Vulnerability index

Browse CVEs

1,249 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
CRITICAL 9.8 CVE-2017-8225EPSS 18% On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is not correctly checked. An attacker can bypass authentic… Wireless Ip Camera \(p2p\) Firmware No fix yet Fix from $2,3002017-04-25 HIGH 8.1 CVE-2017-6528 An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is affected by plaintext password storage (the /home/dna/spool/.pfile file). Dnalims No fix yet Fix from $1,9502017-03-09 MEDIUM 6.7 CVE-2016-9360 An issue was discovered in General Electric (GE) Proficy HMI/SCADA iFIX Version 5.8 SIM 13 and prior versions, Proficy HMI/SCADA CIMPLICITY Version 9… Cimplicity after 9.0 Fix from $1,6002017-02-13 CRITICAL 9.8 CVE-2017-5139 An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. Any user i… Xl Web Ii Controller Mitigation only Fix from $2,3002017-02-13 CRITICAL 9.8 CVE-2017-5140 An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. Password i… Xl Web Ii Controller Mitigation only Fix from $2,3002017-02-13 MEDIUM 5.5 CVE-2015-5013 The IBM Security Access Manager appliance includes configuration files that contain obfuscated plaintext-passwords which authenticated users can acce… Security Access Manager For Web 8.0 Firmware Patch available Fix from $1,6002017-02-08 HIGH 7.5 CVE-2015-7546 The identity service in OpenStack Identity (Keystone) before 2015.1.3 (Kilo) and 8.0.x before 8.0.2 (Liberty) and keystonemiddleware (formerly python… Keystonemiddleware 8.0.2+ Fix from $1,9502016-02-03 MEDIUM 5.0 CVE-2015-5955 ownCloud iOS app before 3.4.4 does not properly switch state between multiple instances, which might allow remote instance administrators to obtain s… Owncloud Client 3.4.4+ Fix from $1,6002015-10-29 MEDIUM 5.0 CVE-2015-3962 Schneider Electric StruxureWare Building Expert MPM before 2.15 does not use encryption for the client-server data stream, which allows remote attack… Struxureware Building Expert Multi Purpose Management 2.15+ Fix from $1,6002015-09-18 MEDIUM 5.5 CVE-2014-4806 The installation process in IBM Security AppScan Enterprise 8.x before 8.6.0.2 iFix 003, 8.7.x before 8.7.0.1 iFix 003, 8.8.x before 8.8.0.1 iFix 002… Security Appscan 8.6.0.2 / 8.7.0.1+ Fix from $1,6002014-08-29 HIGH 8.8 CVE-2014-1812 KEVEPSS 65% The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Window… Windows 7 Patch available Fix from $1,9502014-05-14 MEDIUM 6.9 CVE-2014-0755 Rockwell Automation RSLogix 5000 7 through 20.01, and 21.0, does not properly implement password protection for .ACD files (aka project files), which… Rslogix 5000 Design And Configuration Software Mitigation only Fix from $1,6002014-02-05 MEDIUM 6.5 CVE-2013-4222 OpenStack Identity (Keystone) Folsom, Grizzly 2013.1.3 and earlier, and Havana before havana-3 does not properly revoke user tokens when a tenant is … Fedora after 2013.1.3 Fix from $1,6002013-09-30 MEDIUM 5.0 CVE-2012-3025 The default configuration of Tridium Niagara AX Framework through 3.6 uses a cleartext base64 format for transmission of credentials in cookies, whic… Niagara Ax after 3.6 Fix from $1,6002012-08-16 HIGH 7.8 CVE-2012-4028 Tridium Niagara AX Framework does not properly store credential data, which allows context-dependent attackers to bypass intended access restrictions… Niagara Ax Mitigation only Fix from $1,9502012-07-16 CRITICAL 9.8 CVE-2007-0681EPSS 5% profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without providing the original password, … Extcalendar after 2 Fix from $2,3002007-02-03 CRITICAL 9.8 CVE-2005-3435 admin_news.php in Archilles Newsworld up to 1.3.0 allows attackers to bypass authentication by obtaining the password hash for another user, for exam… Newsworld after 1.3.0 Fix from $2,3002005-11-02 CRITICAL 9.8 CVE-2000-0944EPSS 11% CGI Script Center News Update 1.1 does not properly validate the original news administration password during a password change operation, which allo… Script Center News Update No fix yet Fix from $2,3002000-12-19 HIGH 8.4 CVE-1999-0013 Stolen credentials from SSH clients via ssh-agent program, allowing other local users to access remote accounts belonging to the ssh-agent user. Ssh Mitigation only Fix from $1,9501998-01-22