CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,867 CVEs tracked 53,243 with exploits 4,725 exploited in wild 1,540 CISA KEV 3,925 Nuclei templates 37,802 vendors 42,500 researchers
1,290 results Clear all
CVE-2018-0828 7.8 HIGH EPSS 0.01
Microsoft Windows 10 - Insufficiently Protected Credentials
Windows 10 version 1607 and Windows Server 2016 allow an elevation of privilege vulnerability due to how the MultiPoint management account password is stored, aka "Windows Elevation of Privilege Vulnerability".
CWE-522 Feb 15, 2018
CVE-2017-9969 6.7 MEDIUM EPSS 0.00
Schneider-electric Igss Mobile - Insufficiently Protected Credentials
An information disclosure vulnerability exists in Schneider Electric's IGSS Mobile application version 3.01 and prior. Passwords are stored in clear text in the configuration which can result in exposure of sensitive information.
CWE-522 Feb 12, 2018
CVE-2018-1000057 4.3 MEDIUM EPSS 0.00
Jenkins Credentials Binding Plugin <1.14 - Info Disclosure
Jenkins Credentials Binding Plugin 1.14 and earlier masks passwords it provides to build processes in their build logs. Jenkins however transforms provided password values, e.g. replacing environment variable references, which could result in values different from but similar to configured passwords being provided to the build. Those values are not subject to masking, and could allow unauthorized users to recover the original password.
CWE-522 Feb 09, 2018
CVE-2017-15656 8.8 HIGH EPSS 0.00
Asuswrt < 3.0.0.4.380.7743 - Insufficiently Protected Credentials
Password are stored in plaintext in nvram in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt.
CWE-522 Jan 31, 2018
CVE-2017-1779 7.8 HIGH EPSS 0.00
IBM Cognos Analytics - Insufficiently Protected Credentials
IBM Cognos Analytics 11.0 could store cached credentials locally that could be obtained by a local user. IBM X-Force ID: 136824.
CWE-522 Jan 29, 2018
CVE-2017-1000387 7.8 HIGH EPSS 0.00
Jenkins Build-Publisher <1.21 - Info Disclosure
Jenkins Build-Publisher plugin version 1.21 and earlier stores credentials to other Jenkins instances in the file hudson.plugins.build_publisher.BuildPublisher.xml in the Jenkins master home directory. These credentials were stored unencrypted, allowing anyone with local file system access to access them. Additionally, the credentials were also transmitted in plain text as part of the configuration form. This could result in exposure of the credentials through browser extensions, cross-site scripting vulnerabilities, and similar situations.
CWE-522 Jan 26, 2018
CVE-2017-16731 8.8 HIGH EPSS 0.00
ABB Ellipse <8.9 - Info Disclosure
An Unprotected Transport of Credentials issue was discovered in ABB Ellipse 8.3 through Ellipse 8.9 released prior to December 2017 (including Ellipse Select). A vulnerability exists in the authentication of Ellipse to LDAP/AD using the LDAP protocol. An attacker could exploit the vulnerability by sniffing local network traffic, allowing the discovery of authentication credentials.
CWE-523 Dec 20, 2017
CVE-2017-17106 9.8 CRITICAL EXPLOITED EPSS 0.28
Zivif PR115-204-P-RS V2.3.4.2103 - Info Disclosure
Credentials for Zivif PR115-204-P-RS V2.3.4.2103 Webcams can be obtained by an unauthenticated remote attacker using a standard web /cgi-bin/hi3510/param.cgi?cmd=getuser HTTP request. This vulnerability exists because of a lack of authentication checks in requests to CGI pages.
CWE-522 Dec 19, 2017
CVE-2017-3192 9.8 CRITICAL EPSS 0.28
D-link Dir-130 Firmware - Insufficiently Protected Credentials
D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 do not sufficiently protect administrator credentials. The tools_admin.asp page discloses the administrator password in base64 encoding in the returned web page. A remote attacker with access to this page (potentially through a authentication bypass such as CVE-2017-3191) may obtain administrator credentials for the device.
