CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,563 researchers
1,290 results Clear all
CVE-2020-2128 4.3 MEDIUM EPSS 0.00
Jenkins Ecx Copy Data Management - Insufficiently Protected Credent...
Jenkins ECX Copy Data Management Plugin 1.9 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.
CWE-522 Feb 12, 2020
CVE-2020-2127 4.3 MEDIUM EPSS 0.00
Jenkins Bmc Release Package And Deplo... - Insufficiently Protected Credentials
Jenkins BMC Release Package and Deployment Plugin 1.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
CWE-522 Feb 12, 2020
CVE-2020-2126 4.3 MEDIUM EPSS 0.00
Jenkins Digitalocean < 1.1 - Insufficiently Protected Credentials
Jenkins DigitalOcean Plugin 1.1 and earlier stores a token unencrypted in the global config.xml file on the Jenkins master where it can be viewed by users with access to the master file system.
CWE-522 Feb 12, 2020
CVE-2020-2125 4.3 MEDIUM EPSS 0.00
Jenkins Debian Package Builder - Insufficiently Protected Credentials
Jenkins Debian Package Builder Plugin 1.6.11 and earlier stores a GPG passphrase unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to the master file system.
CWE-522 Feb 12, 2020
CVE-2020-2124 4.3 MEDIUM EPSS 0.00
Jenkins Dynamic Extended Choice Param... - Insufficiently Protected Credentials
Jenkins Dynamic Extended Choice Parameter Plugin 1.0.1 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.
CWE-522 Feb 12, 2020
CVE-2020-2119 5.3 MEDIUM EPSS 0.00
Jenkins Azure AD < 1.1.2 - Insufficiently Protected Credentials
Jenkins Azure AD Plugin 1.1.2 and earlier transmits configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.
CWE-522 Feb 12, 2020
CVE-2020-2114 7.5 HIGH EPSS 0.00
Jenkins S3 Publisher < 0.11.4 - Insufficiently Protected Credentials
Jenkins S3 publisher Plugin 0.11.4 and earlier transmits configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.
CWE-522 Feb 12, 2020
CVE-2020-6969 9.8 CRITICAL EPSS 0.00
Automationdirect C-more Ea9-rhi Firmware - Insufficiently Protected...
It is possible to unmask credentials and other sensitive information on “unprotected” project files, which may allow an attacker to remotely access the C-More Touch Panels EA9 series: firmware versions prior to 6.53 and manipulate system configurations.
CWE-522 Feb 05, 2020
CVE-2013-7055 9.8 CRITICAL 1 PoC Analysis EPSS 0.49
Dlink Dir-100 Firmware - Insufficiently Protected Credentials
D-Link DIR-100 4.03B07 has PPTP and poe information disclosure
CWE-522 Feb 04, 2020
CVE-2013-7052 9.8 CRITICAL 1 PoC Analysis EPSS 0.43
Dlink Dir-100 Firmware - Insufficiently Protected Credentials
D-Link DIR-100 4.03B07: security bypass via an error in the cliget.cgi script
CWE-522 Feb 04, 2020
CVE-2013-2672 7.5 HIGH EPSS 0.01
Brother MFC-9970CDW <0D - Info Disclosure
Brother MFC-9970CDW devices with firmware 0D allow cleartext submission of passwords.
CWE-522 Feb 03, 2020
CVE-2019-19119 5.5 MEDIUM EPSS 0.00
PRTG <19.4.53 - Privilege Escalation
An issue was discovered in PRTG 7.x through 19.4.53. Due to insufficient access control on local registry keys for the Core Server Service, a non-administrative user on the local machine is able to access administrative credentials.
CWE-522 Feb 03, 2020
CVE-2013-5113 6.8 MEDIUM EPSS 0.00
LastPass <2.5.1 - Info Disclosure
LastPass prior to 2.5.1 has an insecure PIN implementation.
CWE-522 Jan 31, 2020
CVE-2020-7909 7.5 HIGH EPSS 0.00
JetBrains TeamCity <2019.1.5 - Info Disclosure
In JetBrains TeamCity before 2019.1.5, some server-stored passwords could be shown via the web UI.
CWE-522 Jan 30, 2020
CVE-2020-2107 4.3 MEDIUM EPSS 0.00
Jenkins Fortify < 19.1.29 - Insufficiently Protected Credentials
Jenkins Fortify Plugin 19.1.29 and earlier stores proxy server passwords unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
CWE-522 Jan 29, 2020
CVE-2014-3445 9.8 CRITICAL EPSS 0.04
Handsomeweb Sos Webpages - Insufficiently Protected Credentials
backup.php in HandsomeWeb SOS Webpages before 1.1.12 does not require knowledge of the cleartext password, which allows remote attackers to bypass authentication by leveraging knowledge of the administrator password hash.
CWE-522 Jan 28, 2020
CVE-2014-2581 7.5 HIGH EPSS 0.02
Smb4K <1.1.1 - Info Disclosure
Smb4K before 1.1.1 allows remote attackers to obtain credentials via vectors related to the cuid option in the "Additional options" line edit.
CWE-522 Jan 28, 2020
CVE-2019-19539 5.5 MEDIUM EPSS 0.00
Idelji Web ViewPoint - Info Disclosure
An issue was discovered in Idelji Web ViewPoint H01ABO-H01BY and L01ABP-L01ABZ, Web ViewPoint Plus H01AAG-H01AAQ and L01AAH-L01AAR, and Web ViewPoint Enterprise H01-H01AAE and L01-L01AAF. By reading ADB or AADB file content within the Installation subvolume, a Guardian user can discover the password of the group.user or alias who acknowledges events from the WVP Events screen.
CWE-522 Jan 27, 2020
CVE-2019-19823 7.5 HIGH 1 Writeup NUCLEI EPSS 0.35
Totolink A3002ru Firmware - Insufficiently Protected Credentials
A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords in flash memory and in a file. This affects TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, and N100RE through 3.4.0; Rutek RTK 11N AP through 2019-12-12; Sapido GR297n through 2019-12-12; CIK TELECOM MESH ROUTER through 2019-12-12; KCTVJEJU Wireless AP through 2019-12-12; Fibergate FGN-R2 through 2019-12-12; Hi-Wifi MAX-C300N through 2019-12-12; HCN MAX-C300N through 2019-12-12; T-broad GN-866ac through 2019-12-12; Coship EMTA AP through 2019-12-12; and IO-Data WN-AC1167R through 2019-12-12.
CWE-522 Jan 27, 2020
CVE-2020-6961 10.0 CRITICAL EPSS 0.00
ApexPro Telemetry Server <4.2 - Info Disclosure
In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Telemetry Server Version 4.3, CARESCAPE Central Station (CSCS) Versions 1.X, a vulnerability exists in the affected products that could allow an attacker to obtain access to the SSH private key in configuration files.
CWE-522 Jan 24, 2020