Vulnerability index

Browse CVEs

1,244 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
HIGH 7.1 CVE-2025-1886 Pass-Back vulnerability in versions prior to 2025.35.000 of Sage 200 Spain. This vulnerability allows an authenticated attacker with administrator pr… Mitigation only Fix from $1,9502025-03-07 CRITICAL 10.0 CVE-2024-12799 Insufficiently Protected Credentials vulnerability in OpenText Identity Manager Advanced Edition on Windows, Linux, 64 bit allows Privilege Abuse. Th… Mitigation only Fix from $2,3002025-03-05 CRITICAL 9.8 CVE-2025-27648 Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.913 Application 20.0.2253 allows Cross Tenant Password Exposure V-2024-003. Vasion Print 20.0.2253 / 22.0.913+ Fix from $2,3002025-03-05 CRITICAL 9.8 CVE-2025-27650 Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Private Keys in Docker Overlay V-2023-013. Vasion Print 20.0.2014 / 22.0.862+ Fix from $2,3002025-03-05 HIGH 7.5 CVE-2024-41771 IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a remote attacker to download temporary files which could expose… Engineering Requirements Management Doors Next Mitigation only Fix from $1,9502025-03-03 HIGH 7.5 CVE-2024-41770 IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a remote attacker to download temporary files which could expose… Engineering Requirements Management Doors Next Mitigation only Fix from $1,9502025-03-03 MEDIUM 6.8 CVE-2024-44754 Cryptographic key extraction from internal flash in Minut M2 with firmware version #15142 allows physically proximate attackers to inject modified fi… Mitigation only Fix from $1,6002025-02-28 HIGH 8.8 CVE-2024-38291 In XIQ-SE before 24.2.11, a low-privileged user may be able to access admin passwords, which could lead to privilege escalation. Xiq Se 24.2.11+ Fix from $1,9502025-02-27 CRITICAL 9.8 CVE-2025-25570 Vue Vben Admin 2.10.1 allows unauthorized login to the backend due to an issue with hardcoded credentials. Mitigation only Fix from $2,3002025-02-27 MEDIUM 6.3 CVE-2024-37362 The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or re… Mitigation only Fix from $1,6002025-02-20 CRITICAL 9.9 CVE-2025-0867 The standard user uses the run as function to start the MEAC applications with administrative privileges. To ensure that the system can startup on it… Mitigation only Fix from $2,3002025-02-14 CRITICAL 9.1 CVE-2025-26492 In JetBrains TeamCity before 2024.12.2 improper Kubernetes connection settings could expose sensitive resources Teamcity 2024.12.2+ Fix from $2,3002025-02-11 MEDIUM 6.5 CVE-2024-43779 An information disclosure vulnerability exists in the Vault API functionality of ClearML Enterprise Server 3.22.5-1533. A specially crafted HTTP requ… Clearml Enterprise Server No fix yet Fix from $1,6002025-02-06 CRITICAL 9.8 CVE-2025-0890EPSS 14% **UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAF… Vmg4325 B10a Firmware Mitigation only Fix from $2,3002025-02-04 HIGH 7.6 CVE-2024-12511 With address book access, SMB/FTP settings could be modified, redirecting scans and possibly capturing credentials. This requires enabled scan functi… Mitigation only Fix from $1,9502025-02-03 CRITICAL 9.8 CVE-2025-0498 A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists du… Factorytalk Assetcentre 15.00.01+ Fix from $2,3002025-01-30 CRITICAL 9.8 CVE-2025-0497 A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists du… Factorytalk Assetcentre 15.00.01+ Fix from $2,3002025-01-30 CRITICAL 9.8 CVE-2025-0477 An encryption vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due … Factorytalk Assetcentre 15.00.01+ Fix from $2,3002025-01-30 CRITICAL 9.8 CVE-2024-57395 Password Vulnerability in Safety production process management system v1.0 allows a remote attacker to escalate privileges, execute arbitrary code an… Mitigation only Fix from $2,3002025-01-29 HIGH 7.5 CVE-2024-23733 The /WmAdmin/,/invoke/vm.server/login login page in the Integration Server in Software AG webMethods 10.15.0 before Core_Fix7 allows remote attackers… Mitigation only Fix from $1,9502025-01-29 MEDIUM 5.5 CVE-2023-50945 IBM Common Licensing 9.0 stores user credentials in plain clear text which can be read by a local user. Common Licensing Mitigation only Fix from $1,6002025-01-26 MEDIUM 5.7 CVE-2024-42012 GRAU DATA Blocky before 3.1 stores passwords encrypted rather than hashed. At the login screen, the user's password is compared to the user's decrypt… Mitigation only Fix from $1,6002025-01-22 MEDIUM 6.6 CVE-2025-23040 GitHub Desktop is an open-source Electron-based GitHub app designed for git development. An attacker convincing a user to clone a repository directly… Mitigation only Fix from $1,6002025-01-15 HIGH 7.2 CVE-2024-46480 An NTLM hash leak in Venki Supravizio BPM up to 18.0.1 allows authenticated attackers with Application Administrator access to escalate privileges on… Supravizio Bpm after 18.0.1 Fix from $1,9502025-01-13 CRITICAL 9.8 CVE-2024-42172 HCL MyXalytics is affected by broken authentication. It allows attackers to compromise keys, passwords, and session tokens, potentially leading to i… Dryice Myxalytics Mitigation only Fix from $2,3002025-01-11 MEDIUM 5.5 CVE-2024-54471 This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A … macOS 13.7.1 / 14.7.1+ Fix from $1,6002024-12-12 MEDIUM 6.7 CVE-2024-53292 Dell VxVerify, versions prior to x.40.405, contain a Plain-text Password Storage Vulnerability in the shell wrapper. A local high privileged attacker… Vxrail Hyperconverged Infrastructure Mitigation only Fix from $1,6002024-12-11 HIGH 8.0 CVE-2024-46341 TP-Link TL-WR845N(UN)_V4_190219 was discovered to transmit credentials in base64 encoded form, which can be easily decoded by an attacker executing a… Tl Wr845n Firmware Mitigation only Fix from $1,9502024-12-10 HIGH 8.0 CVE-2024-50699 TP-Link TL-WR845N(UN)_V4_201214, TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 were discovered to contain weak default credentials for the Admi… Tl Wr845n Firmware No fix yet Fix from $1,9502024-12-10 CRITICAL 9.1 CVE-2024-40583 Pentaminds CuroVMS v2.0.1 was discovered to contain exposed credentials. Curovms No fix yet Fix from $2,3002024-12-09