Vulnerability index

Browse CVEs

1,246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
HIGH 7.5 CVE-2020-29322 The D-Link router DIR-880L 1.07 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthent… Dir 880l Firmware No fix yet Fix from $1,9502021-06-04 HIGH 7.5 CVE-2020-29323 The D-link router DIR-885L-MFC 1.15b02, v1.21b05 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that al… Dir 885l Mfc Firmware No fix yet Fix from $1,9502021-06-04 MEDIUM 5.5 CVE-2021-1537 A vulnerability in the installer software of Cisco ThousandEyes Recorder could allow an unauthenticated, local attacker to access sensitive informati… Thousandeyes Recorder 1.0.5+ Fix from $1,6002021-06-04 HIGH 7.5 CVE-2019-4723 IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete settings in N… Cognos Analytics Patch available Fix from $1,9502021-06-01 HIGH 7.5 CVE-2019-4724 IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete settings in N… Cognos Analytics Patch available Fix from $1,9502021-06-01 HIGH 7.8 CVE-2021-23019 The NGINX Controller 2.0.0 thru 2.9.0 and 3.x before 3.15.0 Administrator password may be exposed in the systemd.txt file that is included in the NGI… Nginx Controller 3.15.0+ Fix from $1,9502021-06-01 MEDIUM 5.4 CVE-2020-27839 A flaw was found in ceph-dashboard. The JSON Web Token (JWT) used for user authentication is stored by the frontend application in the browser’s loca… Ceph 14.2.17 / 15.2.9+ Fix from $1,6002021-05-26 MEDIUM 5.5 CVE-2019-25030 In Versa Director, Versa Analytics and VOS, Passwords are not hashed using an adaptive cryptographic hash function or key derivation function prior t… Versa Analytics Mitigation only Fix from $1,6002021-05-26 MEDIUM 5.5 CVE-2021-29253 The Tableau integration in RSA Archer 6.4 P1 (6.4.0.1) through 6.9 P2 (6.9.0.2) is affected by an insecure credential storage vulnerability. An malic… Archer 6.6.0.8 / 6.7.0.8+ Fix from $1,6002021-05-26 HIGH 7.8 CVE-2021-20389 IBM Security Guardium 11.2 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 195770. Security Guardium Patch available Fix from $1,9502021-05-24 CRITICAL 9.8 CVE-2020-12061 An issue was discovered in Nitrokey FIDO U2F firmware through 1.1. Communication between the microcontroller and the secure element transmits credent… Fido U2f Firmware after 1.1 Fix from $2,3002021-05-21 HIGH 7.5 CVE-2020-24396 homee Brain Cube v2 (2.28.2 and 2.28.4) devices have sensitive SSH keys within downloadable and unencrypted firmware images. This allows remote attac… Brain Cube Core Mitigation only Fix from $1,9502021-05-20 MEDIUM 5.9 CVE-2021-29043 The Portal Store module in Liferay Portal 7.0.0 through 7.3.5, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 21, 7.2 before fix pack 10… Digital Experience Platform after 7.3.5 Fix from $1,6002021-05-17 HIGH 8.8 CVE-2021-3528 A flaw was found in noobaa-operator in versions before 5.7.0, where internal RPC AuthTokens between the noobaa operator and the noobaa core are leake… Noobaa Operator 5.7.0+ Fix from $1,9502021-05-13 HIGH 7.5 CVE-2021-20997 In multiple managed switches by WAGO in different versions it is possible to read out the password hashes of all Web-based Management users. 0852 0303 Firmware after 1.2.3.s0 Fix from $1,9502021-05-13 CRITICAL 9.8 CVE-2020-21994 AVE DOMINAplus <=1.10.x suffers from clear-text credentials disclosure vulnerability that allows an unauthenticated attacker to issue a request to an… Dominaplus after 1.10.77 Fix from $2,3002021-04-28 CRITICAL 9.8 CVE-2021-30167 The manage users profile services of the network camera device allows an authenticated. Remote attackers can modify URL parameters and further amend … P2r8852e2 Firmware 7.1.94.8908+ Fix from $2,3002021-04-28 CRITICAL 9.8 CVE-2021-30168 The sensitive information of webcam device is not properly protected. Remote attackers can unauthentically grant administrator’s credential and furth… P2r8852e2 Firmware 7.1.94.8908+ Fix from $2,3002021-04-28 HIGH 7.5 CVE-2021-30169 The sensitive information of webcam device is not properly protected. Remote attackers can unauthentically grant user’s credential. P2r8852e2 Firmware 7.1.94.8908+ Fix from $1,9502021-04-28 HIGH 7.5 CVE-2021-29262EPSS 8% When starting Apache Solr versions prior to 8.8.2, configured with the SaslZkACLProvider or VMParamsAllAndReadonlyDigestZkACLProvider and no existing… Solr 8.8.2+ Fix from $1,9502021-04-13 MEDIUM 6.5 CVE-2020-15942 An information disclosure vulnerability in Web Vulnerability Scan profile of Fortinet's FortiWeb version 6.2.x below 6.2.4 and version 6.3.x below 6.… Fortiweb after 6.3.4 Fix from $1,6002021-04-12 MEDIUM 6.5 CVE-2021-22115 Cloud Controller API versions prior to 1.106.0 logs service broker credentials if the default value of db logging config field is changed. CAPI datab… Capi Release 1.106.0 / 16.2.0+ Fix from $1,6002021-04-08 CRITICAL 9.8 CVE-2021-28171 The Vangene deltaFlow E-platform does not take properly protective measures. Attackers can obtain privileged permissions remotely by tampering with u… Deltaflow 7.7+ Fix from $2,3002021-04-06 HIGH 8.8 CVE-2020-11925 An issue was discovered in Luvion Grand Elite 3 Connect through 2020-02-25. Authentication to the device is based on a username and password. The roo… Grand Elite 3 Connect Firmware after 2020-02-25 Fix from $1,9502021-04-02 MEDIUM 6.5 CVE-2021-21634 Jenkins Jabber (XMPP) notifier and control Plugin 1.41 and earlier stores passwords unencrypted in its global configuration file on the Jenkins contr… Jabber \(xmpp\) Notifier And Control after 1.41 Fix from $1,6002021-03-30 HIGH 7.5 CVE-2021-29255 MicroSeven MYM71080i-B 2.0.5 through 2.0.20 devices send admin credentials in cleartext to pnp.microseven.com TCP port 7007. An attacker on the same … Mym71080i B Firmware after 2.0.20 Fix from $1,9502021-03-26 CRITICAL 9.8 CVE-2021-27372 Realtek xPON RTL9601D SDK 1.9 stores passwords in plaintext which may allow attackers to possibly gain access to the device with root permissions via… Xpon Rtl9601d Software Development Kit Mitigation only Fix from $2,3002021-03-25 HIGH 7.8 CVE-2021-1392 A vulnerability in the CLI command permissions of Cisco IOS and Cisco IOS XE Software could allow an authenticated, local attacker to retrieve the pa… iOS Mitigation only Fix from $1,9502021-03-24 MEDIUM 6.3 CVE-2019-10225 A flaw was found in atomic-openshift of openshift-4.2 where the basic-user RABC role in OpenShift Container Platform doesn't sufficiently protect the… Openshift Mitigation only Fix from $1,6002021-03-19 HIGH 7.8 CVE-2021-3141 In Unisys Stealth (core) before 6.0.025.0, the Keycloak password is stored in a recoverable format that might be accessible by a local attacker, who … Stealth 6.0.025.0+ Fix from $1,9502021-03-18