Vulnerability index

Browse CVEs

1,246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
CRITICAL 9.8 CVE-2018-18754 ZyXEL VMG3312-B10B 1.00(AAPP.7) devices have a backdoor root account with the tTn3+Z@!Sr0O+ password hash in the etc/default.cfg file. Vmg3312 B10b Firmware Mitigation only Fix from $2,3002018-10-29 HIGH 7.8 CVE-2018-18656 The PureVPN client before 6.1.0 for Windows stores Login Credentials (username and password) in cleartext. The location of such files is %PROGRAMDATA… Purevpn 6.1.0+ Fix from $1,9502018-10-26 HIGH 7.8 CVE-2018-11079 Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains a Plaintext Password Storage vulnerability. Database credentials are stored i… Secure Remote Services 3.32.00.08+ Fix from $1,9502018-10-18 MEDIUM 5.5 CVE-2018-12383 If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is… Enterprise Linux Desktop No fix yet Fix from $1,6002018-10-18 CRITICAL 9.8 CVE-2018-10824EPSS 12% An issue was discovered on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L through 1.02, DWR-512 through 2.02, DWR-712 through 2.02, DWR… Dwr 116 Firmware after 2.02 Fix from $2,3002018-10-17 CRITICAL 9.8 CVE-2018-17900 Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The web application improperly protects credentials which … Fcj Firmware Mitigation only Fix from $2,3002018-10-12 HIGH 7.8 CVE-2017-1231 IBM BigFix Platform 9.5 - 9.5.9 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 123910. Bigfix Platform after 9.5.9 Fix from $1,9502018-10-12 HIGH 7.5 CVE-2018-13789 An issue was discovered in Descor Infocad FM before 3.1.0.0. An unauthenticated web service allows the retrieval of files on the web server and on re… Infocad Fm 3.1.0.0+ Fix from $1,9502018-10-10 HIGH 7.5 CVE-2018-18074EPSS 7% The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect… Requests 2.20.0+ Fix from $1,9502018-10-09 CRITICAL 9.8 CVE-2018-14081 An issue was discovered on D-Link DIR-809 A1 through 1.09, A2 through 1.11, and Guest Zone through 1.09 devices. Device passwords, such as the admin … Dir 809 A1 Firmware after 1.11 Fix from $2,3002018-10-09 MEDIUM 6.5 CVE-2018-17871 Verba Collaboration Compliance and Quality Management Platform before 9.2.1.5545 has Incorrect Access Control. Verba Collaboration Compliance And Quality Management Platform 9.2.1.5545+ Fix from $1,6002018-10-04 CRITICAL 9.8 CVE-2018-17969 Samsung SCX-6545X V2.00.03.01 03-23-2012 devices allows remote attackers to discover cleartext credentials via iso.3.6.1.4.1.236.11.5.11.81.10.1.5.0 … Scx 6545x Firmware No fix yet Fix from $2,3002018-10-03 MEDIUM 5.5 CVE-2018-11752 Previous releases of the Puppet cisco_ios module output SSH session debug information including login credentials to a world readable file on every r… Cisco Ios 0.4.0+ Fix from $1,6002018-10-02 HIGH 7.8 CVE-2018-11748 Previous releases of the Puppet device_manager module creates configuration files containing credentials that are world readable. This issue has been… Device Manager 2.7.0+ Fix from $1,9502018-10-02 HIGH 7.8 CVE-2018-1498 IBM Security Guardium EcoSystem 10.5 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 141223. Security Guardium Mitigation only Fix from $1,9502018-10-02 CRITICAL 9.8 CVE-2018-17613 Telegram Desktop (aka tdesktop) 1.3.16 alpha, when "Use proxy" is enabled, sends credentials and application data in cleartext over the SOCKS5 protoc… Telegram Desktop Mitigation only Fix from $2,3002018-09-28 CRITICAL 9.8 CVE-2018-16669 An issue was discovered in CIRCONTROL Open Charge Point Protocol (OCPP) before 1.5.0, as used in CirCarLife, PowerStudio, and other products. Due to … Open Charge Point Protocol 1.5.0+ Fix from $2,3002018-09-18 HIGH 7.8 CVE-2018-10814 Synametrics SynaMan 4.0 build 1488 uses cleartext password storage for SMTP credentials. Synaman No fix yet Fix from $1,9502018-09-14 HIGH 7.2 CVE-2018-16987 Squash TM through 1.18.0 presents the cleartext passwords of external services in the administration panel, as demonstrated by a ta-server-password f… Squash Tm after 1.18.0 Fix from $1,9502018-09-13 HIGH 8.1 CVE-2017-17691 Homeputer CL Studio fur HomeMatic 4.0 Rel 160808 and earlier uses cleartext to exchange the username and password between server and client instances… Homeputer Cl Studio Fur Homematic 4.0+ Fix from $1,9502018-09-07 CRITICAL 9.8 CVE-2017-16714 In Ice Qube Thermal Management Center versions prior to version 4.13, passwords are stored in plaintext in a file that is accessible without authenti… Thermal Management Center Firmware 4.13+ Fix from $2,3002018-09-06 HIGH 7.5 CVE-2018-13822 Unprotected storage of credentials in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows attackers to access sensi… Project Portfolio Management after 14.3 Fix from $1,9502018-08-30 HIGH 8.1 CVE-2018-1139 A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A ma… Ubuntu Linux 4.7.9 / 4.8.4+ Fix from $1,9502018-08-22 MEDIUM 5.2 CVE-2018-10622 Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials for … Mycarelink 24952 Patient Monitor Firmware Mitigation only Fix from $1,6002018-08-10 HIGH 7.5 CVE-2017-1411 IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 does not require that users should have strong passwords by default, which mak… Security Identity Governance And Intelligence Patch available Fix from $1,9502018-08-06 HIGH 8.8 CVE-2018-11050 Dell EMC NetWorker versions between 9.0 and 9.1.1.8 through 9.2.1.3, and the version 18.1.0.1 contain a Clear-Text authentication over network vulner… Emc Networker after 9.2.1.3 Fix from $1,9502018-08-01 HIGH 8.8 CVE-2018-5543 The F5 BIG-IP Controller for Kubernetes 1.0.0-1.5.0 (k8s-bigip-crtl) passes BIG-IP username and password as command line parameters, which may lead t… Big Ip Controller after 1.5.0 Fix from $1,9502018-07-31 CRITICAL 9.8 CVE-2018-8851 Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The dev… Smartserver 1 Firmware 4.11.007+ Fix from $2,3002018-07-24 MEDIUM 6.7 CVE-2017-5704 Platform sample code firmware included with 4th Gen Intel Core Processor, 5th Gen Intel Core Processor, 6th Gen Intel Core Processor, and 7th Gen Int… Core I3 Mitigation only Fix from $1,6002018-07-10 HIGH 7.8 CVE-2018-1000401 Jenkins project Jenkins AWS CodePipeline Plugin version 0.36 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSCodePipe… Aws Codepipeline after 0.36 Fix from $1,9502018-07-09