Vulnerability index

Browse CVEs

1,246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
HIGH 7.8 CVE-2019-10476 Jenkins Zulip Plugin 1.1.0 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be view… Zulip after 1.1.0 Fix from $1,9502019-10-23 MEDIUM 6.5 CVE-2019-10459 Jenkins Mattermost Notification Plugin 2.7.0 and earlier stored webhook URLs containing a secret token unencrypted in its global configuration file a… Mattermost Notification after 2.7.0 Fix from $1,6002019-10-23 HIGH 7.8 CVE-2019-10460 Jenkins Bitbucket OAuth Plugin 0.9 and earlier stored credentials unencrypted in the global config.xml configuration file on the Jenkins master where… Bitbucket Oauth after 0.9 Fix from $1,9502019-10-23 HIGH 7.8 CVE-2019-10461 Jenkins Dynatrace Application Monitoring Plugin 2.1.3 and earlier stored credentials unencrypted in its global configuration file on the Jenkins mast… Dynatrace Application Monitoring after 2.1.3 Fix from $1,9502019-10-23 MEDIUM 6.5 CVE-2019-10467 Jenkins Sonar Gerrit Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Exten… Sonar Gerrit after 2.3 Fix from $1,6002019-10-23 CRITICAL 9.8 CVE-2019-17393 The Customer's Tomedo Server in Version 1.7.3 communicates to the Vendor Tomedo Server via HTTP (in cleartext) that can be sniffed by unauthorized ac… Server No fix yet Fix from $2,3002019-10-18 HIGH 8.6 CVE-2019-11284 Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones. A remote unauthenticated malicious u… Reactor Netty 0.8.11+ Fix from $1,9502019-10-17 CRITICAL 9.8 CVE-2019-17662EPSS 97% ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exists even when authentication … Thinvnc No fix yet Fix from $2,3002019-10-16 HIGH 8.8 CVE-2019-10448 Jenkins Extensive Testing Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with … Extensive Testing Mitigation only Fix from $1,9502019-10-16 MEDIUM 6.5 CVE-2019-17356 The Infinite Design application 3.4.12 for Android sends a username and password via TCP without any encryption during login, as demonstrated by snif… Infinite Design No fix yet Fix from $1,6002019-10-15 MEDIUM 6.5 CVE-2019-17497EPSS 6% Tracker PDF-XChange Editor before 8.0.330.0 has an NTLM SSO hash theft vulnerability using crafted FDF or XFDF files (a related issue to CVE-2018-499… Pdf Xchange Editor 8.0.330.0+ Fix from $1,6002019-10-11 CRITICAL 9.8 CVE-2019-9533 The root password of the Cobham EXPLORER 710 is the same for all versions of firmware up to and including v1.08. This could allow an attacker to reve… Explorer 710 Firmware Mitigation only Fix from $2,3002019-10-10 MEDIUM 5.5 CVE-2019-0072 An Unprotected Storage of Credentials vulnerability in the identity and access management certificate generation procedure allows a local attacker to… Sbr Carrier Mitigation only Fix from $1,6002019-10-09 MEDIUM 5.5 CVE-2019-10429 Jenkins GitLab Logo Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users wi… Gitlab Logo after 1.0.3 Fix from $1,6002019-09-25 MEDIUM 6.5 CVE-2019-10413 Jenkins Data Theorem: CI/CD Plugin 1.3 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be v… Data Theorem Mobile App Security after 1.3 Fix from $1,6002019-09-25 MEDIUM 6.5 CVE-2019-10414 Jenkins Git Changelog Plugin 2.17 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be viewed… Git Changelog after 2.17 Fix from $1,6002019-09-25 MEDIUM 6.5 CVE-2019-10415 Jenkins Violation Comments to GitLab Plugin 2.28 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master wh… Violation Comments To Gitlab after 2.28 Fix from $1,6002019-09-25 MEDIUM 6.5 CVE-2019-10416 Jenkins Violation Comments to GitLab Plugin 2.28 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they … Violation Comments To Gitlab after 2.28 Fix from $1,6002019-09-25 MEDIUM 5.5 CVE-2019-10419 Jenkins vFabric Application Director Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be v… Vfabric Application Director after 1.3 Fix from $1,6002019-09-25 MEDIUM 5.5 CVE-2019-10420 Jenkins Assembla Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with … Assembla after 1.4 Fix from $1,6002019-09-25 MEDIUM 6.5 CVE-2019-10422 Jenkins Call Remote Job Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Ex… Call Remote Job after 1.0.21 Fix from $1,6002019-09-25 MEDIUM 5.5 CVE-2019-10423 Jenkins CodeScan Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with … Codescan after 0.11 Fix from $1,6002019-09-25 MEDIUM 5.5 CVE-2019-10424 Jenkins elOyente Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with … Eloyente after 1.3 Fix from $1,6002019-09-25 MEDIUM 6.5 CVE-2019-10425 Jenkins Google Calendar Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Ex… Google Calendar after 0.4 Fix from $1,6002019-09-25 MEDIUM 5.5 CVE-2019-10426 Jenkins Gem Publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users … Gem Publisher after 1.0 Fix from $1,6002019-09-25 CRITICAL 9.8 CVE-2019-5505 ONTAP Select Deploy administration utility versions 2.2 through 2.12.1 transmit credentials in plaintext. Ontap Select Deploy Administration Utility after 2.12.1 Fix from $2,3002019-09-24 CRITICAL 10.0 CVE-2019-16649 On Supermicro H11, H12, M11, X9, X10, and X11 products, a combination of encryption and authentication problems in the virtual media service allows c… X11dai N Firmware Mitigation only Fix from $2,3002019-09-21 MEDIUM 6.5 CVE-2019-11663 Clear text credentials are used to access managers app in Tomcat in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, … Service Manager after 9.62 Fix from $1,6002019-09-18 MEDIUM 6.5 CVE-2019-11664 Clear text password in browser in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60… Service Manager after 9.62 Fix from $1,6002019-09-18 HIGH 7.7 CVE-2019-5534 VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains an information disclosure vulnerability where Vi… Vcenter Server No fix yet Fix from $1,9502019-09-18