CVE & Exploit Intelligence Database

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,555 researchers
1,290 results Clear all
CVE-2019-8932 7.5 HIGH EPSS 0.00
Rdbrck Shift < 3.4.3 - Insufficiently Protected Credentials
Redbrick Shift through 3.4.3 allows an attacker to extract authentication tokens of services (such as Gmail, Outlook, etc.) used in the application.
CWE-522 Jul 17, 2019
CVE-2019-1010308 9.8 CRITICAL 1 Writeup EPSS 0.00
Aquaverde GmbH Aquarius CMS <4.1.1 - Info Disclosure
Aquaverde GmbH Aquarius CMS prior to version 4.1.1 is affected by: Incorrect Access Control. The impact is: The access to the log file is not restricted. It contains sensitive information like passwords etc. The component is: log file. The attack vector is: open the file.
CWE-522 Jul 15, 2019
CVE-2019-9657 7.8 HIGH EPSS 0.00
Alarm.com ADC-V522IR 0100b9 - Info Disclosure
Alarm.com ADC-V522IR 0100b9 devices have Incorrect Access Control, a different issue than CVE-2018-19588. This occurs because of incorrect protection of VPN certificates (used for initiating a VPN session to the Alarm.com infrastructure) on the local camera device.
CWE-522 Jul 11, 2019
CVE-2019-10347 8.8 HIGH EPSS 0.00
Jenkins Mashup Portlets < 1.0.9 - Insufficiently Protected Credentials
Jenkins Mashup Portlets Plugin stored credentials unencrypted on the Jenkins master where they can be viewed by users with access to the master file system.
CWE-522 Jul 11, 2019
CVE-2019-12171 7.8 HIGH EPSS 0.00
Dropbox <71.4.108.0 - Memory Corruption
Dropbox.exe (and QtWebEngineProcess.exe in the Web Helper) in the Dropbox desktop application 71.4.108.0 store cleartext credentials in memory upon successful login or new account creation. These are not securely freed in the running process.
CWE-522 Jul 08, 2019
CVE-2019-13400 9.8 CRITICAL EPSS 0.00
Fortinet Fcm-mb40 Firmware - Insufficiently Protected Credentials
Dynacolor FCM-MB40 v1.2.0.0 use /etc/appWeb/appweb.pass to store administrative web-interface credentials in cleartext. These credentials can be retrieved via cgi-bin/getuserinfo.cgi?mode=info.
CWE-522 Jul 08, 2019
CVE-2019-9873 9.8 CRITICAL EPSS 0.00
JetBrains IntelliJ IDEA Ultimate - Info Disclosure
In several versions of JetBrains IntelliJ IDEA Ultimate, creating Task Servers configurations leads to saving a cleartext unencrypted record of the server credentials in the IDE configuration files. The issue has been fixed in the following versions: 2019.1, 2018.3.5, 2018.2.8, and 2018.1.8.
CWE-522 Jul 03, 2019
CVE-2019-9872 8.1 HIGH EPSS 0.00
JetBrains IntelliJ IDEA Ultimate - Info Disclosure
In several versions of JetBrains IntelliJ IDEA Ultimate, creating run configurations for cloud application servers leads to saving a cleartext unencrypted record of the server credentials in the IDE configuration files. If the Settings Repository plugin was then used and configured to synchronize IDE settings using a public repository, these credentials were published to this repository. The issue has been fixed in the following versions: 2019.1, 2018.3.5, 2018.2.8, and 2018.1.8.
CWE-522 Jul 03, 2019
CVE-2019-9823 9.8 CRITICAL EPSS 0.00
JetBrains IntelliJ IDEA - Info Disclosure
In several JetBrains IntelliJ IDEA versions, creating remote run configurations of JavaEE application servers leads to saving a cleartext record of the server credentials in the IDE configuration files. The issue has been fixed in the following versions: 2018.3.5, 2018.2.8, 2018.1.8.
CWE-522 Jul 03, 2019
CVE-2019-12847 7.2 HIGH EPSS 0.00
Jetbrains Hub < 2018.4.11298 - Insufficiently Protected Credentials
In JetBrains Hub versions earlier than 2018.4.11298, the audit events for SMTPSettings show a cleartext password to the admin user. It is only relevant in cases where a password has not changed since 2017, and if the audit log still contains events from before that period.
CWE-522 Jul 03, 2019
CVE-2019-13179 7.5 HIGH EPSS 0.01
Calamares < 3.2.10 - Insufficiently Protected Credentials
Calamares versions 3.1 through 3.2.10 copies a LUKS encryption keyfile from /crypto_keyfile.bin (mode 0600 owned by root) to /boot within a globally readable initramfs image with insecure permissions, which allows this originally protected file to be read by any user, thereby disclosing decryption keys for LUKS containers created with Full Disk Encryption.
CWE-522 Jul 02, 2019
CVE-2019-7260 9.8 CRITICAL EPSS 0.00
Linear eMerge E3-Series - Info Disclosure
Linear eMerge E3-Series devices have Cleartext Credentials in a Database.
CWE-522 Jul 02, 2019
CVE-2019-7271 9.8 CRITICAL EPSS 0.00
Nortek Linear eMerge 50P/5000P - Info Disclosure
Nortek Linear eMerge 50P/5000P devices have Default Credentials.
CWE-522 Jul 01, 2019
CVE-2019-13054 6.5 MEDIUM EPSS 0.00
Logitech R500 Firmware - Insufficiently Protected Credentials
The Logitech R500 presentation clicker allows attackers to determine the AES key, leading to keystroke injection. On Windows, any text may be injected by using ALT+NUMPAD input to bypass the restriction on the characters A through Z.
CWE-522 Jun 29, 2019
CVE-2019-11272 7.3 HIGH EPSS 0.00
Vmware Spring Security < 4.2.13 - Authentication Bypass
Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPasswordEncoder. If an application using an affected version of Spring Security is leveraging PlaintextPasswordEncoder and a user has a null encoded password, a malicious user (or attacker) can authenticate using a password of "null".
CWE-522 Jun 26, 2019
CVE-2019-4385 6.5 MEDIUM EPSS 0.00
IBM Spectrum Protect Plus 10.1.2 - Info Disclosure
IBM Spectrum Protect Plus 10.1.2 may display the vSnap CIFS password in the IBM Spectrum Protect Plus Joblog. This can result in an attacker gaining access to sensitive information as well as vSnap. IBM X-Force ID: 162173.
CWE-522 Jun 19, 2019
CVE-2019-11271 7.8 HIGH EPSS 0.00
Cloud Foundry Bosh < 270.1.1 - Insufficiently Protected Credentials
Cloud Foundry BOSH 270.x versions prior to v270.1.1, contain a BOSH Director that does not properly redact credentials when configured to use a MySQL database. A local authenticated malicious user may read any credentials that are contained in a BOSH manifest.
CWE-522 Jun 19, 2019
CVE-2019-4239 5.5 MEDIUM EPSS 0.00
IBM Cloud Private < 3.0.1 - Insufficiently Protected Credentials
IBM MQ Advanced Cloud Pak (IBM Cloud Private 1.0.0 through 3.0.1) stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 159465.
CWE-522 Jun 14, 2019
CVE-2019-11092 4.4 MEDIUM EPSS 0.00
Intel Open Cloud Integrity Tehnology - Insufficiently Protected Credentials
Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access.
CWE-522 Jun 13, 2019
CVE-2019-0183 3.3 LOW EPSS 0.00
Intel Open Cloud Integrity Tehnology - Insufficiently Protected Credentials
Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access.
CWE-522 Jun 13, 2019