Vulnerability index

Browse CVEs

1,249 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
CRITICAL 9.8 CVE-2018-8851 Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The dev… Smartserver 1 Firmware 4.11.007+ Fix from $2,3002018-07-24 MEDIUM 6.7 CVE-2017-5704 Platform sample code firmware included with 4th Gen Intel Core Processor, 5th Gen Intel Core Processor, 6th Gen Intel Core Processor, and 7th Gen Int… Core I3 Mitigation only Fix from $1,6002018-07-10 HIGH 7.8 CVE-2018-1000401 Jenkins project Jenkins AWS CodePipeline Plugin version 0.36 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSCodePipe… Aws Codepipeline after 0.36 Fix from $1,9502018-07-09 HIGH 7.8 CVE-2018-1000403 Jenkins project Jenkins AWS CodeDeploy Plugin version 1.19 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSCodeDeploy… Aws Codedeploy after 1.19 Fix from $1,9502018-07-09 HIGH 7.8 CVE-2018-1000404 Jenkins project Jenkins AWS CodeBuild Plugin version 0.26 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSClientFacto… Aws Codebuild after 0.26 Fix from $1,9502018-07-09 HIGH 7.0 CVE-2017-2665 The skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /etc/skyring/skyring.conf file… MongoDB Mitigation only Fix from $1,9502018-07-06 HIGH 7.8 CVE-2018-11634 Plaintext Storage of Passwords in the administrative console in Dialogic PowerMedia XMS before 3.5 SU2 allows local users to access the web applicati… Powermedia Xms after 3.5 Fix from $1,9502018-07-03 HIGH 8.1 CVE-2018-11639 Plaintext Storage of Passwords within Cookies in /var/www/xms/application/controllers/verifyLogin.php in the administrative console in Dialogic Power… Powermedia Xms after 3.5 Fix from $1,9502018-07-03 HIGH 8.8 CVE-2018-7782 In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, authenticated users can view passwords… Imps110 1 Firmware 3.29.69+ Fix from $1,9502018-07-03 CRITICAL 9.8 CVE-2018-11746 In Puppet Discovery prior to 1.2.0, when running Discovery against Windows hosts, WinRM connections can fall back to using basic auth over insecure c… Discovery 1.2.0+ Fix from $2,3002018-07-03 HIGH 7.8 CVE-2018-13014 Storing password in recoverable format in safensec.com (SysWatch service) in SAFE'N'SEC SoftControl/SafenSoft SysWatch, SoftControl/SafenSoft TPSecur… Enterprise Suite 4.4.2+ Fix from $1,9502018-06-29 MEDIUM 5.9 CVE-2017-16718 Beckhoff TwinCAT 3 supports communication over ADS. ADS is a protocol for industrial automation in protected environments. This protocol uses user co… Twincat No fix yet Fix from $1,6002018-06-27 HIGH 7.2 CVE-2018-1000608 A exposure of sensitive information vulnerability exists in Jenkins z/OS Connector Plugin 1.2.6.1 and earlier in SCLMSCM.java that allows an attacker… Z\/os Connector after 1.2.6.1 Fix from $1,9502018-06-26 HIGH 8.8 CVE-2018-1000610 A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in DataBoundConfigurator.java,… Configuration As Code Mitigation only Fix from $1,9502018-06-26 MEDIUM 6.7 CVE-2018-12260 An issue was discovered on Momentum Axel 720P 5.1.8 devices. The root password can be obtained in cleartext by issuing the command 'showKey' from the… Momentum Axel 720p Firmware No fix yet Fix from $1,6002018-06-12 HIGH 7.8 CVE-2018-1075 ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one choo… Ovirt 4.2.3+ Fix from $1,9502018-06-12 HIGH 8.8 CVE-2018-4190 An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is aff… Safari 7.5 / 11.1.1+ Fix from $1,9502018-06-08 HIGH 7.8 CVE-2018-0335 A vulnerability in the web portal authentication process of Cisco Prime Collaboration Provisioning could allow an unauthenticated, local attacker to … Prime Collaboration Mitigation only Fix from $1,9502018-06-07 CRITICAL 9.8 CVE-2017-7933 In ABB IP GATEWAY 3.39 and prior, some configuration files contain passwords stored in plain-text, which may allow an attacker to gain unauthorized a… Ip Gateway Firmware after 3.39 Fix from $2,3002018-06-06 CRITICAL 9.8 CVE-2018-7510 In the web application in BeaconMedaes TotalAlert Scroll Medical Air Systems running software versions prior to 4107600010.23, passwords are presente… Scroll Medical Air Systems Firmware 4107600010.23+ Fix from $2,3002018-06-06 CRITICAL 9.8 CVE-2018-11544 The Olive Tree Ftp Server application 1.32 for Android has Insecure Data Storage because a username and password are stored in the /data/data/com.the… Ftp Server No fix yet Fix from $2,3002018-05-29 CRITICAL 9.8 CVE-2018-7518 In TotalAlert Web Application in BeaconMedaes Scroll Medical Air Systems prior to v4107600010.23, an attacker with network access to the integrated w… Scroll Medical Air Systems Firmware 4107600010.23+ Fix from $2,3002018-05-24 HIGH 7.0 CVE-2018-10355 An authentication weakness vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to recover user passwords on vulnerable … Email Encryption Gateway after 5.5 Fix from $1,9502018-05-23 HIGH 7.0 CVE-2018-10327 PrinterOn Enterprise 4.1.3 stores the Active Directory bind credentials using base64 encoding, which allows local users to obtain credentials for a d… Printeron No fix yet Fix from $1,9502018-05-17 HIGH 8.8 CVE-2017-12123 An exploitable clear text transmission of password vulnerability exists in the web server and telnet functionality of Moxa EDR-810 V4.1 build 1703031… Edr 810 Firmware No fix yet Fix from $1,9502018-05-14 HIGH 7.8 CVE-2018-6618 Easy Hosting Control Panel (EHCP) v0.37.12.b allows attackers to obtain sensitive information by leveraging cleartext password storage. Easy Hosting Control Panel No fix yet Fix from $1,9502018-05-11 HIGH 7.2 CVE-2018-1074 ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentials, includ… Enterprise Virtualization after 4.1.11.1 Fix from $1,9502018-04-26 HIGH 8.8 CVE-2017-9654 The Philips DoseWise Portal web-based application versions 1.1.7.333 and 2.1.1.3069 stores login credentials in clear text within backend system file… Dosewise Mitigation only Fix from $1,9502018-04-24 HIGH 7.0 CVE-2017-1764 IBM Cognos Business Intelligence 10.2, 10.2.1, 10.2.1.1, and 10.2.2, under specialized circumstances, could expose plain text credentials to a local … Cognos Business Intelligence No fix yet Fix from $1,9502018-04-23 HIGH 8.8 CVE-2018-10286EPSS 7% The Ericsson-LG iPECS NMS A.1Ac web application discloses sensitive information such as the NMS admin credentials and the PostgreSQL database credent… Ipecs Nms No fix yet Fix from $1,9502018-04-22