The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
1,360 vulnerabilities with CWE-522
CVE-2022-46155
HIGH
Airtable.js <0.11.6 - Info Disclosure
CVSS 7.6
CVE-2022-41732
MEDIUM
IBM Maximo Mobile <8.9 - Info Disclosure
CVSS 6.2
CVE-2022-29833
MEDIUM
Mitsubishi Electric GX Works3 1.015R-1.086Q - Unauthenticated Sensitive Information Disclosure
CVSS 6.8
CVE-2022-41933
MEDIUM
XWiki 13.1-13.10.8 - Plaintext Password Storage in Forgot Password Feature
CVSS 6.2
CVE-2022-40751
MEDIUM
IBM UrbanCode Deploy Credential Exposure via LDAP Search
CVSS 4.9
CVE-2022-45392
MEDIUM
Jenkins NS-ND Integration Performance Publisher < 4.8.0.146 - Insufficiently Protected Credentials in Job Config Files
CVSS 6.5
CVE-2022-45384
MEDIUM
Jenkins Reverse Proxy Auth Plugin <= 1.7.3 - Insufficiently Protected Credentials in LDAP Manager Password Storage
CVSS 6.5
CVE-2022-37109
CRITICAL
camp_project camp < 2022-07-21 - Insufficiently Protected Credentials via StaticFileHandler
CVSS 9.8
CVE-2022-26341
HIGH
Intel(R) AMT SDK <16.0.4.1 - Privilege Escalation
CVSS 8.2
CVE-2022-38121
MEDIUM
UPSMON PRO - Insufficiently Protected Credentials in Configuration File
CVSS 6.5
CVE-2022-36077
HIGH
Electron <21.0.0-beta.1-18.3.7 - Info Disclosure
CVSS 7.2
CVE-2022-3781
MEDIUM
Devolutions Server < 2022.3.2 and Remote Desktop Manager < 2022.2.27 - Insufficiently Protected Credentials
CVSS 6.5
CVE-2022-3474
MEDIUM
Bazel 3.1.0-4.2.2 - Insufficiently Protected Credentials in Remote Assets API
CVSS 4.3
CVE-2022-3644
MEDIUM
pulp_ansible - Insufficiently Protected Credentials via Plaintext Token Storage
CVSS 5.5
CVE-2022-41575
HIGH
Gradle Enterprise <2022.3.3 - Info Disclosure
CVSS 7.5
CVE-2022-43419
MEDIUM
Jenkins Katalon Plugin <1.0.32 - Info Disclosure
CVSS 6.5
CVE-2022-22251
HIGH
Juniper Networks Junos OS <21.2R1 - Privilege Escalation
CVSS 7.8
CVE-2022-28291
MEDIUM
Nessus - Authenticated Cleartext Credential Exposure via Process Dumping
CVSS 6.5
CVE-2022-3206
MEDIUM
Passster WP <3.5.5.5.2 - Info Disclosure
CVSS 5.9
CVE-2022-31130
MEDIUM
Grafana <9.1.8 & <8.5.14 - Info Disclosure
CVSS 4.9
CVE-2022-38465
CRITICAL
SIMATIC Drive Controller <V2.9.2, SIMATIC ET 200SP Open Controller ...
CVSS 9.3
CVE-2022-39168
HIGH
IBM Robotic Process Automation - Credential Exposure in Upgrade Logs
CVSS 7.5
CVE-2022-29089
MEDIUM
Dell Networking OS10 - Info Disclosure
CVSS 6.4
CVE-2022-37193
HIGH
Chipolo ONE Bluetooth Tracker - Insufficiently Protected Credentials
CVSS 7.4
CVE-2022-41255
MEDIUM
Jenkins CONS3RT Plugin <1.0.0 - Info Disclosure
CVSS 6.5
Details
Vulnerabilities
1,360