… Powerstoreos 2.1.0.0 / 2.1.1.0+ Fix from $1,9502022-06-02 MEDIUM 6.7 CVE-2022-29085 Dell Unity, Dell UnityVSA, and Dell Unity XT versions prior to 5.2.0.0.5.173 contain a plain-text password storage vulnerability when certain off-arr… Unity Operating Environment 5.2.0.0.5.173+ Fix from $1,6002022-06-02 MEDIUM 5.7 CVE-2022-27774 An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extr… Curl after 7.82.0 Fix from $1,6002022-06-02 MEDIUM 6.5 CVE-2022-27776 A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the… Curl 7.83.0+ Fix from $1,6002022-06-02 HIGH 8.8 CVE-2022-22767 Specific BD Pyxis™ products were installed with default credentials and may presently still operate with these credentials. There may be scenarios wh… Pyxis Anesthesia Station Es Firmware Mitigation only Fix from $1,9502022-06-02 HIGH 7.5 CVE-2022-1413 Missing input masking in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versi… GitLab 14.8.6 / 14.9.4+ Fix from $1,9502022-05-19 HIGH 8.8 CVE-2022-30018 Mobotix Control Center (MxCC) through 2.5.4.5 has Insufficiently Protected Credentials, Storing Passwords in a Recoverable Format via the MxCC.ini co… Mxcontrolcenter after 2.5.4.5 Fix from $1,9502022-05-19 MEDIUM 6.5 CVE-2022-30952 Jenkins Pipeline SCM API for Blue Ocean Plugin 1.25.3 and earlier allows attackers with Job/Configure permission to access credentials with attacker-… Blue Ocean after 1.25.3 Fix from $1,6002022-05-17 HIGH 7.5 CVE-2022-29588 Konica Minolta bizhub MFP devices before 2022-04-14 use cleartext password storage for the /var/log/nginx/html/ADMINPASS and /etc/shadow files. Bizhub 226i Firmware 2022-04-14+ Fix from $1,9502022-05-16 CRITICAL 9.8 CVE-2022-28005EPSS 6% An issue was discovered in the 3CX Phone System Management Console prior to version 18 Update 3 FINAL. An unauthenticated attacker could abuse improp… 3cx after 18.0.3.450 Fix from $2,3002022-05-06 HIGH 7.5 CVE-2021-46440 Storing passwords in a recoverable format in the DOCUMENTATION plugin component of Strapi before 3.6.9 and 4.x before 4.1.5 allows an attacker to acc… Strapi 3.6.9 / 4.1.5+ Fix from $1,9502022-05-03 HIGH 7.8 CVE-2022-26856 Dell EMC Repository Manager version 3.4.0 contains a plain-text password storage vulnerability. A local attacker could potentially exploit this vulne… Emc Repository Manager Mitigation only Fix from $1,9502022-04-21 HIGH 7.5 CVE-2022-24867 GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. When you … Glpi 10.0.0+ Fix from $1,9502022-04-21 MEDIUM 6.5 CVE-2022-27179 A malicious actor having access to the exported configuration file may obtain the stored credentials and thereby gain access to the protected resourc… Da50n Firmware Mitigation only Fix from $1,6002022-04-20 HIGH 8.8 CVE-2022-29457EPSS 8% Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure du… Manageengine Adaudit Plus 5.7 / 6.1+ Fix from $1,9502022-04-18 MEDIUM 5.5 CVE-2021-3681 A flaw was found in Ansible Galaxy Collections. When collections are built manually, any files in the repository directory that are not explicitly ex… Ansible Automation Platform Mitigation only Fix from $1,6002022-04-18 MEDIUM 6.7 CVE-2022-22550 Dell PowerScale OneFS, versions 8.2.2 and above, contain a password disclosure vulnerability. An unprivileged local attacker could potentially exploi… Emc Powerscale Onefs after 9.3.0 Fix from $1,6002022-04-12 HIGH 8.8 CVE-2022-24978 Zoho ManageEngine ADAudit Plus before 7055 allows authenticated Privilege Escalation on Integrated products. This occurs because a password field is … Manageengine Adaudit Plus after 6.0 Fix from $1,9502022-04-05 MEDIUM 5.5 CVE-2022-28651 In JetBrains IntelliJ IDEA before 2021.3.3 it was possible to get passwords from protected fields Intellij Idea 2021.3.3+ Fix from $1,6002022-04-05 MEDIUM 5.9 CVE-2021-45892 An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4. There is storage of Passwords in a Recoverable Format. Arc Mitigation only Fix from $1,6002022-04-05 HIGH 7.5 CVE-2021-32978 The programming protocol allows for a previously entered password and lock state to be read by an attacker. If the previously entered password was su… C0 10dd1e D Firmware 3.00+ Fix from $1,9502022-04-04 HIGH 8.6 CVE-2022-1026EPSS 15% Kyocera multifunction printers running vulnerable versions of Net View unintentionally expose sensitive user information, including usernames and pas… Net Viewer after 2s0_1000.005.0012s5_2000.002.505 Fix from $1,9502022-04-04 HIGH 7.5 CVE-2021-33024 Philips Vue PACS versions 12.2.x.x and prior transmits or stores authentication credentials, but it uses an insecure method susceptible to unauthoriz… Myvue 12.2.1.5 / 12.2.8.0+ Fix from $1,9502022-04-01 HIGH 7.5 CVE-2022-26948 The Archer RSS feed integration for Archer 6.x through 6.9 SP1 (6.9.1.0) is affected by an insecure credential storage vulnerability. A malicious att… Archer 6.9.1.1+ Fix from $1,9502022-03-30 MEDIUM 6.5 CVE-2022-28135 Jenkins instant-messaging Plugin 1.41 and earlier stores passwords for group chats unencrypted in the global configuration file of plugins based on J… Instant Messaging 1.42+ Fix from $1,6002022-03-29 MEDIUM 6.5 CVE-2022-28141 Jenkins Proxmox Plugin 0.5.0 and earlier stores the Proxmox Datacenter password unencrypted in the global config.xml file on the Jenkins controller w… Proxmox after 0.5.0 Fix from $1,6002022-03-29