Vulnerability index

Browse CVEs

1,249 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
HIGH 8.8 CVE-2016-9593 foreman-debug before version 1.15.0 is vulnerable to a flaw in foreman-debug's logging. An attacker with access to the foreman log file would be able… Satellite 1.15.0+ Fix from $1,9502018-04-16 CRITICAL 9.8 CVE-2018-10024 ubiQuoss Switch VP5208A creates a bcm_password file at /cgi-bin/ with the user credentials in cleartext when a failed login attempt occurs. The file … Vp5208a Firmware Mitigation only Fix from $2,3002018-04-11 HIGH 7.8 CVE-2018-4170 An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "Admin Framework" component. It allows lo… Mac Os X 10.13.4+ Fix from $1,9502018-04-03 CRITICAL 9.8 CVE-2018-9160EPSS 76% SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses. Sickrage after 9.2.101 Fix from $2,3002018-03-31 HIGH 8.0 CVE-2018-5708EPSS 6% An issue was discovered on D-Link DIR-601 B1 2.02NA devices. Being on the same local network as, but being unauthenticated to, the administrator's pa… Dir 601 Firmware No fix yet Fix from $1,9502018-03-30 CRITICAL 9.8 CVE-2018-9031 The login interface on TNLSoftSolutions Sentry Vision 3.x devices provides password disclosure by reading an "if(pwd ==" line in the HTML source code… Sentry Vision No fix yet Fix from $2,3002018-03-29 CRITICAL 9.8 CVE-2017-11510 An information leak exists in Wanscam's HW0021 network camera that allows an unauthenticated remote attacker to recover the administrator username an… Hw0021 Firmware No fix yet Fix from $2,3002018-03-28 HIGH 7.2 CVE-2017-0925 Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration API endpoin… GitLab after 10.3.3 Fix from $1,9502018-03-21 HIGH 7.8 CVE-2018-1000104 A plaintext storage of a password vulnerability exists in Jenkins Coverity Plugin 1.10.0 and earlier in CIMInstance.java that allows an attacker with… Coverity after 1.10.0 Fix from $1,9502018-03-13 HIGH 8.1 CVE-2018-7698 An issue was discovered in D-Link mydlink+ 3.8.5 build 259 for DCS-933L 1.05.04 and DCS-934L 1.05.04 devices. The mydlink+ app sends the username and… Mydlink\+ Mitigation only Fix from $1,9502018-03-05 HIGH 7.5 CVE-2017-5189 NetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel, allowing attackers to extrac… Imanager Mitigation only Fix from $1,9502018-03-02 HIGH 7.8 CVE-2018-1377 IBM Security Guardium Big Data Intelligence (SonarG) 3.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Forc… Security Guardium Big Data Intelligence Mitigation only Fix from $1,9502018-02-26 HIGH 8.1 CVE-2018-3609EPSS 21% A vulnerability in the Trend Micro InterScan Messaging Security Virtual Appliance 9.0 and 9.1 management portal could allow an unauthenticated user t… Interscan Messaging Security Virtual Appliance No fix yet Fix from $1,9502018-02-16 HIGH 7.8 CVE-2018-0828 Windows 10 version 1607 and Windows Server 2016 allow an elevation of privilege vulnerability due to how the MultiPoint management account password i… Windows 10 Patch available Fix from $1,9502018-02-15 MEDIUM 6.7 CVE-2017-9969 An information disclosure vulnerability exists in Schneider Electric's IGSS Mobile application version 3.01 and prior. Passwords are stored in clear … Igss Mobile after 3.01 Fix from $1,6002018-02-12 HIGH 8.8 CVE-2017-15656 Password are stored in plaintext in nvram in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt. Asuswrt after 3.0.0.4.380.7743 Fix from $1,9502018-01-31 HIGH 7.8 CVE-2017-1779 IBM Cognos Analytics 11.0 could store cached credentials locally that could be obtained by a local user. IBM X-Force ID: 136824. Cognos Analytics Patch available Fix from $1,9502018-01-29 HIGH 7.8 CVE-2017-1000387 Jenkins Build-Publisher plugin version 1.21 and earlier stores credentials to other Jenkins instances in the file hudson.plugins.build_publisher.Buil… Build Publisher after 1.21 Fix from $1,9502018-01-26 HIGH 8.8 CVE-2017-16731 An Unprotected Transport of Credentials issue was discovered in ABB Ellipse 8.3 through Ellipse 8.9 released prior to December 2017 (including Ellips… Ellipse after 8.9.0 Fix from $1,9502017-12-20 CRITICAL 9.8 CVE-2017-17106EPSS 15% Credentials for Zivif PR115-204-P-RS V2.3.4.2103 Webcams can be obtained by an unauthenticated remote attacker using a standard web /cgi-bin/hi3510/p… Pr115 204 P Rs Firmware No fix yet Fix from $2,3002017-12-19 CRITICAL 9.8 CVE-2017-3192EPSS 39% D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 do not sufficiently protect administrator credentials. The tools_admin.asp pag… Dir 130 Firmware Mitigation only Fix from $2,3002017-12-16 HIGH 7.2 CVE-2017-14111 The workstation logging function in Philips IntelliSpace Cardiovascular (ISCV) 2.3.0 and earlier and Xcelera R4.1L1 and earlier records domain authen… Intellispace Cardiovascular after 2.3.0 Fix from $1,9502017-11-17 MEDIUM 5.3 CVE-2017-15272 The PSFTPd 10.0.4 Build 729 server stores its configuration inside PSFTPd.dat. This file is a Microsoft Access Database and can be extracted. The app… Psftpd No fix yet Fix from $1,6002017-11-15 HIGH 8.1 CVE-2017-14711 The Kickbase GmbH "Kickbase Bundesliga Manager" app before 2.2.1 -- aka kickbase-bundesliga-manager/id678241305 -- for iOS is vulnerable to a credent… Bundesliga Manager 2.2.1+ Fix from $1,9502017-11-13 HIGH 7.8 CVE-2017-15918 Sera 1.2 stores the user's login password in plain text in their home directory. This makes privilege escalation trivial and also exposes the user an… Sera No fix yet Fix from $1,9502017-11-01 CRITICAL 9.8 CVE-2017-1000245 The SSH Plugin stores credentials which allow jobs to access remote servers via the SSH protocol. User passwords and passphrases for encrypted SSH ke… Ssh after 2.4 Fix from $2,3002017-11-01 HIGH 8.1 CVE-2017-3760 The Lenovo Service Framework Android application uses a set of nonsecure credentials when performing integrity verification of downloaded application… Service Framework Patch available Fix from $1,9502017-10-17 HIGH 8.4 CVE-2017-5700 Insufficient protection of password storage in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and be… Nuc7i7bnh Firmware Patch available Fix from $1,9502017-10-11 HIGH 7.5 CVE-2017-13998 An Insufficiently Protected Credentials issue was discovered in LOYTEC LVIS-3ME versions prior to 6.2.0. The application does not sufficiently protec… Lvis 3me Firmware after 6.1.1 Fix from $1,9502017-10-05 HIGH 7.8 CVE-2017-1201 IBM BigFix Compliance Analytics 1.9.79 (TEMA SUAv1 SCA SCM) stores user credentials in clear text which can be read by a local user. IBM X-Force ID: … Bigfix Security Compliance Analytics Mitigation only Fix from $1,9502017-10-05