Vulnerability index

Browse CVEs

1,246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
MEDIUM 6.5 CVE-2020-2133 Jenkins Applatix Plugin 1.1 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users w… Applatix after 1.1 Fix from $1,6002020-02-12 MEDIUM 5.3 CVE-2020-2119 Jenkins Azure AD Plugin 1.1.2 and earlier transmits configured credentials in plain text as part of the global Jenkins configuration form, potentiall… Azure Ad after 1.1.2 Fix from $1,6002020-02-12 HIGH 7.5 CVE-2020-2114 Jenkins S3 publisher Plugin 0.11.4 and earlier transmits configured credentials in plain text as part of the global Jenkins configuration form, poten… S3 Publisher after 0.11.4 Fix from $1,9502020-02-12 CRITICAL 9.8 CVE-2020-6969 It is possible to unmask credentials and other sensitive information on “unprotected” project files, which may allow an attacker to remotely access t… C More Ea9 Rhi Firmware 6.53+ Fix from $2,3002020-02-05 CRITICAL 9.8 CVE-2013-7055EPSS 7% D-Link DIR-100 4.03B07 has PPTP and poe information disclosure Dir 100 Firmware No fix yet Fix from $2,3002020-02-04 CRITICAL 9.8 CVE-2013-7052EPSS 25% D-Link DIR-100 4.03B07: security bypass via an error in the cliget.cgi script Dir 100 Firmware No fix yet Fix from $2,3002020-02-04 HIGH 7.5 CVE-2013-2672 Brother MFC-9970CDW devices with firmware 0D allow cleartext submission of passwords. Mfc 9970cdw Firmware No fix yet Fix from $1,9502020-02-03 MEDIUM 5.5 CVE-2019-19119 An issue was discovered in PRTG 7.x through 19.4.53. Due to insufficient access control on local registry keys for the Core Server Service, a non-adm… Prtg Network Monitor after 19.4.53. Fix from $1,6002020-02-03 MEDIUM 6.8 CVE-2013-5113 LastPass prior to 2.5.1 has an insecure PIN implementation. Lastpass 2.5.1+ Fix from $1,6002020-01-31 HIGH 7.5 CVE-2020-7909 In JetBrains TeamCity before 2019.1.5, some server-stored passwords could be shown via the web UI. Teamcity 2019.1.5+ Fix from $1,9502020-01-30 HIGH 7.5 CVE-2014-2581 Smb4K before 1.1.1 allows remote attackers to obtain credentials via vectors related to the cuid option in the "Additional options" line edit. Fedora 1.1.1+ Fix from $1,9502020-01-28 CRITICAL 9.8 CVE-2014-3445EPSS 5% backup.php in HandsomeWeb SOS Webpages before 1.1.12 does not require knowledge of the cleartext password, which allows remote attackers to bypass au… Sos Webpages 1.1.12+ Fix from $2,3002020-01-28 MEDIUM 5.5 CVE-2019-19539 An issue was discovered in Idelji Web ViewPoint H01ABO-H01BY and L01ABP-L01ABZ, Web ViewPoint Plus H01AAG-H01AAQ and L01AAH-L01AAR, and Web ViewPoint… Web Viewpoint T0320 Mitigation only Fix from $1,6002020-01-27 HIGH 7.5 CVE-2019-19823EPSS 6% A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords in flash … A3002ru Firmware after 2019-12-12 Fix from $1,9502020-01-27 CRITICAL 10.0 CVE-2020-6961 In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X,… Apexpro Telemetry Server Firmware after 4.2 Fix from $2,3002020-01-24 HIGH 7.5 CVE-2012-6663EPSS 9% General Electric D20ME devices are not properly configured and reveal plaintext passwords. D20me Firmware No fix yet Fix from $1,9502020-01-23 HIGH 7.5 CVE-2019-19898 In IXP EasyInstall 6.2.13723, there are cleartext credentials in network communication on TCP port 20050 when using the Administrator console remotel… Easyinstall No fix yet Fix from $1,9502020-01-23 CRITICAL 9.8 CVE-2019-19843 Incorrect access control in the web interface in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote credential fetch via an unauthentica… Unleashed 9.10.2.0.84 / 9.12.3.0.136+ Fix from $2,3002020-01-22 CRITICAL 9.8 CVE-2020-7233 KMS Controls BAC-A1616BC BACnet devices have a cleartext password of snowman in the BACKDOOR_NAME variable in the BC_Logon.swf file. Bac A1616bc Firmware No fix yet Fix from $2,3002020-01-19 MEDIUM 5.5 CVE-2019-19696 A RootCA vulnerability found in Trend Micro Password Manager for Windows and macOS exists where the localhost.key of RootCA.crt might be improperly a… Password Manager after 5.0.1047 Fix from $1,6002020-01-18 HIGH 7.5 CVE-2019-12423EPSS 6% Apache CXF ships with a OpenId Connect JWK Keys service, which allows a client to obtain the public keys in JWK format, which can then be used to ver… Cxf 3.2.12 / 3.3.5+ Fix from $1,9502020-01-16 CRITICAL 9.8 CVE-2014-5381EPSS 7% Grand MA 300 allows a brute-force attack on the PIN. Grand Ma300 Firmware No fix yet Fix from $2,3002020-01-13 HIGH 7.5 CVE-2014-6039EPSS 69% ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability. Fixed version 10 Build 10000. Manageengine Eventlog Analyzer after 9.9 Fix from $1,9502020-01-13 HIGH 7.5 CVE-2012-3823 Arial Campaign Enterprise before 11.0.551 stores passwords in clear text and these may be retrieved. Campaign Enterprise 11.0.551+ Fix from $1,9502020-01-10 HIGH 7.8 CVE-2019-4508 IBM QRadar SIEM 7.3.0 through 7.3.3 uses weak credential storage in some instances which could be decrypted by a local attacker. IBM X-Force ID: 1644… Qradar Security Information And Event Manager after 7.3.3 Fix from $1,9502020-01-10 CRITICAL 9.8 CVE-2014-5093 Status2k does not remove the install directory allowing credential reset. Status2k No fix yet Fix from $2,3002020-01-10 MEDIUM 6.5 CVE-2019-6700 An information exposure vulnerability in the external authentication profile form of FortiSIEM 5.2.2 and earlier may allow an authenticated attacker … Fortisiem 5.2.5+ Fix from $1,6002020-01-07 HIGH 7.5 CVE-2019-5990 Access analysis CGI An-Analyzer released in 2019 June 24 and earlier allow remote attackers to obtain a login password via HTTP referer. Cgi An Anlyzer after 2019-06-24 Fix from $1,9502020-01-06 HIGH 7.5 CVE-2013-3620 Hardcoded WSMan credentials in Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before 3.15 (… Netscaler Sdx Firmware 3.12 / 3.15+ Fix from $1,9502020-01-02 MEDIUM 6.3 CVE-2019-10205 A flaw was found in the way Red Hat Quay stores robot account tokens in plain text. An attacker able to perform database queries in the Red Hat Quay … Quay Mitigation only Fix from $1,6002020-01-02