Vulnerability index

Browse CVEs

1,246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
MEDIUM 5.3 CVE-2018-21239 An issue was discovered in Foxit Reader and PhantomPDF before 9.2. It allows NTLM credential theft via a GoToE or GoToR action. Phantompdf 9.2+ Fix from $1,6002020-06-04 MEDIUM 5.5 CVE-2020-7030 A sensitive information disclosure vulnerability was discovered in the web interface component of IP Office that may potentially allow a local user t… Ip Office after 11.0.4.2 Fix from $1,6002020-06-04 MEDIUM 6.5 CVE-2020-2198 Jenkins Project Inheritance Plugin 19.08.02 and earlier does not redact encrypted secrets in the 'getConfigAsXML' API URL when transmitting job confi… Project Inheritance after 19.08.02 Fix from $1,6002020-06-03 HIGH 7.8 CVE-2014-8938 Lexiglot through 2014-11-20 allows local users to obtain sensitive information by listing a process because the username and password are on the comm… Lexiglot after 2014-11-20 Fix from $1,9502020-06-01 HIGH 7.5 CVE-2014-9702 system/classes/DbPDO.php in Cmfive through 2015-03-15, when database connectivity malfunctions, allows remote attackers to obtain sensitive informati… Cmfive after 2015-03-15 Fix from $1,9502020-06-01 MEDIUM 6.5 CVE-2019-13023 An issue was discovered in all versions of Bond JetSelect. Within the JetSelect Application, the web interface hides RADIUS secrets, WPA passwords, a… Jetselect Mitigation only Fix from $1,6002020-05-14 MEDIUM 5.5 CVE-2014-1423 signond before 8.57+15.04.20141127.1-0ubuntu1, as used in Ubuntu Touch, did not properly restrict applications from querying oath tokens due to incor… Signond 8.57+ Fix from $1,6002020-05-07 HIGH 7.5 CVE-2020-10972 An issue was discovered where a page is exposed that has the current administrator password in cleartext in the source code of the page. No authentic… Wn530hg4 Firmware Mitigation only Fix from $1,9502020-05-07 CRITICAL 9.8 CVE-2019-18868 Blaauw Remote Kiln Control through v3.00r4 allows an unauthenticated attacker to access MySQL credentials in cleartext in /engine/db.inc, /lang/nl.ba… Remote Kiln Control after 3.0.0 Fix from $2,3002020-05-07 MEDIUM 6.5 CVE-2020-2181 Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets in the build log when the build contains no … Credentials Binding after 1.22 Fix from $1,6002020-05-06 HIGH 7.5 CVE-2019-19218 BMC Control-M/Agent 7.0.00.000 has Insecure Password Storage. Control M\/agent Mitigation only Fix from $1,9502020-04-30 MEDIUM 5.3 CVE-2020-11821 In Rukovoditel 2.5.2, users' passwords and usernames are stored in a cookie with URL encoding, base64 encoding, and hashing. Thus, an attacker can ea… Rukovoditel No fix yet Fix from $1,6002020-04-27 HIGH 7.5 CVE-2020-12273 In TestLink 1.9.20, a crafted login.php viewer parameter exposes cleartext credentials. Testlink Patch available Fix from $1,9502020-04-27 MEDIUM 5.5 CVE-2019-4668 IBM UrbanCode Deploy (UCD) 7.0.4.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 171250. Urbancode Deploy 7.0.4.0+ Fix from $1,6002020-04-23 MEDIUM 5.5 CVE-2019-19105 The backup function in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway saves the current settings and configuration of the ap… Tg\/s3.2 Firmware Mitigation only Fix from $1,6002020-04-22 HIGH 7.8 CVE-2017-18777 Certain NETGEAR devices are affected by administrative password disclosure. This affects D6220 before V1.0.0.28, D6400 before V1.0.0.60, D8500 before… D6220 Firmware 1.0.0.28 / 1.0.0.60+ Fix from $1,9502020-04-22 HIGH 7.5 CVE-2020-11008 Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. This b… Git 2.17.5 / 2.18.4+ Fix from $1,9502020-04-21 HIGH 7.8 CVE-2017-18843 Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects R6700v2 before 1.1.0.38, R6800 before 1.1.0.38, and D7… R6700 Firmware 1.0.1.50 / 1.1.0.38+ Fix from $1,9502020-04-20 HIGH 7.8 CVE-2017-18844 Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects R6700v2 before 1.1.0.38, R6800 before 1.1.0.38, and D7… R6700 Firmware 1.0.1.50 / 1.1.0.38+ Fix from $1,9502020-04-20 HIGH 7.8 CVE-2017-18845 Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects R6700v2 before 1.1.0.38 and R6800 before 1.1.0.38. R6700 Firmware 1.1.0.38+ Fix from $1,9502020-04-20 HIGH 8.8 CVE-2020-9523 Insufficiently protected credentials vulnerability on Micro Focus enterprise developer and enterprise server, affecting all version prior to 4.0 Patc… Enterprise Developer after 3.0 Fix from $1,9502020-04-17 MEDIUM 5.5 CVE-2020-5721 MikroTik WinBox 3.22 and below stores the user's cleartext password in the settings.cfg.viw configuration file when the Keep Password field is set an… Winbox after 3.22 Fix from $1,6002020-04-15 HIGH 7.5 CVE-2020-5260EPSS 10% Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. Git us… Git 2.17.4 / 2.18.3+ Fix from $1,9502020-04-14 CRITICAL 9.8 CVE-2020-6195 SAP Business Objects Business Intelligence Platform (CMC), version 4.1, 4.2, shows cleartext password in the response, leading to Information Disclos… Businessobjects Business Intelligence Platform Mitigation only Fix from $2,3002020-04-14 HIGH 7.5 CVE-2020-11694 In JetBrains PyCharm 2019.2.5 and 2019.3 on Windows, Apple Notarization Service credentials were included. This is fixed in 2019.2.6 and 2019.3.3. Pycharm No fix yet Fix from $1,9502020-04-10 MEDIUM 6.5 CVE-2020-5406 VMware Tanzu Application Service for VMs, 2.6.x versions prior to 2.6.18, 2.7.x versions prior to 2.7.11, and 2.8.x versions prior to 2.8.5, includes… Tanzu Application Service For Vms 2.6.18 / 2.7.11+ Fix from $1,6002020-04-10 HIGH 7.5 CVE-2020-11555 An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It allows remote attackers to obtain sensitive credential information… Snmpc Online 2020-01-28+ Fix from $1,9502020-04-09 HIGH 7.5 CVE-2020-11557 An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It includes the username and password values in cleartext within each… Snmpc Online 2020-01-28+ Fix from $1,9502020-04-09 HIGH 7.2 CVE-2020-11629 An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. The External Command Certificate Validator, which allows administrators to u… Ejbca 6.15.2.6 / 7.3.1.2+ Fix from $1,9502020-04-08 HIGH 7.8 CVE-2020-11560 NCH Express Invoice 7.25 allows local users to discover the cleartext password by reading the configuration file. Express Invoice No fix yet Fix from $1,9502020-04-07