Vulnerability index

Browse CVEs

1,249 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
HIGH 7.8 CVE-2017-1378 IBM Spectrum Protect 7.1 and 8.1 (formerly Tivoli Storage Manager) disclosed unencrypted login credentials to Vmware vCenter in the application trace… Tivoli Storage Manager Patch available Fix from $1,9502017-10-05 HIGH 7.8 CVE-2017-1362 IBM Security Identity Manager Adapters 6.0 and 7.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: … Security Identity Manager Patch available Fix from $1,9502017-09-25 HIGH 8.1 CVE-2017-14418 The D-Link NPAPI extension, as used in conjunction with D-Link DIR-850L REV. B (with firmware through FW208WWb02) devices, sends the cleartext admin … Dir 850l Firmware No fix yet Fix from $1,9502017-09-13 CRITICAL 9.8 CVE-2017-13771 Lexmark Scan To Network (SNF) 3.2.9 and earlier stores network configuration credentials in plaintext and transmits them in requests, which allows re… Scan To Network after 3.2.9 Fix from $2,3002017-09-07 MEDIUM 5.3 CVE-2017-8446 The Reporting feature in X-Pack in versions prior to 5.5.2 and standalone Reporting plugin versions versions prior to 2.4.6 had an impersonation vuln… X Pack after 5.5.1 Fix from $1,6002017-08-18 HIGH 8.8 CVE-2017-7547EPSS 6% PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attackers to re… PostgreSQL Mitigation only Fix from $1,9502017-08-16 CRITICAL 9.8 CVE-2017-4923 VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure vulnerability. This issue may allow plaintext credentials to be obtain… Vcenter Server Patch available Fix from $2,3002017-08-01 CRITICAL 9.8 CVE-2017-6532 Televes COAXDATA GATEWAY 1Gbps devices doc-wifi-hgw_v1.02.0014 4.20 have cleartext credentials in /mib.db. Coaxdata Gateway 1gbps Firmware Mitigation only Fix from $2,3002017-07-20 CRITICAL 9.8 CVE-2017-11349 dataTaker DT8x dEX 1.72.007 allows remote attackers to compose programs or schedules, for purposes such as sending e-mail messages or making outbound… Dt8x Firmware No fix yet Fix from $2,3002017-07-17 HIGH 8.1 CVE-2017-1337 IBM WebSphere MQ 9.0.1 and 9.0.2 Java/JMS application can incorrectly transmit user credentials in plain text. IBM X-Force ID: 126245. Websphere Mq Mitigation only Fix from $1,9502017-07-10 CRITICAL 9.8 CVE-2017-6709 A vulnerability in the AutoVNF tool for the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to access administrative c… Ultra Services Framework after 5.0.2 Fix from $2,3002017-07-06 MEDIUM 5.5 CVE-2017-1207 IBM WebSphere Message Broker stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 123777. Websphere Message Broker Mitigation only Fix from $1,6002017-07-05 CRITICAL 9.8 CVE-2017-7315 An issue was discovered on Humax Digital HG100R 2.0.6 devices. To download the backup file it's not necessary to use credentials, and the router cred… Hg100r Firmware No fix yet Fix from $2,3002017-07-04 CRITICAL 9.8 CVE-2017-9248 KEVEPSS 75% Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web… Sitefinity 10.0.6412.0+ Fix from $2,3002017-07-03 CRITICAL 9.8 CVE-2017-6028 An Insufficiently Protected Credentials issue was discovered in Schneider Electric Modicon PLCs Modicon M241, all firmware versions, and Modicon M251… Modicon M241 Firmware after 4.0.3.20 Fix from $2,3002017-06-30 HIGH 7.5 CVE-2017-6046 An Insufficiently Protected Credentials issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT,… Airlink Raven Xe Firmware Mitigation only Fix from $1,9502017-06-30 CRITICAL 9.8 CVE-2017-7905 A Weak Cryptography for Passwords issue was discovered in General Electric (GE) Multilin SR 750 Feeder Protection Relay, firmware versions prior to V… Multilin Sr 750 Feeder Protection Relay Firmware after 6.0 Fix from $2,3002017-06-30 HIGH 7.5 CVE-2017-7524 tpm2-tools versions before 1.1.1 are vulnerable to a password leak due to transmitting password in plaintext from client to server when generating HM… Tpm2.0 Tools after 1.1.0 Fix from $1,9502017-06-27 HIGH 7.5 CVE-2017-3214 The Milwaukee ONE-KEY Android mobile application stores the master token in plaintext in the apk binary. One Key Mitigation only Fix from $1,9502017-06-20 HIGH 7.8 CVE-2017-9552 A design flaw in authentication in Synology Photo Station 6.0-2528 through 6.7.1-3419 allows local users to obtain credentials via cmdline. Synology … Photo Station Mitigation only Fix from $1,9502017-06-13 MEDIUM 5.5 CVE-2017-6694 A vulnerability in the Virtual Network Function Manager's (VNFM) logging function of Cisco Ultra Services Platform could allow an authenticated, loca… Ultra Services Platform Mitigation only Fix from $1,6002017-06-13 HIGH 7.5 CVE-2017-9557 register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1 allows remote attackers to discover passwords by sending the username parameter in … Easy Chat Server after 3.1 Fix from $1,9502017-06-12 CRITICAL 9.8 CVE-2017-8837 Cleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_… B305hw2 Firmware Patch available Fix from $2,3002017-06-05 CRITICAL 9.8 CVE-2017-7913 A Plaintext Storage of a Password issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3110-HSDPA… Oncell G3110 Hspa Firmware after 1.4 Fix from $2,3002017-05-29 HIGH 7.5 CVE-2017-9136 An issue was discovered on Mimosa Client Radios before 2.2.3. In the device's web interface, there is a page that allows an attacker to use an unsani… Backhaul Radios after 2.2.1 Fix from $1,9502017-05-21 HIGH 7.5 CVE-2017-7486EPSS 6% PostgreSQL versions 8.4 - 9.6 are vulnerable to information leak in pg_user_mappings view which discloses foreign server passwords to any user having… PostgreSQL Mitigation only Fix from $1,9502017-05-12 CRITICAL 9.8 CVE-2017-7925EPSS 51% A Password in Configuration File issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XX… Dh Ipc Hdbw23a0rn Zs Firmware Patch available Fix from $2,3002017-05-06 MEDIUM 6.8 CVE-2017-8371 Schneider Electric StruxureWare Data Center Expert before 7.4.0 uses cleartext RAM storage for passwords, which might allow remote attackers to obtai… Struxureware Data Center Expert after 7.3.1 Fix from $1,6002017-04-30 HIGH 7.5 CVE-2017-8296 kedpm 0.5 and 1.0 creates a history file in ~/.kedpm/history that is written in cleartext. All of the commands performed in the password manager are … Ked Password Manager Patch available Fix from $1,9502017-04-27 HIGH 7.5 CVE-2017-8222 Wireless IP Camera (P2P) WIFICAM devices have an "Apple Production IOS Push Services" private RSA key and certificate stored in /system/www/pem/ck.pe… Wireless Ip Camera \(p2p\) Firmware No fix yet Fix from $1,9502017-04-25