Vulnerability index

Browse CVEs

1,246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
CRITICAL 9.8 CVE-2019-11402 In Gradle Enterprise before 2018.5.3, Build Cache Nodes did not store the credentials at rest in an encrypted format. Enterprise 2018.5.3+ Fix from $2,3002019-04-22 CRITICAL 9.8 CVE-2019-11350 CloudBees Jenkins Operations Center 2.150.2.3, when an expired trial license exists, allows Cleartext Password Storage and Retrieval via the proxy co… Jenkins Operations Center Mitigation only Fix from $2,3002019-04-19 HIGH 8.8 CVE-2019-10302 Jenkins jira-ext Plugin 0.8 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be vie… Jira Ext after 0.8 Fix from $1,9502019-04-18 HIGH 8.8 CVE-2019-10303 Jenkins Azure PublisherSettings Credentials Plugin 1.2 and earlier stored credentials unencrypted in the credentials.xml file on the Jenkins master w… Azure Publishersettings Credentials after 1.2 Fix from $1,9502019-04-18 CRITICAL 9.8 CVE-2019-6609 Platform dependent weakness. This issue only impacts iSeries platforms. On these platforms, in BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge … Big Ip Local Traffic Manager 12.1.4.1 / 13.1.1.4+ Fix from $2,3002019-04-15 HIGH 8.8 CVE-2019-6525 AVEVA Wonderware System Platform 2017 Update 2 and prior uses an ArchestrA network user account for authentication of system processes and inter-node… Wonderware System Platform 2017+ Fix from $1,9502019-04-11 HIGH 7.8 CVE-2019-0032 A password management issue exists where the Organization authentication username and password were stored in plaintext in log files. A locally authe… Service Insight 18.1r1+ Fix from $1,9502019-04-10 MEDIUM 6.8 CVE-2019-0035 When "set system ports console insecure" is enabled, root login is disallowed for Junos OS as expected. However, the root password can be changed usi… Junos Mitigation only Fix from $1,6002019-04-10 MEDIUM 6.5 CVE-2019-5615 Users with Site-level permissions can access files containing the username-encrypted passwords of Security Console Global Administrators and clear-te… Insightvm after 6.5.49 Fix from $1,6002019-04-09 HIGH 8.8 CVE-2019-10630 A plaintext password vulnerability in the Zyxel NAS 326 through 5.21 allows an elevated privileged user to get the admin password of the device. Nas326 Firmware after 5.21 Fix from $1,9502019-04-09 HIGH 8.8 CVE-2019-10294 Jenkins Kmap Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read… Kmap Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-10295 Jenkins crittercism-dsym Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with E… Crittercism Dsym Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-10296 Jenkins Serena SRA Deploy Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by us… Serena Sra Deploy Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-10297 Jenkins Sametime Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with … Sametime Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-10298 Jenkins Koji Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with acce… Koji Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-10299 Jenkins CloudCoreo DeployTime Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed b… Cloudcoreo Deploytime Mitigation only Fix from $1,9502019-04-04 MEDIUM 6.5 CVE-2019-1003096 Jenkins TestFairy Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended… Testfairy after 4.16 Fix from $1,6002019-04-04 MEDIUM 6.5 CVE-2019-1003097 Jenkins Crowd Integration Plugin stores credentials unencrypted in the global config.xml configuration file on the Jenkins master where they can be v… Crowd Integration after 1.2 Fix from $1,6002019-04-04 HIGH 8.8 CVE-2019-10277 Jenkins StarTeam Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended … Starteam Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-10280 Jenkins Assembla Auth Plugin stores credentials unencrypted in the global config.xml configuration file on the Jenkins master where they can be viewe… Assembla Auth Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-10281 Jenkins Relution Enterprise Appstore Publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where the… Relution Enterprise Appstore Publisher Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-10282 Jenkins Klaros-Testmanagement Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users w… Klaros Testmanagement Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-10283 Jenkins mabl Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read… Mabl Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-10284 Jenkins Diawi Upload Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Exten… Diawi Upload Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-10285 Jenkins Minio Storage Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users … Minio Storage Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-10286 Jenkins DeployHub Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended… Deployhub Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-10287 Jenkins youtrack-plugin Plugin 0.7.1 and older stored credentials unencrypted in its global configuration file on the Jenkins master where they could… Youtrack Plugin after 0.7.1 Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-10288 Jenkins Jabber Server Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users … Jabber Server Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-10291 Jenkins Netsparker Cloud Scan Plugin 1.1.5 and older stored credentials unencrypted in its global configuration file on the Jenkins master where they… Netsparker Cloud Scan after 1.1.5 Fix from $1,9502019-04-04 MEDIUM 6.5 CVE-2019-1003045 A vulnerability in Jenkins ECS Publisher Plugin 1.0.0 and earlier allows attackers with Item/Extended Read permission, or local file system access to… Ecs Publisher after 1.0.0 Fix from $1,6002019-03-28