Skip to main content

CWE archive

CWE-522 CVEs

Programmatic archive

1,394 CVEs tagged with CWE-522217 Critical, 485 High, 645 Medium, 45 Low, 2 Unrated.

CVE-2018-11050

Published Aug 1, 2018

Dell EMC NetWorker versions between 9.0 and 9.1.1.8 through 9.2.1.3, and the version 18.1.0.1 contain a Clear-Text authentication over network vulnerability in the Rabbit MQ Advan…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-5543

Published Jul 31, 2018

The F5 BIG-IP Controller for Kubernetes 1.0.0-1.5.0 (k8s-bigip-crtl) passes BIG-IP username and password as command line parameters, which may lead to disclosure of the credential…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000404

Published Jul 9, 2018

Jenkins project Jenkins AWS CodeBuild Plugin version 0.26 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSClientFactory.java, CodeBuilder.java that…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000403

Published Jul 9, 2018

Jenkins project Jenkins AWS CodeDeploy Plugin version 1.19 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSCodeDeployPublisher.java that can result…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000401

Published Jul 9, 2018

Jenkins project Jenkins AWS CodePipeline Plugin version 0.36 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSCodePipelineSCM.java that can result i…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-2665

Published Jul 6, 2018

The skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /etc/skyring/skyring.conf file which is owned by root but re…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-11639

Published Jul 3, 2018

Plaintext Storage of Passwords within Cookies in /var/www/xms/application/controllers/verifyLogin.php in the administrative console in Dialogic PowerMedia XMS before 3.5 SU2 allow…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11634

Published Jul 3, 2018

Plaintext Storage of Passwords in the administrative console in Dialogic PowerMedia XMS before 3.5 SU2 allows local users to access the web application's user passwords in clearte…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11746

Published Jul 3, 2018

In Puppet Discovery prior to 1.2.0, when running Discovery against Windows hosts, WinRM connections can fall back to using basic auth over insecure channels if a HTTPS server is n…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2017-16718

Published Jun 27, 2018

Beckhoff TwinCAT 3 supports communication over ADS. ADS is a protocol for industrial automation in protected environments. This protocol uses user configured routes, that can be e…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000610

Published Jun 26, 2018

A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in DataBoundConfigurator.java, Attribute.java, BaseConfigura…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000608

Published Jun 26, 2018

A exposure of sensitive information vulnerability exists in Jenkins z/OS Connector Plugin 1.2.6.1 and earlier in SCLMSCM.java that allows an attacker with local file system access…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1075

Published Jun 12, 2018

ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one chooses to provision the database…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0335

Published Jun 7, 2018

A vulnerability in the web portal authentication process of Cisco Prime Collaboration Provisioning could allow an unauthenticated, local attacker to view sensitive data. The vulne…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7933

Published Jun 6, 2018

In ABB IP GATEWAY 3.39 and prior, some configuration files contain passwords stored in plain-text, which may allow an attacker to gain unauthorized access.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-11544

Published May 29, 2018

The Olive Tree Ftp Server application 1.32 for Android has Insecure Data Storage because a username and password are stored in the /data/data/com.theolivetree.ftpserver/shared_pre…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1,276-1,300 of 1,394 CVEsPage 52 of 56