Skip to main content

CWE archive

CWE-522 CVEs

Programmatic archive

1,394 CVEs tagged with CWE-522217 Critical, 485 High, 645 Medium, 45 Low, 2 Unrated.

CVE-2018-9280

Published Oct 24, 2018

An issue was discovered on Eaton UPS 9PX 8000 SP devices. The appliance discloses the SNMP version 3 user's password. The web page displayed by the appliance contains the password…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-9279

Published Oct 24, 2018

An issue was discovered on Eaton UPS 9PX 8000 SP devices. The appliance discloses the user's password. The web page displayed by the appliance contains the password in cleartext.…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-11079

Published Oct 18, 2018

Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains a Plaintext Password Storage vulnerability. Database credentials are stored in plaintext in a configuration…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-12383

Published Oct 18, 2018

If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored pass…

CVSS 5.5 · Medium

CVE-2018-10824

Published Oct 17, 2018

An issue was discovered on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L through 1.02, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 thr…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2017-1231

Published Oct 12, 2018

IBM BigFix Platform 9.5 - 9.5.9 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 123910.

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-13789

Published Oct 10, 2018

An issue was discovered in Descor Infocad FM before 3.1.0.0. An unauthenticated web service allows the retrieval of files on the web server and on reachable SMB servers.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11752

Published Oct 2, 2018

Previous releases of the Puppet cisco_ios module output SSH session debug information including login credentials to a world readable file on every run. These issues have been res…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-11748

Published Oct 2, 2018

Previous releases of the Puppet device_manager module creates configuration files containing credentials that are world readable. This issue has been resolved as of device_manager…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-16984

Published Oct 2, 2018

An issue was discovered in Django 2.1 before 2.1.2, in which unprivileged users can read the password hashes of arbitrary accounts. The read-only password widget used by the Djang…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1498

Published Oct 2, 2018

IBM Security Guardium EcoSystem 10.5 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 141223.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-17613

Published Sep 28, 2018

Telegram Desktop (aka tdesktop) 1.3.16 alpha, when "Use proxy" is enabled, sends credentials and application data in cleartext over the SOCKS5 protocol.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-16669

Published Sep 18, 2018

An issue was discovered in CIRCONTROL Open Charge Point Protocol (OCPP) before 1.5.0, as used in CirCarLife, PowerStudio, and other products. Due to storage of credentials in XML…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-16987

Published Sep 13, 2018

Squash TM through 1.18.0 presents the cleartext passwords of external services in the administration panel, as demonstrated by a ta-server-password field in the HTML source code.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2018-13822

Published Aug 30, 2018

Unprotected storage of credentials in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows attackers to access sensitive information.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1,251-1,275 of 1,394 CVEsPage 51 of 56