Vulnerability index

Browse CVEs

1,246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
MEDIUM 5.5 CVE-2020-16280 Multiple Rangee GmbH RangeeOS 8.0.4 modules store credentials in plaintext including credentials of users for several external facing administrative … Rangeeos Mitigation only Fix from $1,6002020-08-20 HIGH 7.5 CVE-2020-8210 Insufficient protection of secrets in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.… Xenmobile Server after 10.8.0 Fix from $1,9502020-08-17 MEDIUM 5.2 CVE-2020-7307 Unprotected Storage of Credentials vulnerability in McAfee Data Loss Prevention (DLP) for Mac prior to 11.5.2 allows local users to gain access to th… Data Loss Prevention 11.3.28 / 11.4.200+ Fix from $1,6002020-08-13 MEDIUM 5.2 CVE-2020-7306 Unprotected Storage of Credentials vulnerability in McAfee Data Loss Prevention (DLP) for Mac prior to 11.5.2 allows local users to gain access to th… Data Loss Prevention 11.3.31 / 11.4.200+ Fix from $1,6002020-08-13 MEDIUM 5.5 CVE-2020-9403 In PACTware before 4.1 SP6 and 5.x before 5.0.5.31, passwords are stored in a recoverable format, and may be retrieved by any user with access to the… Pactware 5.0.5.31+ Fix from $1,6002020-08-11 HIGH 7.1 CVE-2020-9404 In PACTware before 4.1 SP6 and 5.x before 5.0.5.31, passwords are stored in an insecure manner, and may be modified by an attacker with no knowledge … Pactware 5.0.5.31+ Fix from $1,9502020-08-11 MEDIUM 6.5 CVE-2020-15661 A rogue webpage could override the injected WKUserScript used by the logins autofill, this exploit could result in leaking a password for the current… Firefox Mobile 28.0+ Fix from $1,6002020-08-10 HIGH 8.1 CVE-2020-9525 CS2 Network P2P through 3.x, as used in millions of Internet of Things devices, suffers from an authentication flaw that allows remote attackers to p… P2p after 3.0.3a Fix from $1,9502020-08-10 HIGH 8.8 CVE-2020-15058 Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to elevate privileges because the administr… 42633 Firmware Mitigation only Fix from $1,9502020-08-07 HIGH 8.8 CVE-2020-15062 DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to elevate privileges because the administr… Da 70254 Firmware Mitigation only Fix from $1,9502020-08-07 HIGH 8.8 CVE-2020-15054 TP-Link USB Network Server TL-PS310U devices before 2.079.000.t0210 allow an attacker on the same network to elevate privileges because the administr… Tl Ps310u Firmware 2.079.000.t0210+ Fix from $1,9502020-08-07 HIGH 8.8 CVE-2020-14334 A flaw was found in Red Hat Satellite 6 which allows privileged attacker to read cache files. These cache credentials could help attacker to gain com… Satellite Mitigation only Fix from $1,9502020-07-31 MEDIUM 6.5 CVE-2020-2078 Passwords are stored in plain text within the configuration of SICK Package Analytics software up to and including V04.1.1. An authorized attacker co… Package Analytics after 04.1.1 Fix from $1,6002020-07-29 HIGH 7.5 CVE-2020-14489 OpenClinic GA 5.09.02 and 5.89.05b stores passwords using inadequate hashing complexity, which may allow an attacker to recover passwords using known… Openclinic Ga Mitigation only Fix from $1,9502020-07-29 HIGH 7.5 CVE-2020-13915 Insecure permissions in emfd/libemf in Ruckus Wireless Unleashed through 200.7.10.102.92 allow a remote attacker to overwrite admin credentials via a… Unleashed Firmware after 200.7.10.102.92 Fix from $1,9502020-07-28 HIGH 7.5 CVE-2020-10609 Grundfos CIM 500 v06.16.00 stores plaintext credentials, which may allow sensitive information to be read or allow modification to system settings by… Cim 500 Mitigation only Fix from $1,9502020-07-27 HIGH 7.8 CVE-2020-4372 IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 179009 Verify Gateway Patch available Fix from $1,9502020-07-22 MEDIUM 6.0 CVE-2020-4095 "BigFix Platform is storing clear text credentials within the system's memory. An attacker who is able to gain administrative privileges can use a pr… Bigfix Platform after 9.5.15 Fix from $1,6002020-07-16 HIGH 7.8 CVE-2020-3180 A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, local attacker to access an affected device by using an account tha… Sd Wan 18.3.6 / 18.4.5+ Fix from $1,9502020-07-16 CRITICAL 9.8 CVE-2020-10287 The IRC5 family with UAS service enabled comes by default with credentials that can be found on publicly available manuals. ABB considers this a well… Irb140 Firmware Mitigation only Fix from $2,3002020-07-15 MEDIUM 6.5 CVE-2020-3391 A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to view sensitive information in cle… Digital Network Architecture Center 1.2.10+ Fix from $1,6002020-07-02 HIGH 7.8 CVE-2020-5899 In NGINX Controller 3.0.0-3.4.0, recovery code required to change a user's password is transmitted and stored in the database in plain text, which al… Nginx Controller after 3.4.0 Fix from $1,9502020-07-01 MEDIUM 5.5 CVE-2020-10727 A flaw was found in ActiveMQ Artemis management API from version 2.7.0 up until 2.12.0, where a user inadvertently stores passwords in plaintext in t… Artemis after 2.12.0 Fix from $1,6002020-06-26 HIGH 8.1 CVE-2020-14930 An issue was discovered in BT CTROMS Terminal OS Port Portal CT-464. Account takeover can occur because the password-reset feature discloses the veri… Bt Ctroms Terminal No fix yet Fix from $1,9502020-06-19 HIGH 7.5 CVE-2018-21248 An issue was discovered in Mattermost Server before 5.4.0. It mishandles possession of superfluous authentication credentials. Mattermost Server 5.4.0+ Fix from $1,9502020-06-19 HIGH 7.5 CVE-2020-0540 Insufficiently protected credentials in Intel(R) AMT versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to pot… Active Management Technology Firmware 11.8.77 / 11.12.77+ Fix from $1,9502020-06-15 HIGH 7.5 CVE-2020-10752 A flaw was found in the OpenShift API Server, where it failed to sufficiently protect OAuthTokens by leaking them into the logs when an API Server pa… Openshift Container Platform Patch available Fix from $1,9502020-06-12 MEDIUM 6.5 CVE-2020-10755 An insecure-credentials flaw was found in all openstack-cinder versions before openstack-cinder 14.1.0, all openstack-cinder 15.x.x versions before o… Openstack Cinder 14.1.0 / 15.2.0+ Fix from $1,6002020-06-10 HIGH 8.1 CVE-2020-11681 Castel NextGen DVR v1.0.0 stores and displays credentials for the associated SMTP server in cleartext. Low privileged users can exploit this to creat… Nextgen Dvr Firmware No fix yet Fix from $1,9502020-06-04 MEDIUM 5.3 CVE-2018-21237 An issue was discovered in Foxit PhantomPDF before 8.3.7. It allows NTLM credential theft via a GoToE or GoToR action. Phantompdf 8.3.7+ Fix from $1,6002020-06-04