Vulnerabilities (CVE)

Filtered by CWE-522
Total 1230 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-26567 1 Sangoma 1 Freepbx Linux 7 2025-02-03 N/A 8.1 HIGH
Sangoma FreePBX 1805 through 2302 (when obtained as a ,.ISO file) places AMPDBUSER, AMPDBPASS, AMPMGRUSER, and AMPMGRPASS in the list of global variables. This exposes cleartext authentication credentials for the Asterisk Database (MariaDB/MySQL) and Asterisk Manager Interface. For example, an attacker can make a /ari/asterisk/variable?variable=AMPDBPASS API call.
CVE-2023-28090 1 Hp 1 Oneview 2025-02-03 N/A 5.5 MEDIUM
An HPE OneView appliance dump may expose SNMPv3 read credentials
CVE-2023-28089 1 Hp 1 Oneview 2025-02-03 N/A 7.1 HIGH
An HPE OneView appliance dump may expose FTP credentials for c7000 Interconnect Modules
CVE-2023-28088 1 Hp 1 Oneview 2025-02-03 N/A 7.8 HIGH
An HPE OneView appliance dump may expose SAN switch administrative credentials
CVE-2023-28084 2 Hp, Hpe 2 Oneview, Oneview Global Dashboard 2025-02-03 N/A 5.5 MEDIUM
HPE OneView and HPE OneView Global Dashboard appliance dumps may expose authentication tokens
CVE-2024-57395 2025-01-31 N/A 9.8 CRITICAL
Password Vulnerability in Safety production process management system v1.0 allows a remote attacker to escalate privileges, execute arbitrary code and obtain sensitive information via the password and account number parameters.
CVE-2024-23733 2025-01-31 N/A 7.5 HIGH
The /WmAdmin/,/invoke/vm.server/login login page in the Integration Server in Software AG webMethods 10.15.0 before Core_Fix7 allows remote attackers to reach the administration panel and discover hostname and version information by sending an arbitrary username and a blank password to the /WmAdmin/#/login/ URI.
CVE-2023-24506 1 Milesight 2 Ncr\/camera, Ncr\/camera Firmware 2025-01-29 N/A 7.5 HIGH
Milesight NCR/camera version 71.8.0.6-r5 exposes credentials through an unspecified request.
CVE-2024-28971 1 Dell 1 Openmanage Enterprise Update Manager 2025-01-27 N/A 3.5 LOW
Dell Update Manager Plugin, versions 1.4.0 through 1.5.0, contains a Plain-text Password Storage Vulnerability in Log file. A remote high privileged attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.
CVE-2022-47880 1 Jedox 2 Jedox, Jedox Cloud 2025-01-27 N/A 5.3 MEDIUM
An Information disclosure vulnerability in /be/rpc.php in Jedox GmbH Jedox 2020.2.5 allow remote, authenticated users with permissions to modify database connections to disclose a connections' cleartext password via the 'test connection' function.
CVE-2025-21111 1 Dell 84 Vxrail D560, Vxrail D560 Firmware, Vxrail D560f and 81 more 2025-01-24 N/A 7.5 HIGH
Dell VxRail, versions 8.0.000 through 8.0.311, contain(s) a Plaintext Storage of a Password vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.
CVE-2025-21102 1 Dell 84 Vxrail D560, Vxrail D560 Firmware, Vxrail D560f and 81 more 2025-01-24 N/A 7.5 HIGH
Dell VxRail, versions 7.0.000 through 7.0.532, contain(s) a Plaintext Storage of a Password vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.
CVE-2023-32988 1 Jenkins 1 Azure Vm Agents 2025-01-23 N/A 4.3 MEDIUM
A missing permission check in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
CVE-2023-4538 1 Comarch 1 Erp Xl 2025-01-23 N/A 6.2 MEDIUM
The database access credentials configured during installation are stored in a special table, and are encrypted with a shared key, same among all Comarch ERP XL client installations. This could allow an attacker with access to that table to retrieve plain text passwords. This issue affects ERP XL: from 2020.2.2 through 2023.2.
CVE-2023-33000 1 Jenkins 1 Ns-nd Integration Performance Publisher 2025-01-23 N/A 7.5 HIGH
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.149 and earlier does not mask credentials displayed on the configuration form, increasing the potential for attackers to observe and capture them.
CVE-2023-33263 1 Wftpd Project 1 Wftpd 2025-01-16 N/A 7.5 HIGH
In WFTPD 3.25, usernames and password hashes are stored in an openly viewable wftpd.ini configuration file within the WFTPD directory. NOTE: this is a product from 2006.
CVE-2025-23040 2025-01-15 N/A 6.6 MEDIUM
GitHub Desktop is an open-source Electron-based GitHub app designed for git development. An attacker convincing a user to clone a repository directly or through a submodule can allow the attacker access to the user's credentials through the use of maliciously crafted remote URL. GitHub Desktop relies on Git to perform all network related operations (such as cloning, fetching, and pushing). When a user attempts to clone a repository GitHub Desktop will invoke `git clone` and when Git encounters a remote which requires authentication it will request the credentials for that remote host from GitHub Desktop using the git-credential protocol. Using a maliciously crafted URL it's possible to cause the credential request coming from Git to be misinterpreted by Github Desktop such that it will send credentials for a different host than the host that Git is currently communicating with thereby allowing for secret exfiltration. GitHub username and OAuth token, or credentials for other Git remote hosts stored in GitHub Desktop could be improperly transmitted to an unrelated host. Users should update to GitHub Desktop 3.4.12 or greater which fixes this vulnerability. Users who suspect they may be affected should revoke any relevant credentials.
CVE-2024-22345 1 Ibm 1 Txseries For Multiplatform 2025-01-14 N/A 6.2 MEDIUM
IBM TXSeries for Multiplatforms 8.2 transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. IBM X-Force ID: 280192.
CVE-2023-25740 1 Mozilla 1 Firefox 2025-01-09 N/A 8.8 HIGH
After downloading a Windows <code>.scf</code> script from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials to the resource.<br>*This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 110.
CVE-2024-29992 1 Microsoft 1 Azure Identity Library For .net 2025-01-09 N/A 5.5 MEDIUM
Azure Identity Library for .NET Information Disclosure Vulnerability