Skip to main content

CWE archive

CWE-522 CVEs

Programmatic archive

1,430 CVEs tagged with CWE-522223 Critical, 496 High, 659 Medium, 50 Low, 2 Unrated.

CVE-2017-9557

Published Jun 12, 2017

register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1 allows remote attackers to discover passwords by sending the username parameter in conjunction with an empty pass…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-8837

Published Jun 5, 2017

Cleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093.…

CVSS 9.8 · Critical

CVE-2017-7913

Published May 29, 2017

A Plaintext Storage of a Password issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3110-HSDPA Version 1.2 Build 09123015 an…

CVSS 9.8 · Critical

CVE-2017-7486

Published May 12, 2017

PostgreSQL versions 8.4 - 9.6 are vulnerable to information leak in pg_user_mappings view which discloses foreign server passwords to any user having USAGE privilege on the associ…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2017-6528

Published Mar 9, 2017

An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is affected by plaintext password storage (the /home/dna/spool/.pfile file).

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5140

Published Feb 13, 2017

An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. Password is stored in clear text.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-5139

Published Feb 13, 2017

An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. Any user is able to disclose a password…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-9360

Published Feb 13, 2017

An issue was discovered in General Electric (GE) Proficy HMI/SCADA iFIX Version 5.8 SIM 13 and prior versions, Proficy HMI/SCADA CIMPLICITY Version 9.0 and prior versions, and Pro…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5013

Published Feb 8, 2017

The IBM Security Access Manager appliance includes configuration files that contain obfuscated plaintext-passwords which authenticated users can access.

CVSS 5.5 · Medium

CVE-2015-5955

Published Oct 29, 2015

ownCloud iOS app before 3.4.4 does not properly switch state between multiple instances, which might allow remote instance administrators to obtain sensitive credential and cookie…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4806

Published Aug 29, 2014

The installation process in IBM Security AppScan Enterprise 8.x before 8.6.0.2 iFix 003, 8.7.x before 8.7.0.1 iFix 003, 8.8.x before 8.8.0.1 iFix 002, and 9.0.x before 9.0.0.1 iFi…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5627

Published Oct 1, 2013

Oracle MySQL and MariaDB 5.5.x before 5.5.29, 5.3.x before 5.3.12, and 5.2.x before 5.2.14 does not modify the salt during multiple executions of the change_user command within th…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4869

Published Jul 18, 2013

Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(2) and the IM & Presence Service in Cisco Unified Presence Server through 9.1(2) use the same CTI and database-encry…

CVSS 0.0 · Unrated
Vendor/product tagsBeta · best-effort

CVE-2012-3268

Published Feb 1, 2013

Certain HP Access Controller, Fabric Module, Firewall, Router, Switch, and UTM Appliance products; certain HP 3Com Access Controller, Router, and Switch products; certain HP H3C A…

CVSS 3.5 · Low
Showing 1,401-1,425 of 1,430 CVEsPage 57 of 58