Vulnerability index

Browse CVEs

1,246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
MEDIUM 6.5 CVE-2019-13054 The Logitech R500 presentation clicker allows attackers to determine the AES key, leading to keystroke injection. On Windows, any text may be injecte… R500 Firmware No fix yet Fix from $1,6002019-06-29 HIGH 7.3 CVE-2019-11272 Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPasswordEncoder. If an appli… Spring Security 4.2.13+ Fix from $1,9502019-06-26 MEDIUM 6.5 CVE-2019-4385 IBM Spectrum Protect Plus 10.1.2 may display the vSnap CIFS password in the IBM Spectrum Protect Plus Joblog. This can result in an attacker gaining … Spectrum Protect Plus after 10.1.2.303 Fix from $1,6002019-06-19 HIGH 7.8 CVE-2019-11271 Cloud Foundry BOSH 270.x versions prior to v270.1.1, contain a BOSH Director that does not properly redact credentials when configured to use a MySQL… Bosh 270.1.1+ Fix from $1,9502019-06-19 MEDIUM 5.5 CVE-2019-4239 IBM MQ Advanced Cloud Pak (IBM Cloud Private 1.0.0 through 3.0.1) stores user credentials in plain in clear text which can be read by a local user. I… Cloud Private after 3.0.1 Fix from $1,6002019-06-14 CRITICAL 9.8 CVE-2019-3947 Fuji Electric V-Server before 6.0.33.0 stores database credentials in project files as plaintext. An attacker that can gain access to the project fil… V Server 6.0.33.0+ Fix from $2,3002019-06-12 MEDIUM 5.5 CVE-2019-6567 A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All Versions < V5.2.4), SCALANCE X-200IRT switch fam… Scalance X 200 Firmware 5.2.4+ Fix from $1,6002019-06-12 CRITICAL 9.8 CVE-2019-10160EPSS 5% A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.… Python 2.7.17 / 3.5.8+ Fix from $2,3002019-06-07 HIGH 8.8 CVE-2019-6452 Kyocera Command Center RX TASKalfa4501i and TASKalfa5052ci allows remote attackers to abuse the Test button in the machine address book to obtain a c… Command Center Rx No fix yet Fix from $1,9502019-06-06 CRITICAL 9.8 CVE-2019-11367 An issue was discovered in AUO Solar Data Recorder before 1.3.0. The web portal uses HTTP Basic Authentication and provides the account and password … Solar Data Recorder 1.3.0+ Fix from $2,3002019-06-03 HIGH 8.8 CVE-2019-11369EPSS 8% An issue was discovered in Carel pCOWeb prior to B1.2.4. In /config/pw_changeusers.html the device stores cleartext passwords, which may allow sensit… Pcoweb Card Firmware No fix yet Fix from $1,9502019-06-03 HIGH 7.8 CVE-2019-10981 In Vijeo Citect 7.30 and 7.40, and CitectSCADA 7.30 and 7.40, a vulnerability has been identified that may allow an authenticated local user access t… Citectscada Patch available Fix from $1,9502019-05-31 HIGH 8.8 CVE-2019-10329 Jenkins InfluxDB Plugin 1.21 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they can be view… Influxdb after 1.21 Fix from $1,9502019-05-31 HIGH 7.5 CVE-2019-12452 types/types.go in Containous Traefik 1.7.x through 1.7.11, when the --api flag is used and the API is publicly reachable and exposed without sufficie… Traefik after 1.7.11 Fix from $1,9502019-05-29 MEDIUM 5.9 CVE-2019-4138 IBM Tivoli Storage Productivity Center 5.2.13 through 5.3.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to… Spectrum Control after 5.3.2.0 Fix from $1,6002019-05-29 HIGH 7.1 CVE-2019-5625 The Android mobile application Halo Home before 1.11.0 stores OAuth authentication and refresh access tokens in a clear text file. This file persists… Halo Home No fix yet Fix from $1,9502019-05-22 HIGH 7.8 CVE-2019-5626 The Android mobile application BlueCats Reveal before 3.0.19 stores the username and password in a clear text file. This file persists until the user… Bluecats Reveal 3.0.19+ Fix from $1,9502019-05-22 HIGH 7.8 CVE-2019-5627 The iOS mobile application BlueCats Reveal before 5.14 stores the username and password in the app cache as base64 encoded strings, i.e. clear text. … Bc Reveal 5.14+ Fix from $1,9502019-05-22 CRITICAL 9.8 CVE-2019-12046 LemonLDAP::NG -2.0.3 has Incorrect Access Control. Debian Linux No fix yet Fix from $2,3002019-05-22 HIGH 7.8 CVE-2019-10139 During HE deployment via cockpit-ovirt, cockpit-ovirt generates an ansible variable file `/var/lib/ovirt-hosted-engine-setup/cockpit/ansibleVarFileXX… Cockpit Ovirt Mitigation only Fix from $1,9502019-05-17 HIGH 7.8 CVE-2019-0881 An elevation of privilege vulnerability exists when the Windows Kernel improperly handles key enumeration, aka 'Windows Kernel Elevation of Privilege… Windows 10 Patch available Fix from $1,9502019-05-16 HIGH 7.5 CVE-2019-10921 A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Unencrypted storage of passwords in the project coul… Logo\!8 Bm Firmware 8.3+ Fix from $1,9502019-05-14 MEDIUM 6.8 CVE-2019-8350 The Simple - Better Banking application 2.45.0 through 2.45.3 (fixed in 2.46.0) for Android was affected by an information disclosure vulnerability t… Better Banking after 2.45.3 Fix from $1,6002019-05-13 MEDIUM 6.8 CVE-2019-11885 eyeDisk implements the unlock feature by sending a cleartext password. The password can be discovered by sniffing USB traffic or by sending a 06 05 5… Eyedisk No fix yet Fix from $1,6002019-05-12 MEDIUM 5.5 CVE-2019-11820 Information exposure through process environment vulnerability in Synology Calendar before 2.3.3-0620 allows local users to obtain credentials via cm… Calendar 2.3.3-0620+ Fix from $1,6002019-05-09 HIGH 7.8 CVE-2019-3938 Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 stores usernames, passwords, and other configuration options in the file gener… Am 100 Firmware No fix yet Fix from $1,9502019-04-30 HIGH 8.8 CVE-2019-10313 Jenkins Twitter Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with a… Twitter after 0.7 Fix from $1,9502019-04-30 HIGH 8.8 CVE-2019-10316 Jenkins Aqua MicroScanner Plugin 1.0.5 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they c… Aqua Microscanner after 1.0.5 Fix from $1,9502019-04-30 HIGH 8.8 CVE-2019-10318 Jenkins Azure AD Plugin 0.3.3 and earlier stored the client secret unencrypted in the global config.xml configuration file on the Jenkins master wher… Azure Ad after 0.3.3 Fix from $1,9502019-04-30 HIGH 7.8 CVE-2019-10239 Robotronic RunAsSpc 3.7.0.0 protects stored credentials insufficiently, which allows locally authenticated attackers (under the same user context) to… Runasspc No fix yet Fix from $1,9502019-04-24