Vulnerability index

Browse CVEs

1,246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
MEDIUM 6.5 CVE-2017-18695 An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.0) software. Attackers (who control a certain subdomain) … Android Mitigation only Fix from $1,6002020-04-07 HIGH 7.5 CVE-2016-11029 An issue was discovered on Samsung mobile devices with L(5.0/5.1), M(6.0), and N(7.0) software. Attackers can read the password of the Mobile Hotspot… Android Mitigation only Fix from $1,9502020-04-07 MEDIUM 6.1 CVE-2019-19096 The Redis data structure component used in ABB eSOMS versions 6.0 to 6.0.2 stores credentials in clear text. If an attacker has file system access, t… Esoms after 6.0.2 Fix from $1,6002020-04-02 HIGH 7.5 CVE-2019-3942 Advantech WebAccess 8.3.4 does not properly restrict an RPC call that allows unauthenticated, remote users to read files. An attacker can use this vu… Webaccess Mitigation only Fix from $1,9502020-04-01 HIGH 7.5 CVE-2020-11449 An issue was discovered on Technicolor TC7337 8.89.17 devices. An attacker can discover admin credentials in the backup file, aka backupsettings.conf. Tc7337 Firmware No fix yet Fix from $1,9502020-04-01 MEDIUM 6.5 CVE-2020-2164 Jenkins Artifactory Plugin 3.5.0 and earlier stores its Artifactory server password unencrypted in its global configuration file on the Jenkins maste… Artifactory after 3.5.0 Fix from $1,6002020-03-25 HIGH 7.5 CVE-2020-2165 Jenkins Artifactory Plugin 3.6.0 and earlier transmits configured passwords in plain text as part of its global Jenkins configuration form, potential… Artifactory after 3.6.0 Fix from $1,9502020-03-25 HIGH 7.5 CVE-2019-18785 SuiteCRM 7.10.x prior to 7.10.21 and 7.11.x prior to 7.11.9 mishandles API access tokens and credentials. Suitecrm 7.10.21 / 7.11.9+ Fix from $1,9502020-03-20 HIGH 7.5 CVE-2019-16067 NETSAS Enigma NMS 65.0.0 and prior utilises basic authentication over HTTP for enforcing access control to the web application. The use of weak authe… Enigma Network Management Solution after 65.0.0 Fix from $1,9502020-03-19 HIGH 7.5 CVE-2019-15653 Comba AP2600-I devices through A02,0202N00PD2 are prone to password disclosure via an insecure authentication mechanism. The HTML source code of the … Ap2600 I A02 0202n00pd2 Firmware No fix yet Fix from $1,9502020-03-19 HIGH 7.5 CVE-2019-15655 D-Link DSL-2875AL devices through 1.00.05 are prone to password disclosure via a simple crafted /romfile.cfg request to the web management server. Th… Dsl 2875al Firmware after 1.00.05 Fix from $1,9502020-03-19 HIGH 7.5 CVE-2019-15656 D-Link DSL-2875AL and DSL-2877AL devices through 1.00.05 are prone to information disclosure via a simple crafted request to index.asp on the web man… Dsl 2875al Firmware after 1.00.05 Fix from $1,9502020-03-19 HIGH 7.5 CVE-2020-9324 Aquaforest TIFF Server 4.0 allows Unauthenticated SMB Hash Capture via UNC. Tiff Server No fix yet Fix from $1,9502020-03-18 CRITICAL 9.8 CVE-2019-13394 The Voo branded NETGEAR CG3700b custom firmware V2.02.03 uses HTTP Basic Authentication over cleartext HTTP. Cg3700b Firmware No fix yet Fix from $2,3002020-03-13 MEDIUM 6.5 CVE-2019-5648 Authenticated, administrative access to a Barracuda Load Balancer ADC running unpatched firmware <= v6.4 allows one to edit the LDAP service configur… Load Balancer Adc Firmware after 6.4 Fix from $1,6002020-03-12 HIGH 7.5 CVE-2019-9104 An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB31… Mb3170 Firmware after 4.0 Fix from $1,9502020-03-11 HIGH 7.5 CVE-2019-10705 Western Digital SanDisk X600 devices in certain configurations, a vulnerability in the access control mechanism of the drive may allow data to be dec… Sandisk X600 Sd9tb8w 128g Firmware Mitigation only Fix from $1,9502020-03-10 MEDIUM 6.3 CVE-2019-10706 Western Digital SanDisk SanDisk X300, X300s, X400, and X600 devices: The firmware update authentication method relies on a symmetric HMAC digest. The… Sandisk X600 Sd9tb8w 128g Firmware Mitigation only Fix from $1,6002020-03-10 MEDIUM 5.5 CVE-2019-11686 Western Digital SanDisk X300, X300s, X400, and X600 devices: A vulnerability in the wear-leveling algorithm of the drive may cause cryptographically … Sandisk X600 Sd9tb8w 128g Firmware Mitigation only Fix from $1,6002020-03-10 MEDIUM 5.5 CVE-2020-2145 Jenkins Zephyr Enterprise Test Management Plugin 1.9.1 and earlier stores its Zephyr password in plain text on the Jenkins master file system. Zephyr Enterprise Test Management after 1.9.1 Fix from $1,6002020-03-09 MEDIUM 5.9 CVE-2020-5404 The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorrectly, leading to a credentia… Reactor Netty after 0.9.4 Fix from $1,6002020-03-03 MEDIUM 6.5 CVE-2020-6794 If a user saved passwords before Thunderbird 60 and then later set a master password, an unencrypted copy of these passwords is still accessible. Thi… Ubuntu Linux 68.5.0+ Fix from $1,6002020-03-02 MEDIUM 6.5 CVE-2020-3841 The issue was addressed with improved UI handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, Safari 13.0.5. A local user may unknowingly s… Safari 13.0.5 / 13.3.1+ Fix from $1,6002020-02-27 MEDIUM 6.5 CVE-2020-5400 Cloud Foundry Cloud Controller (CAPI), versions prior to 1.91.0, logs properties of background jobs when they are run, which may include sensitive in… Capi Release 1.91.0 / 12.33.0+ Fix from $1,6002020-02-27 MEDIUM 5.5 CVE-2014-4659 Ansible before 1.5.5 sets 0644 permissions for sources.list, which might allow local users to obtain sensitive credential information in opportunisti… Ansible 1.5.5+ Fix from $1,6002020-02-20 MEDIUM 5.5 CVE-2014-4660 Ansible before 1.5.5 constructs filenames containing user and password fields on the basis of deb lines in sources.list, which might allow local user… Ansible 1.5.5+ Fix from $1,6002020-02-20 MEDIUM 6.5 CVE-2020-2129 Jenkins Eagle Tester Plugin 1.0.9 and earlier stores a password unencrypted in its global configuration file on the Jenkins master where it can be vi… Eagle Tester after 1.0.9 Fix from $1,6002020-02-12 MEDIUM 6.5 CVE-2020-2130 Jenkins Harvest SCM Plugin 0.5.1 and earlier stores a password unencrypted in its global configuration file on the Jenkins master where it can be vie… Harvest Scm after 0.5.1 Fix from $1,6002020-02-12 MEDIUM 6.5 CVE-2020-2131 Jenkins Harvest SCM Plugin 0.5.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins master where they can be viewed by u… Harvest Scm after 0.5.1 Fix from $1,6002020-02-12 MEDIUM 6.5 CVE-2020-2132 Jenkins Parasoft Environment Manager Plugin 2.14 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can… Parasoft Environment Manager after 2.14 Fix from $1,6002020-02-12