Vulnerability index

Browse CVEs

1,246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
HIGH 7.5 CVE-2022-0738 An issue has been discovered in GitLab affecting all versions starting from 14.6 before 14.6.5, all versions starting from 14.7 before 14.7.4, all ve… GitLab 14.6.5 / 14.7.4+ Fix from $1,9502022-03-28 MEDIUM 6.7 CVE-2022-0859 McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a local attacker to point an ePO server to an arbitrary SQL server during… Epolicy Orchestrator 5.10.0+ Fix from $1,6002022-03-23 MEDIUM 5.3 CVE-2022-0862 A lack of password change protection vulnerability in a depreciated API of McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allow… Epolicy Orchestrator 5.10.0+ Fix from $1,6002022-03-23 MEDIUM 5.5 CVE-2020-25184 Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x stores the password in plaintext in a file that is in the same directory as the executable f… Epas Gtw Firmware 1.1.0+ Fix from $1,6002022-03-18 MEDIUM 6.5 CVE-2022-27216 Jenkins dbCharts Plugin 0.5.2 and earlier stores JDBC connection passwords unencrypted in its global configuration file on the Jenkins controller whe… Dbcharts after 0.5.2 Fix from $1,6002022-03-15 MEDIUM 6.5 CVE-2022-27217 Jenkins Vmware vRealize CodeStream Plugin 1.2 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they c… Vmware Vrealize Codestream after 1.2 Fix from $1,6002022-03-15 MEDIUM 6.5 CVE-2022-27206 Jenkins GitLab Authentication Plugin 1.13 and earlier stores the GitLab client secret unencrypted in the global config.xml file on the Jenkins contro… Gitlab Authentication after 1.13 Fix from $1,6002022-03-15 MEDIUM 5.9 CVE-2021-23222 A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryp… PostgreSQL 9.6.24 / 10.19+ Fix from $1,6002022-03-02 MEDIUM 5.5 CVE-2022-22908 SangforCSClient.exe in Sangfor VDI Client 5.4.2.1006 allows attackers, when they are able to read process memory, to discover the contents of the Use… Vdi Client No fix yet Fix from $1,6002022-02-26 HIGH 8.6 CVE-2022-24610 Settings/network settings/wireless settings on the Alecto DVC-215IP camera version 63.1.1.173 and below shows the Wi-Fi passphrase hidden, but by edi… Dvc 215ip Firmware 63.1.1.173+ Fix from $1,9502022-02-24 MEDIUM 6.5 CVE-2022-24982 Forms generated by JQueryForm.com before 2022-02-05 allows a remote authenticated attacker to access the cleartext credentials of all other form user… Jqueryform 2022-02-05+ Fix from $1,6002022-02-16 MEDIUM 6.5 CVE-2022-25184 Jenkins Pipeline: Build Step Plugin 2.15 and earlier reveals password parameter default values when generating a pipeline script using the Pipeline S… Pipeline\ after 2.15 Fix from $1,6002022-02-15 HIGH 7.5 CVE-2021-22798 A CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause Sensitive data such as login credentials being exposed when a N… Conext Combox Firmware Mitigation only Fix from $1,9502022-02-11 MEDIUM 5.5 CVE-2022-0019 An insufficiently protected credentials vulnerability exists in the Palo Alto Networks GlobalProtect app on Linux that exposes the hashed credentials… Globalprotect 5.1.10 / 5.3.2+ Fix from $1,6002022-02-10 HIGH 8.8 CVE-2021-40360 A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions), SIMATIC PCS 7 V9.1 (All versions < V9.1 … Simatic Pcs 7 7.4+ Fix from $1,9502022-02-09 MEDIUM 6.5 CVE-2021-44451EPSS 8% Apache Superset up to and including 1.3.2 allowed for registered database connections password leak for authenticated users. This information could b… Superset after 1.3.2 Fix from $1,6002022-02-01 HIGH 7.5 CVE-2022-23223 On Apache ShenYu versions 2.4.0 and 2.4.1, and endpoint existed that disclosed the passwords of all users. Users are recommended to upgrade to versio… Shenyu Patch available Fix from $1,9502022-01-25 MEDIUM 5.5 CVE-2022-22554 Dell EMC System Update, version 1.9.2 and prior, contain an Unprotected Storage of Credentials vulnerability. A local attacker with user privleges co… Emc System Update after 1.9.2.0 Fix from $1,6002022-01-24 CRITICAL 9.8 CVE-2021-23196 The web application on Agilia Link+ version 3.0 implements authentication and session management mechanisms exclusively on the client-side and does n… Agilia Connect Firmware 3.0+ Fix from $2,3002022-01-21 MEDIUM 5.5 CVE-2021-23207 An attacker with physical access to the host can extract the secrets from the registry and create valid JWT tokens for the Fresenius Kabi Vigilant Ma… Agilia Connect 3.0+ Fix from $1,6002022-01-21 MEDIUM 5.5 CVE-2021-32039 Users with appropriate file access may be able to access unencrypted user credentials saved by MongoDB Extension for VS Code in a binary file. These … MongoDB after 0.7.0 Fix from $1,6002022-01-20 MEDIUM 5.5 CVE-2022-20621 Jenkins Metrics Plugin 4.0.2.8 and earlier stores an access key unencrypted in its global configuration file on the Jenkins controller where it can b… Metrics after 4.0.2.8 Fix from $1,6002022-01-12 MEDIUM 6.5 CVE-2022-23109 Jenkins HashiCorp Vault Plugin 3.7.0 and earlier does not mask Vault credentials in Pipeline build logs or in Pipeline step descriptions when Pipelin… Hashicorp Vault after 3.7.0 Fix from $1,6002022-01-12 HIGH 7.5 CVE-2022-23117 Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent processes to retrieve all userna… Conjur Secrets after 1.0.9 Fix from $1,9502022-01-12 CRITICAL 9.8 CVE-2021-37400 An attacker may obtain the user credentials from the communication between the PLC and the software. As a result, the PLC user program may be uploade… Data File Manager after 8.19.1 Fix from $2,3002021-12-28 CRITICAL 9.8 CVE-2021-37401 An attacker may obtain the user credentials from file servers, backup repositories, or ZLD files saved in SD cards. As a result, the PLC user program… Data File Manager after 8.19.1 Fix from $2,3002021-12-28 HIGH 7.6 CVE-2021-20826 Unprotected transport of credentials vulnerability in IDEC PLCs (FC6A Series MICROSmart All-in-One CPU module v2.32 and earlier, FC6A Series MICROSma… Microsmart Fc6a Firmware after 8.19.1 Fix from $1,9502021-12-24 MEDIUM 6.7 CVE-2021-36317 Dell EMC Avamar Server version 19.4 contains a plain-text password storage vulnerability in AvInstaller. A local attacker could potentially exploit t… Emc Avamar Server Patch available Fix from $1,6002021-12-21 MEDIUM 6.7 CVE-2021-36318 Dell EMC Avamar versions 18.2,19.1,19.2,19.3,19.4 contain a plain-text password storage vulnerability. A high privileged user could potentially explo… Emc Avamar Server Patch available Fix from $1,6002021-12-21 HIGH 7.5 CVE-2021-42913 The SyncThru Web Service on Samsung SCX-6x55X printers allows an attacker to gain access to a list of SMB users and cleartext passwords by reading th… Syncthru Web Service Mitigation only Fix from $1,9502021-12-20