Vulnerability index

Browse CVEs

1,244 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
HIGH 7.3 CVE-2025-53650 Jenkins Credentials Binding Plugin 687.v619cb_15e923f and earlier does not properly mask (i.e., replace with asterisks) credentials present in except… Credentials Binding after 687.689.v1a_f775332fc Fix from $1,9502025-07-09 MEDIUM 6.5 CVE-2025-53654 Jenkins Statistics Gatherer Plugin 2.0.3 and earlier stores the AWS Secret Key unencrypted in its global configuration file on the Jenkins controller… Statistics Gatherer after 2.0.3 Fix from $1,6002025-07-09 MEDIUM 6.4 CVE-2025-24508 Extraction of Account Connectivity Credentials (ACCs) from the IT Management Agent secure storage Mitigation only Fix from $1,6002025-07-07 HIGH 7.8 CVE-2025-34078 A local privilege escalation vulnerability exists in NSClient++ 0.5.2.35 when both the web interface and ExternalScripts features are enabled. The co… Nsclient\+\+ No fix yet Fix from $1,9502025-07-02 MEDIUM 5.7 CVE-2025-34062 An information disclosure vulnerability exists in OneLogin AD Connector versions prior to 6.1.5 via the /api/adc/v4/configuration endpoint. An attack… Mitigation only Fix from $1,6002025-07-01 MEDIUM 6.8 CVE-2025-6081 Insufficiently Protected Credentials in LDAP in Konica Minolta bizhub 227 Multifunction printers version GCQ-Y3 or earlier allows an attacker can rec… Mitigation only Fix from $1,6002025-07-01 HIGH 8.1 CVE-2024-49364 tiny-secp256k1 is a tiny secp256k1 native/JS wrapper. Prior to version 1.1.7, a private key can be extracted on signing a malicious JSON-stringifiabl… Patch available Fix from $1,9502025-07-01 MEDIUM 6.8 CVE-2024-51984 An authenticated attacker can reconfigure the target device to use an external service (such as LDAP or FTP) controlled by the attacker. If an existi… Mitigation only Fix from $1,6002025-06-25 MEDIUM 5.3 CVE-2025-6526 A vulnerability, which was classified as problematic, has been found in 70mai M300 up to 20250611. This issue affects some unknown processing of the … M300 Firmware after 2025-06-11 Fix from $1,6002025-06-23 MEDIUM 5.5 CVE-2025-35941 A password is exposed locally. No fix yet Fix from $1,6002025-06-11 HIGH 7.5 CVE-2025-30183 CyberData 011209 Intercom does not properly store or protect web server admin credentials. 011209 Sip Emergency Intercom Firmware 22.0.1+ Fix from $1,9502025-06-09 MEDIUM 5.3 CVE-2024-47081 Requests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific m… Patch available Fix from $1,6002025-06-09 MEDIUM 6.5 CVE-2025-33079 IBM Controller 11.0.0, 11.0.1, and 11.1.0 application could allow an authenticated user to obtain sensitive credentials that may be inadvertently inc… Cognos Controller Mitigation only Fix from $1,6002025-05-27 MEDIUM 6.5 CVE-2025-3480 MedDream WEB DICOM Viewer Cleartext Transmission of Credentials Information Disclosure Vulnerability. This vulnerability allows network-adjacent atta… Pacs Server Mitigation only Fix from $1,6002025-05-22 HIGH 8.7 CVE-2025-3079 A passback vulnerability which relates to office/small office multifunction printers and laser printers. No fix yet Fix from $1,9502025-05-20 HIGH 8.7 CVE-2025-3078 A passback vulnerability which relates to production printers and office multifunction printers. Mitigation only Fix from $1,9502025-05-20 MEDIUM 6.5 CVE-2025-4679 A vulnerability in Synology Active Backup for Microsoft 365 allows remote authenticated attackers to obtain sensitive information via unspecified vec… Active Backup For Microsoft 365 Mitigation only Fix from $1,6002025-05-16 HIGH 7.5 CVE-2025-33093 IBM Sterling Partner Engagement Manager 6.1.0, 6.2.0, 6.2.2 JWT secret is stored in public Helm Charts and is not stored as a Kubernetes secret. Sterling Partner Engagement Manager Mitigation only Fix from $1,9502025-05-07 HIGH 7.1 CVE-2025-46820 phpgt/Dom provides access to modern DOM APIs. Versions of phpgt/Dom prior to 4.1.8 expose the GITHUB_TOKEN in the Dom workflow run artifact. The ci.y… Patch available Fix from $1,9502025-05-06 MEDIUM 6.5 CVE-2025-2772 BEC Technologies Multiple Routers Insufficiently Protected Credentials Information Disclosure Vulnerability. This vulnerability allows network-adjace… Router Firmware Mitigation only Fix from $1,6002025-04-23 MEDIUM 6.9 CVE-2025-32963 MinIO Operator STS is a native IAM Authentication for Kubernetes. Prior to version 7.1.0, if no audiences are provided for the `spec.audiences` field… Patch available Fix from $1,6002025-04-22 HIGH 7.5 CVE-2025-28228 A credential exposure vulnerability in Electrolink 500W, 1kW, 2kW Medium DAB Transmitter Web v01.09, v01.08, v01.07, and Display v1.4, v1.2 allows un… Fm\/dab\/tv Transmitter Web Management System No fix yet Fix from $1,9502025-04-18 CRITICAL 9.3 CVE-2025-22372 Insufficiently Protected Credentials vulnerability in SicommNet BASEC on SaaS allows Password Recovery. Passwords are either stored in plain text usi… Mitigation only Fix from $2,3002025-04-14 MEDIUM 5.5 CVE-2025-26628 Insufficiently protected credentials in Azure Local Cluster allows an authorized attacker to disclose information locally. Azure Local Cluster 2411.2+ Fix from $1,6002025-04-08 HIGH 8.5 CVE-2025-2908 The exposure of credentials in the call forwarding configuration module in MeetMe products in versions prior to 2024-09 allows an attacker to gain ac… Mitigation only Fix from $1,9502025-03-28 CRITICAL 9.0 CVE-2025-2311 Incorrect Use of Privileged APIs, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in Sechard Info… Mitigation only Fix from $2,3002025-03-20 CRITICAL 9.1 CVE-2025-25650 An issue in the storage of NFC card data in Dorset DG 201 Digital Lock H5_433WBSK_v2.2_220605 allows attackers to produce cloned NFC cards to bypass … Mitigation only Fix from $2,3002025-03-17 HIGH 7.5 CVE-2025-2277 Exposure of password in web-based SSH authentication component in Devolutions Server 2024.3.13 and earlier allows a user to unadvertently leak his SS… Devolutions Server 2025.1.3.0+ Fix from $1,9502025-03-13 MEDIUM 5.3 CVE-2025-27926 In Nintex Automation 5.6 and 5.7 before 5.8, the K2 SmartForms Designer folder has configuration files (web.config) containing passwords that are rea… Automation 5.8+ Fix from $1,6002025-03-10 MEDIUM 5.3 CVE-2024-47109 IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 UI could disclosure the installation path of the server which could aid… Sterling File Gateway 6.1.2.7 / 6.2.0.4+ Fix from $1,6002025-03-10