The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
1,359 vulnerabilities with CWE-522
CVE-2023-46115
HIGH
Tauri - Insufficiently Protected Credentials via Vite Configuration Misuse
CVSS 8.4
CVE-2023-5552
HIGH
Sophos Firewall < 19.5.3 - Password Disclosure via Secure PDF eXchange Feature
CVSS 7.1
CVE-2023-27132
CRITICAL
TSplus Remote Work 16.0.0.0 - Info Disclosure
CVSS 9.8
CVE-2023-43777
MEDIUM
Eaton easySoft < 8.01 - Insufficiently Protected Credentials
CVSS 5.9
CVE-2023-27315
MEDIUM
SnapGathers < 4.9 - Authenticated Plaintext Credential Exposure
CVSS 6.5
CVE-2023-23370
MEDIUM
QVPN 2.1.0-2.1.0.0518 - Authenticated Credential Exposure via Local Access
CVSS 6.7
CVE-2023-44158
HIGH
Acronis Cyber Protect 15 < 35979 - Sensitive Information Disclosure via Insufficient Token Masking
CVSS 7.5
CVE-2023-1633
MEDIUM
OpenStack Barbican - Info Disclosure
CVSS 6.6
CVE-2023-43634
HIGH
When sealing/unsealing the "vault" key - Info Disclosure
CVSS 8.8
CVE-2023-43633
HIGH
lfedge/eve <8.6.0 - Unauthenticated Insufficiently Protected Credentials via GlobalConfig Override
CVSS 8.8
CVE-2023-43631
HIGH
LF Edge EVE < 8.6.0 - Unauthenticated Credential Injection via Unprotected Config Partition
CVSS 8.8
CVE-2023-43635
HIGH
EVE OS - PCR Locking
CVSS 8.8
CVE-2023-43630
HIGH
Linux Foundation Edge Virtualization Engine 9.0.0-9.4.9 - Credentials Exposure via PCR14 Bypass
CVSS 8.8
CVE-2023-25532
MEDIUM
NVIDIA DGX H100 Firmware < 23.08.18 - Insufficiently Protected Credentials in IPMI
CVSS 6.5
CVE-2023-25531
HIGH
NVIDIA DGX H100 Firmware < 23.08.18 - Insufficiently Protected Credentials in IPMI
CVSS 7.6
CVE-2023-41010
MEDIUM
China Telecom Tianyi Home Gateway v.TEWA-700G - Info Disclosure
CVSS 5.5
CVE-2023-32338
MEDIUM
IBM Sterling Secure Proxy & External Authentication Server 6.0.3/6.1.0 - Credential Protection Bypass
CVSS 5.1
CVE-2023-3251
MEDIUM
Nessus < 10.6.0 - Authenticated SMTP Credential Exposure
CVSS 4.1
CVE-2023-40173
HIGH
social-media-skeleton < 1.0.5 - Insufficiently Protected Credentials via Unsalted Password Hashes
CVSS 7.5
CVE-2023-31492
MEDIUM
Zoho ManageEngine ADManager Plus <7182 - Info Disclosure
CVSS 6.5
CVE-2023-40347
MEDIUM
Jenkins Maven Artifact ChoiceListProvider (Nexus) Plugin < 1.14 - Insufficiently Protected Credentials
CVSS 6.5
CVE-2023-40345
MEDIUM
Jenkins Delphix Plugin < 3.0.2 - Insufficiently Protected Credentials via Credentials Lookup
CVSS 6.5
CVE-2023-4328
MEDIUM
Broadcom RAID Controller - Info Disclosure
CVSS 5.5
CVE-2023-4327
MEDIUM
Broadcom RAID Controller - Info Disclosure
CVSS 5.5
CVE-2023-20965
CRITICAL
Android - Credential Disclosure in TOFU Flow via ClientModeImpl Logic Error
CVSS 9.8
Details
Vulnerabilities
1,359