The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
1,358 vulnerabilities with CWE-522
CVE-2024-44815
MEDIUM
Hathway Skyworth Router CM5100 <4.1.1.24 - Info Disclosure
CVSS 4.6
CVE-2024-40710
HIGH
Veeam Backup & Replication < 12.2.0.334 - Authenticated Remote Code Execution and Credential Extraction
CVSS 8.8
CVE-2024-39278
MEDIUM
EchoStar Fusion < 2.7.0.10 - Unprotected Credential Storage in Flash Memory
CVSS 4.2
CVE-2024-40704
MEDIUM
IBM InfoSphere Information Server 11.7 - Info Disclosure
CVSS 4.9
CVE-2024-31800
MEDIUM
GC2 Indoor Security Camera 1080P - Privilege Escalation
CVSS 6.8
CVE-2024-7813
MEDIUM
Prison Management System 1.0 - Insufficiently Protected Credentials in Profile Image Handler
CVSS 5.3
CVE-2024-39818
HIGH
Zoom Rooms and Workplace < 6.0.0 - Authenticated Information Disclosure via Network Access
CVSS 7.5
CVE-2024-36460
HIGH
Zabbix - Plaintext Password Disclosure in Front-End Audit Log
CVSS 8.1
CVE-2024-6118
CRITICAL
Hamastar MeetingHub Paperless Meetings 2021 - Info Disclosure
CVSS 9.1
CVE-2024-7389
HIGH
Forminator < 1.29.1 - Unauthenticated Sensitive Information Exposure via HubSpot API Key
CVSS 7.5
CVE-2024-3082
MEDIUM
Proges Sensor Net Connect Firmware - Plaintext Password Storage
CVSS 4.2
CVE-2024-6492
HIGH
Drevolutions Remote Desktop Manager <2024.2.14.0 - Info Disclosure
CVSS 7.4
CVE-2024-39733
MEDIUM
IBM Datacap Navigator <9.1.10 - Info Disclosure
CVSS 5.5
CVE-2024-38453
HIGH
Avalara for Salesforce <7.0 - Info Disclosure
CVSS 7.5
CVE-2024-39879
MEDIUM
JetBrains TeamCity < 2024.03.3 - Insufficiently Protected Credentials in EC2 Cloud Profile Settings
CVSS 5.0
CVE-2024-39878
MEDIUM
JetBrains TeamCity < 2024.03.3 - Private Key Exposure via GitHub App Connection Test
CVSS 4.1
CVE-2024-38505
MEDIUM
JetBrains YouTrack <2024.2.34646 - Info Disclosure
CVSS 5.3
CVE-2024-30119
LOW
HCL DRYiCE Optibot Reset Station - Info Disclosure
CVSS 3.7
CVE-2024-38285
HIGH
Motorola Solutions Vigilant Fixed LPR Coms Box (BCAV1F2-C600) < 3.1.171.9 - Insufficiently Protected Credentials in Logs
CVE-2024-38282
HIGH
Motorola Solutions Vigilant Fixed LPR Coms Box (BCAV1F2-C600) < 3.1.171.9 - Unauthenticated Default Credential Exposure
CVE-2024-25052
MEDIUM
IBM Jazz Reporting Service 7.0.3 - Info Disclosure
CVSS 4.4
CVE-2024-26330
MEDIUM
Kape CyberGhostVPN <8.4.3.12823 - Info Disclosure
CVSS 6.5
CVE-2024-35208
MEDIUM
SINEC Traffic Analyzer < 1.2 - Insufficiently Protected Credentials
CVSS 6.3
CVE-2024-37051
CRITICAL
JetBrains IDEs - GitHub Access Token Exposure
CVSS 9.3
CVE-2024-5657
LOW
born05 Two-Factor Authentication 3.3.1-3.3.3 - Password Hash Disclosure via TOTP Submission
CVSS 3.7
Details
Vulnerabilities
1,358