Vulnerability index

Browse CVEs

1,246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
HIGH 7.8 CVE-2021-39373 Samsung Drive Manager 2.0.104 on Samsung H3 devices allows attackers to bypass intended access controls on disk management. WideCharToMultiByte, Wide… Drive Manager No fix yet Fix from $1,9502021-09-01 MEDIUM 5.5 CVE-2021-21681 Jenkins Nomad Plugin 0.7.4 and earlier stores Docker passwords unencrypted in the global config.xml file on the Jenkins controller where they can be … Nomad after 0.7.4 Fix from $1,6002021-08-31 MEDIUM 5.5 CVE-2021-34560 In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.9 a form contains a password field with autocomplete enabled. The stored credentials can be captured by … Wha Gw F2d2 0 As Z2 Eth Firmware after 3.0.9 Fix from $1,6002021-08-31 HIGH 7.5 CVE-2021-39289 Certain NetModule devices have Insecure Password Handling (cleartext or reversible encryption), These models with firmware before 4.3.0.113, 4.4.0.11… Netmodule Router Software 4.3.0.113 / 4.4.0.111+ Fix from $1,9502021-08-23 HIGH 7.2 CVE-2021-35529 Insufficiently Protected Credentials vulnerability in client environment of Hitachi ABB Power Grids Retail Operations and Counterparty Settlement Bil… Counterparty Settlement And Billing 5.7.3+ Fix from $1,9502021-08-20 MEDIUM 5.3 CVE-2021-38165 Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may ap… Debian Linux after 2.8.9 Fix from $1,6002021-08-07 CRITICAL 9.1 CVE-2021-20597 Insufficiently Protected Credentials vulnerability in Mitsubishi Electric MELSEC iQ-R series Safety CPU modules R08/16/32/120SFCPU firmware versions … R08sfcpu Firmware Mitigation only Fix from $2,3002021-08-06 MEDIUM 5.5 CVE-2021-32003 Unprotected Transport of Credentials vulnerability in SiteManager provisioning service allows local attacker to capture credentials if the service is… Sitemanager Firmware 9.5.621256022+ Fix from $1,6002021-08-05 MEDIUM 5.3 CVE-2021-22923 When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink XML file, those sam… Curl 1.0.1.1 / 7.78.0+ Fix from $1,6002021-08-05 HIGH 7.5 CVE-2021-27491 Ypsomed mylife Cloud, mylife Mobile Application:Ypsomed mylife Cloud,All versions prior to 1.7.2,Ypsomed mylife App,All versions prior to 1.7.5,The Y… Mylife 1.7.2 / 1.7.5+ Fix from $1,9502021-07-30 HIGH 7.1 CVE-2021-27495 Ypsomed mylife Cloud, mylife Mobile Application:Ypsomed mylife Cloud,All versions prior to 1.7.2,Ypsomed mylife App,All versions prior to 1.7.5,he Yp… Mylife 1.7.2 / 1.7.5+ Fix from $1,9502021-07-30 MEDIUM 5.5 CVE-2021-34700 A vulnerability in the CLI interface of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to read arbitrary files on the und… Catalyst Sd Wan Manager 20.4.2 / 20.5.1+ Fix from $1,6002021-07-22 HIGH 8.8 CVE-2020-5315 Dell EMC Repository Manager (DRM) version 3.2 contains a plain-text password storage vulnerability. Proxy server user password is stored in a plain t… Emc Repository Manager after 3.2 Fix from $1,9502021-07-19 CRITICAL 9.8 CVE-2021-35965 The Orca HCM digital learning platform uses a weak factory default administrator password, which is hard-coded in the source code of the webpage in p… Orca Hcm after 10.0 Fix from $2,3002021-07-19 HIGH 7.5 CVE-2021-32770 Gatsby is a framework for building websites. The gatsby-source-wordpress plugin prior to versions 4.0.8 and 5.9.2 leaks .htaccess HTTP Basic Authenti… Gatsby Source Wordpress 4.0.8 / 5.9.2+ Fix from $1,9502021-07-15 HIGH 7.5 CVE-2021-20439 IBM Security Access Manager 9.0 and IBM Security Verify Access Docker 10.0.0 stores user credentials in plain clear text which can be read by an unau… Security Access Manager Patch available Fix from $1,9502021-07-15 HIGH 7.1 CVE-2021-22778 Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of U… Ecostruxure Control Expert 15.0+ Fix from $1,9502021-07-14 HIGH 7.1 CVE-2021-22780 Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of U… Ecostruxure Control Expert 15.0+ Fix from $1,9502021-07-14 MEDIUM 5.5 CVE-2021-22781 Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of U… Ecostruxure Control Expert 15.0+ Fix from $1,6002021-07-14 HIGH 7.5 CVE-2021-35527 Password autocomplete vulnerability in the web application password field of Hitachi ABB Power Grids eSOMS allows attacker to gain access to user cre… Esoms 6.3.1+ Fix from $1,9502021-07-14 MEDIUM 6.7 CVE-2021-21590 Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerability. A local malicious user wi… Emc Unity Operating Environment 5.1.0.0.5.394+ Fix from $1,6002021-07-12 MEDIUM 6.7 CVE-2021-21591 Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerability. A local malicious user wi… Emc Unity Operating Environment 5.1.0.0.5.394+ Fix from $1,6002021-07-12 CRITICAL 9.8 CVE-2021-30116 KEVEPSS 86% Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page … Vsa Agent 9.5.0.24 / 9.5.7a+ Fix from $2,3002021-07-09 MEDIUM 5.9 CVE-2021-34075 In Artica Pandora FMS <=754 in the File Manager component, there is sensitive information exposed on the client side which attackers can access. Pandora Fms after 754 Fix from $1,6002021-06-30 HIGH 7.5 CVE-2021-35050 User credentials stored in a recoverable format within Fidelis Network and Deception CommandPost. In the event that an attacker gains access to the C… Deception 9.3.3+ Fix from $1,9502021-06-25 MEDIUM 6.8 CVE-2021-34204 D-Link DIR-2640-US 1.01B04 is affected by Insufficiently Protected Credentials. D-Link AC2600(DIR-2640) stores the device system account password in … Dir 2640 Us Firmware No fix yet Fix from $1,6002021-06-16 HIGH 7.5 CVE-2021-28857 TP-Link's TL-WPA4220 4.0.2 Build 20180308 Rel.37064 username and password are sent via the cookie. Tl Wpa4220 Firmware No fix yet Fix from $1,9502021-06-15 HIGH 7.5 CVE-2020-15381 Brocade SANnav before version 2.1.1 contains an Improper Authentication vulnerability that allows cleartext transmission of authentication credential… Sannav 2.1.1+ Fix from $1,9502021-06-09 HIGH 7.5 CVE-2020-26515 An insufficiently protected credentials issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The remember-me cookie (CB_LOGIN) issue… Codebeamer 10.1.0+ Fix from $1,9502021-06-08 HIGH 7.5 CVE-2020-29321 The D-Link router DIR-868L 3.01 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthent… Dir 868l Firmware No fix yet Fix from $1,9502021-06-04