Vulnerability index

Browse CVEs

1,244 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
HIGH 7.5 CVE-2025-40838 Ericsson Indoor Connect 8855 contains a vulnerability where server-side security can be bypassed in the client which if exploited can lead to unautho… Indoor Connect 8855 Firmware 2025.q2+ Fix from $1,9502025-09-25 MEDIUM 6.9 CVE-2025-10360 In Puppet Enterprise versions 2025.4.0 and 2025.5, the encryption key used for encrypting content in the Infra Assistant database was not excluded fr… Mitigation only Fix from $1,6002025-09-24 MEDIUM 5.3 CVE-2025-54467 When a Java command with password parameters is executed and terminated by NeuVector for Process rule violation the password will appear in the NeuVe… Mitigation only Fix from $1,6002025-09-17 CRITICAL 9.8 CVE-2025-23342 The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to gain access to a privileged account . A successful exploit of this vulner… Nvdebug 1.7.0+ Fix from $2,3002025-09-09 HIGH 8.8 CVE-2025-42933 When a user logs in via SAP Business One native client, the SLD backend service fails to enforce proper encryption of certain APIs. This leads to exp… Mitigation only Fix from $1,9502025-09-09 HIGH 8.8 CVE-2025-41682 An authenticated, low-privileged attacker can obtain credentials stored on the charge controller including the manufacturer password. Mitigation only Fix from $1,9502025-09-08 CRITICAL 9.4 CVE-2025-58366 Onyxia is a data science environment for kubernetes. In versions 4.6.0 through 4.8.0, Onyxia-API leaked the credentials of private helm repositories … Patch available Fix from $2,3002025-09-05 MEDIUM 5.1 CVE-2025-55739 api is a module for FreePBX@, which is an open source GUI that controls and manages Asterisk© (PBX). In versions lower than 15.0.13, 16.0.2 through 1… Patch available Fix from $1,6002025-09-05 MEDIUM 6.9 CVE-2025-57806 Local Deep Research is an AI-powered research assistant for deep, iterative research. Versions 0.2.0 through 0.6.7 stored confidential information, i… Patch available Fix from $1,6002025-09-03 CRITICAL 9.8 CVE-2025-6519 E3 Site Supervisor (firmware version < 2.31F01) has a default admin user "ONEDAY" with a daily generated password. An attacker can predictably genera… E3 Supervisory Controller Firmware 2.31f01+ Fix from $2,3002025-09-02 CRITICAL 9.8 CVE-2025-52549 E3 Site Supervisor Control (firmware version < 2.31F01) generates the root linux password on each boot. An attacker can generate the root linux passw… E3 Supervisory Controller Firmware 2.31f01+ Fix from $2,3002025-09-02 HIGH 7.5 CVE-2025-52545 E3 Site Supervisor Control (firmware version < 2.31F01) RCI service contains an API call to read users info, which returns all usernames and password… E3 Supervisory Controller Firmware 2.31f01+ Fix from $1,9502025-09-02 CRITICAL 9.8 CVE-2025-52095 An issue in PDQ Smart Deploy V.3.0.2040 allows an attacker to escalate privileges via the Credential encryption routines in SDCommon.dll Smart Deploy 3.0.2046+ Fix from $2,3002025-08-22 CRITICAL 9.8 CVE-2025-55306 GenX_FX is an advance IA trading platform that will focus on forex trading. A vulnerability was identified in the GenX FX backend where API keys and … Mitigation only Fix from $2,3002025-08-19 HIGH 7.5 CVE-2025-54156 The Sante PACS Server Web Portal sends credential information without encryption. Sante Pacs Server 4.2.3+ Fix from $1,9502025-08-18 HIGH 7.8 CVE-2025-40751 A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.3). Affected SIMATIC RTLS Locating Manager Report Clients do … Simatic Rtls Locating Manager 3.3+ Fix from $1,9502025-08-12 HIGH 7.8 CVE-2025-48709 BMC Control-M/Server 9.0.21.300 displays cleartext database credentials in process lists and logs. An authenticated attacker with shell access could … Control M\/server Mitigation only Fix from $1,9502025-08-07 MEDIUM 5.3 CVE-2025-54394 Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 has Insufficiently Protected Credentials for requests to remote Ex… Directory Manager 11.1.25162.02+ Fix from $1,6002025-08-07 HIGH 7.1 CVE-2025-54882 Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. In versions 0.8.0 through 0.9.21 and 1.0.0-beta through 1.1.0, Himme… Himmelblau 0.9.22 / 1.2.0+ Fix from $1,9502025-08-07 MEDIUM 6.9 CVE-2025-54876 The Janssen Project is an open-source identity and access management (IAM) platform. In versions 1.9.0 and below, Janssen stores passwords in plainte… Patch available Fix from $1,6002025-08-06 MEDIUM 5.3 CVE-2025-38739 Dell Digital Delivery, versions prior to 5.6.1.0, contains an Insufficiently Protected Credentials vulnerability. A remote unauthenticated attacker c… Digital Delivery 5.6.1.0+ Fix from $1,6002025-08-04 MEDIUM 6.5 CVE-2025-53008 GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features,… Glpi 10.0.19+ Fix from $1,6002025-07-30 MEDIUM 5.5 CVE-2025-54422 Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. In versions 1.16.1 and below, a critical se… Sandboxie 1.16.2+ Fix from $1,6002025-07-29 CRITICAL 9.8 CVE-2025-54428 RevelaCode is an AI-powered faith-tech project that decodes biblical verses, prophecies and global events into accessible language. In versions below… Patch available Fix from $2,3002025-07-28 MEDIUM 6.5 CVE-2025-54380 Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to version 17.6, Opencast would inco… Opencast 17.6+ Fix from $1,6002025-07-26 HIGH 8.7 CVE-2025-34139 A vulnerability exists in Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud that could allow an… Mitigation only Fix from $1,9502025-07-25 HIGH 7.5 CVE-2025-7565 A vulnerability, which was classified as critical, was found in LB-LINK BL-AC3600 up to 1.0.22. This affects the function geteasycfg of the file /cgi… Bl Ac3600 Firmware after 1.0.22 Fix from $1,9502025-07-14 MEDIUM 5.3 CVE-2025-53743 Jenkins Applitools Eyes Plugin 1.16.5 and earlier does not mask Applitools API keys displayed on the job configuration form, increasing the potential… Applitools Eyes 1.16.6+ Fix from $1,6002025-07-09 MEDIUM 5.3 CVE-2025-53667 Jenkins Dead Man's Snitch Plugin 0.1 does not mask Dead Man's Snitch tokens displayed on the job configuration form, increasing the potential for att… Dead Man\'s Snitch Mitigation only Fix from $1,6002025-07-09 MEDIUM 6.5 CVE-2025-53671 Jenkins Nouvola DiveCloud Plugin 1.08 and earlier does not mask DiveCloud API Keys and Credentials Encryption Keys displayed on the job configuration… Nouvola Divecloud after 1.08 Fix from $1,6002025-07-09