Vulnerability index

Browse CVEs

1,246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
MEDIUM 5.5 CVE-2021-3179 GGLocker iOS application, contains an insecure data storage of the password hash value which results in an authentication bypass. Gglocker Mitigation only Fix from $1,6002021-12-16 MEDIUM 5.5 CVE-2021-45097 KNIME Server before 4.12.6 and 4.13.x before 4.13.4 (when installed in unattended mode) keeps the administrator's password in a file without appropri… Knime Server 4.13.4+ Fix from $1,6002021-12-16 MEDIUM 6.5 CVE-2021-42023 A vulnerability has been identified in ModelSim Simulation (All versions), Questa Simulation (All versions). The RSA white-box implementation in affe… Modelsim Patch available Fix from $1,6002021-12-14 HIGH 8.8 CVE-2021-40857 Auerswald COMpact 5500R devices before 8.2B allow Privilege Escalation via the passwd=1 substring. Compact 5500r Ip Firmware after 8.0b Fix from $1,9502021-12-13 MEDIUM 6.5 CVE-2021-37187 An issue was discovered on Digi TransPort devices through 2021-07-21. An authenticated attacker may read a password file (with reversible passwords) … Transport Dr64 Firmware after 8.3.1.2 Fix from $1,6002021-12-10 CRITICAL 9.8 CVE-2021-20146 An unprotected ssh private key exists on the Gryphon devices which could be used to achieve root access to a server affiliated with Gryphon's develop… Gryphon Tower Firmware after 04.0004.12 Fix from $2,3002021-12-09 HIGH 8.1 CVE-2021-43978 Allegro WIndows 3.3.4152.0, embeds software administrator database credentials into its binary files, which allows users to access and modify data us… Allegro Patch available Fix from $1,9502021-12-08 HIGH 8.1 CVE-2021-42306 An information disclosure vulnerability manifests when a user or an application uploads unprotected private key data as part of an authentication cer… Azure Active Directory 2021-10-15 / 2021-10-30+ Fix from $1,9502021-11-24 MEDIUM 5.5 CVE-2021-38976 IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 stores user credentials in plain clear text which can be read by a local user. X-Force ID: … Security Guardium Key Lifecycle Manager after 4.0.0.3 Fix from $1,6002021-11-15 MEDIUM 6.5 CVE-2021-43332 In GNU Mailman before 2.1.36, the CSRF token for the Cgi/admindb.py admindb page contains an encrypted version of the list admin password. This could… Debian Linux 2.1.36+ Fix from $1,6002021-11-12 MEDIUM 6.5 CVE-2021-41972 Apache Superset up to and including 1.3.1 allowed for database connections password leak for authenticated users. This information could be accessed … Superset after 1.3.1 Fix from $1,6002021-11-12 HIGH 8.8 CVE-2021-43397 LiquidFiles before 3.6.3 allows remote attackers to elevate their privileges from Admin (or User Admin) to Sysadmin. Liquidfiles 3.6.3+ Fix from $1,9502021-11-11 HIGH 7.8 CVE-2021-40503 An information disclosure vulnerability exists in SAP GUI for Windows - versions < 7.60 PL13, 7.70 PL4, which allows an attacker with sufficient priv… Gui For Windows 7.60+ Fix from $1,9502021-11-10 MEDIUM 5.5 CVE-2021-41023 A unprotected storage of credentials in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows an authenticated user to disclosure agent pas… Fortisiem after 4.1.4 Fix from $1,6002021-11-02 MEDIUM 5.9 CVE-2020-23036 MEDIA NAVI Inc SMACom v1.2 was discovered to contain an insecure session validation vulnerability in the session handling of the `password` authentic… Smacom No fix yet Fix from $1,6002021-10-22 MEDIUM 6.5 CVE-2021-28496 On systems running Arista EOS and CloudEOS with the affected release version, when using shared secret profiles the password configured for use by Bi… Eos 4.23.10 / 4.24.8+ Fix from $1,6002021-10-21 HIGH 7.5 CVE-2021-40476 Windows AppContainer Elevation Of Privilege Vulnerability Windows 10 Patch available Fix from $1,9502021-10-13 MEDIUM 6.5 CVE-2021-41125 Scrapy is a high-level web crawling and scraping framework for Python. If you use `HttpAuthMiddleware` (i.e. the `http_user` and `http_pass` spider a… Debian Linux 1.8.1 / 2.5.1+ Fix from $1,6002021-10-06 MEDIUM 6.5 CVE-2021-36178 A insufficiently protected credentials in Fortinet FortiSDNConnector version 1.1.7 and below allows attacker to disclose third-party devices credenti… Fortisdnconnector 1.1.8+ Fix from $1,6002021-10-06 HIGH 7.5 CVE-2021-41092 Docker CLI is the command line interface for the docker container runtime. A bug was found in the Docker CLI where running `docker login my-private-r… Command Line Interface 20.10.9+ Fix from $1,9502021-10-04 MEDIUM 6.5 CVE-2021-36309 Dell Enterprise SONiC OS, versions 3.3.0 and earlier, contains a sensitive information disclosure vulnerability. An authenticated malicious user with… Enterprise Sonic Os after 3.3.0 Fix from $1,6002021-10-01 HIGH 8.8 CVE-2021-41297 ECOA BAS controller is vulnerable to weak access control mechanism allowing authenticated user to remotely escalate privileges by disclosing credenti… Ecs Router Controller Ecs Firmware Mitigation only Fix from $1,9502021-09-30 CRITICAL 9.8 CVE-2021-41300 ECOA BAS controller’s special page displays user account and passwords in plain text, thus unauthenticated attackers can access the page and obtain p… Ecs Router Controller Ecs Firmware Mitigation only Fix from $2,3002021-09-30 HIGH 7.5 CVE-2021-39342 The Credova_Financial WordPress plugin discloses a site's associated Credova API account username and password in plaintext via an AJAX action whenev… Financial 1.4.9+ Fix from $1,9502021-09-29 MEDIUM 5.5 CVE-2021-38863 IBM Security Verify Bridge 1.0.5.0 stores user credentials in plain clear text which can be read by a locally authenticated user. IBM X-Force ID: 208… Security Verify Bridge 1.0.7+ Fix from $1,6002021-09-23 MEDIUM 6.5 CVE-2021-1589 A vulnerability in the disaster recovery feature of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain unauthorized … Sd Wan 20.3.4 / 20.4.2+ Fix from $1,6002021-09-23 HIGH 7.5 CVE-2021-28813 A vulnerability involving insecure storage of sensitive information has been reported to affect QSW-M2116P-2T2S and QNAP switches running QuNetSwitch… Qsw M2116p 2t2s Firmware 1.0.6 / 1.0.6.1509+ Fix from $1,9502021-09-10 HIGH 7.8 CVE-2021-28498 In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, user enable passwords set in clear text could resul… Metamako Operating System 0.26.7 / 0.32.0+ Fix from $1,9502021-09-09 MEDIUM 5.5 CVE-2021-28499 In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, user account passwords set in clear text could leak… Metamako Operating System 0.32.0+ Fix from $1,6002021-09-09 MEDIUM 5.5 CVE-2021-34733 A vulnerability in the CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, local att… Evolved Programmable Network Manager 3.8 / 5.0+ Fix from $1,6002021-09-02