CVE & Exploit Intelligence Database

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,563 researchers
1,290 results Clear all
CVE-2022-20914 4.9 MEDIUM EPSS 0.00
Cisco Identity Services Engine - Insufficiently Protected Credentials
A vulnerability in the External RESTful Services (ERS) API of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker to obtain sensitive information. This vulnerability is due to excessive verbosity in a specific REST API output. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to obtain sensitive information, including administrative credentials for an external authentication server. Note: To successfully exploit this vulnerability, the attacker must have valid ERS administrative credentials.
CWE-549 Aug 10, 2022
CVE-2022-33169 6.5 MEDIUM EPSS 0.00
IBM Robotic Process Automation <21.0.3 - Info Disclosure
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to insufficiently protected credentials for users created via a bulk upload. IBM X-Force ID: 228888.
CWE-522 Aug 01, 2022
CVE-2021-27785 3.9 LOW EPSS 0.00
HCL Commerce - Info Disclosure
HCL Commerce's Remote Store server could allow a local attacker to obtain sensitive personal information. The vulnerability requires the victim to first perform a particular operation on the website.
CWE-522 Jul 30, 2022
CVE-2021-22640 7.5 HIGH EPSS 0.00
Ovarro TBox - Info Disclosure
An attacker can decrypt the Ovarro TBox login password by communication capture and brute force attacks.
CWE-522 Jul 28, 2022
CVE-2022-36901 6.5 MEDIUM EPSS 0.00
Jenkins HTTP Request < 1.15 - Insufficiently Protected Credentials
Jenkins HTTP Request Plugin 1.15 and earlier stores HTTP Request passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
CWE-522 Jul 27, 2022
CVE-2022-1766 7.5 HIGH EPSS 0.00
Anchore < 4.0.1 - Insufficiently Protected Credentials
Anchore Enterprise anchorectl version 0.1.4 improperly stored credentials when generating a Software Bill of Materials. anchorectl will add the credentials used to access Anchore Enterprise API in the Software Bill of Materials (SBOM) generated by anchorectl. Users of anchorectl version 0.1.4 should upgrade to anchorectl version 0.1.5 to resolve this issue.
CWE-522 Jul 20, 2022
CVE-2022-27544 5.0 MEDIUM EPSS 0.00
Hcltech Bigfix Platform - Insufficiently Protected Credentials
BigFix Web Reports authorized users may see SMTP credentials in clear text.
CWE-522 Jul 19, 2022
CVE-2022-22998 8.0 HIGH EPSS 0.00
Westerndigital MY Cloud Home Duo Firm... - Insufficiently Protected Credentials
Implemented protections on AWS credentials that were not properly protected.
CWE-522 Jul 12, 2022
CVE-2022-1794 5.5 MEDIUM EPSS 0.00
CODESYS OPC DA Server <V3.5.18.20 - Info Disclosure
The CODESYS OPC DA Server prior V3.5.18.20 stores PLC passwords as plain text in its configuration file so that it is visible to all authorized Microsoft Windows users of the system.
CWE-522 Jul 11, 2022
CVE-2022-35411 9.8 CRITICAL 5 PoCs Analysis EPSS 0.71
Rpc.py < 0.6.0 - Insufficiently Protected Credentials
rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header is sent. In other words, although JSON (not Pickle) is the default data format, an unauthenticated client can cause the data to be processed with unpickle.
CWE-522 Jul 08, 2022
CVE-2022-27548 4.9 MEDIUM EPSS 0.00
HCL Launch - Info Disclosure
HCL Launch stores user credentials in plain clear text which can be read by a local user.
CWE-522 Jul 06, 2022
CVE-2022-23725 7.7 HIGH EPSS 0.00
Pingidentity Pingid Integration For W... - Insufficiently Protected Credentials
PingID Windows Login prior to 2.8 does not properly set permissions on the Windows Registry entries used to store sensitive API keys under some circumstances.
CWE-522 Jun 30, 2022
CVE-2022-34816 6.5 MEDIUM EPSS 0.01
Jenkins Hpe Network Virtualization - Insufficiently Protected Crede...
Jenkins HPE Network Virtualization Plugin 1.0 stores passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
CWE-522 Jun 30, 2022
CVE-2022-34809 6.5 MEDIUM EPSS 0.01
Jenkins Rqm < 2.8 - Insufficiently Protected Credentials
Jenkins RQM Plugin 2.8 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
CWE-522 Jun 30, 2022
CVE-2022-34808 4.3 MEDIUM EPSS 0.01
Jenkins Cisco Spark < 1.1.1 - Insufficiently Protected Credentials
Jenkins Cisco Spark Plugin 1.1.1 and earlier stores bearer tokens unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
CWE-522 Jun 30, 2022
CVE-2022-34807 6.5 MEDIUM EPSS 0.01
Jenkins Elasticsearch Query - Insufficiently Protected Credentials
Jenkins Elasticsearch Query Plugin 1.2 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
CWE-522 Jun 30, 2022
CVE-2022-34806 6.5 MEDIUM EPSS 0.01
Jenkins Jigomerge < 0.9 - Insufficiently Protected Credentials
Jenkins Jigomerge Plugin 0.9 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.
CWE-522 Jun 30, 2022
CVE-2022-34805 6.5 MEDIUM EPSS 0.01
Jenkins Skype Notifier < 1.1.0 - Insufficiently Protected Credentials
Jenkins Skype notifier Plugin 1.1.0 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
CWE-522 Jun 30, 2022
CVE-2022-34803 4.3 MEDIUM EPSS 0.01
Jenkins Opsgenie < 1.9 - Insufficiently Protected Credentials
Jenkins OpsGenie Plugin 1.9 and earlier stores API keys unencrypted in its global configuration file and in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission (config.xml), or access to the Jenkins controller file system.
CWE-522 Jun 30, 2022
CVE-2022-34802 4.3 MEDIUM EPSS 0.00
Jenkins Rocketchat Notifier - Insufficiently Protected Credentials
Jenkins RocketChat Notifier Plugin 1.5.2 and earlier stores the login password and webhook token unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
CWE-522 Jun 30, 2022