CWE-522 Dec 16, 2017
CVE-2017-14111 7.2 HIGH EPSS 0.01
Philips IntelliSpace Cardiovascular <2.3.0 - Info Disclosure
The workstation logging function in Philips IntelliSpace Cardiovascular (ISCV) 2.3.0 and earlier and Xcelera R4.1L1 and earlier records domain authentication credentials, which if accessed allows an attacker to use credentials to access the application, or other user entitlements.
CWE-522 Nov 17, 2017
CVE-2017-15272 5.3 MEDIUM EPSS 0.00
Psftpd - Authentication Bypass
The PSFTPd 10.0.4 Build 729 server stores its configuration inside PSFTPd.dat. This file is a Microsoft Access Database and can be extracted. The application sets the encrypt flag with the password "ITsILLEGAL"; however, this password is not required to extract the data. Cleartext is used for a user password.
CWE-522 Nov 15, 2017
CVE-2017-14711 8.1 HIGH EPSS 0.00
Kickbase GmbH Kickbase Bundesliga Manager <2.2.1 - Info Disclosure
The Kickbase GmbH "Kickbase Bundesliga Manager" app before 2.2.1 -- aka kickbase-bundesliga-manager/id678241305 -- for iOS is vulnerable to a credentials leak due to transmitting a username and password in cleartext from client to server during registration and authentication.
CWE-522 Nov 13, 2017
CVE-2017-15918 7.8 HIGH 1 PoC Analysis EPSS 0.00
Ignitum Sera - Insufficiently Protected Credentials
Sera 1.2 stores the user's login password in plain text in their home directory. This makes privilege escalation trivial and also exposes the user and system keychains to local attacks.
CWE-522 Nov 01, 2017
CVE-2017-1000245 9.8 CRITICAL EPSS 0.00
SSH Plugin - Info Disclosure
The SSH Plugin stores credentials which allow jobs to access remote servers via the SSH protocol. User passwords and passphrases for encrypted SSH keys are stored in plaintext in a configuration file.
CWE-522 Nov 01, 2017
CVE-2017-3760 8.1 HIGH EPSS 0.01
Lenovo Service Framework - RCE
The Lenovo Service Framework Android application uses a set of nonsecure credentials when performing integrity verification of downloaded applications and/or data. This exposes the application to man-in-the-middle attacks leading to possible remote code execution.
CWE-522 Oct 17, 2017
CVE-2017-5700 8.4 HIGH EPSS 0.00
Intel Nuc7i7bnh Firmware - Insufficiently Protected Credentials
Insufficient protection of password storage in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and below allows local attackers to bypass Administrator and User passwords via access to password storage.
CWE-522 Oct 11, 2017
CVE-2017-13998 7.5 HIGH EPSS 0.00
LOYTEC LVIS-3ME <6.2.0 - Info Disclosure
An Insufficiently Protected Credentials issue was discovered in LOYTEC LVIS-3ME versions prior to 6.2.0. The application does not sufficiently protect sensitive information from unauthorized access.
CWE-522 Oct 05, 2017
CVE-2017-1378 7.8 HIGH EPSS 0.00
IBM Spectrum Protect <8.1 - Info Disclosure
IBM Spectrum Protect 7.1 and 8.1 (formerly Tivoli Storage Manager) disclosed unencrypted login credentials to Vmware vCenter in the application trace output which could be obtained by a local user. IBM X-Force ID: 126875.
CWE-522 Oct 05, 2017
CVE-2017-1201 7.8 HIGH EPSS 0.00
IBM Bigfix Security Compliance Analytics - Insufficiently Protected Credentials
IBM BigFix Compliance Analytics 1.9.79 (TEMA SUAv1 SCA SCM) stores user credentials in clear text which can be read by a local user. IBM X-Force ID: 123676.
CWE-522 Oct 05, 2017
CVE-2017-1362 7.8 HIGH EPSS 0.00
IBM Security Identity Manager Adapters <7.0 - Info Disclosure
IBM Security Identity Manager Adapters 6.0 and 7.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 126801.
CWE-522 Sep 25, 2017