The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
1,363 vulnerabilities with CWE-522
CVE-2018-1498
MEDIUM
IBM Security Guardium EcoSystem 10.5 - Info Disclosure
CVSS 6.2
CVE-2018-17613
CRITICAL
Telegram Desktop <1.3.16 - Info Disclosure
CVSS 9.8
CVE-2018-16669
CRITICAL
CIRCONTROL OCPP <1.5.0 - Info Disclosure
CVSS 9.8
CVE-2018-10814
HIGH
Synametrics SynaMan 4.0 build 1488 - Insufficiently Protected SMTP Credentials
CVSS 7.8
CVE-2018-16987
HIGH
Squash TM <1.18.0 - Info Disclosure
CVSS 7.2
CVE-2018-13822
HIGH
Broadcom Project Portfolio Management < 14.3 - Insufficiently Protected Credentials
CVSS 7.5
CVE-2018-1139
HIGH
Samba <4.7.9, 4.8.4 - Info Disclosure
CVSS 8.1
CVE-2018-10622
MEDIUM
Medtronic MyCareLink Patient Monitor - Info Disclosure
CVSS 5.2
CVE-2018-11050
HIGH
Dell EMC NetWorker 9.0-9.1.1.8, 9.2.1.3, 18.1.0.1 - Cleartext Transmission of Sensitive Information in RabbitMQ AMQP
CVSS 8.8
CVE-2018-5543
HIGH
F5 BIG-IP Controller <1.5.0 - Info Disclosure
CVSS 8.8
CVE-2018-8851
CRITICAL
Echelon SmartServer <4.11.007 - Info Disclosure
CVSS 9.8
CVE-2018-1000404
HIGH
Jenkins AWS CodeBuild Plugin <0.27 - Credentials Disclosure
CVSS 7.8
CVE-2018-1000403
HIGH
Jenkins AWS CodeDeploy Plugin <1.19 - Credentials Disclosure
CVSS 7.8
CVE-2018-1000401
HIGH
Jenkins AWS CodePipeline Plugin <0.36 - Credentials Disclosure
CVSS 7.8
CVE-2018-11639
HIGH
Dialogic PowerMedia XMS < 3.5 - Plaintext Password Exposure in Login Cookie
CVSS 8.1
CVE-2018-11634
HIGH
Dialogic PowerMedia XMS < 3.5 SU2 - Plaintext Password Storage in Administrative Console
CVSS 7.8
CVE-2018-7782
HIGH
Schneider Electric Pelco Sarix Professional <3.29.69 - Info Disclosure
CVSS 8.8
CVE-2018-11746
HIGH
Puppet Discovery < 1.2.0 - Insufficiently Protected Credentials via WinRM Basic Auth Fallback
CVSS 8.6
CVE-2018-13014
HIGH
SafenSoft Enterprise Suite < 4.4.2 - Insufficiently Protected Credentials in Settings Database
CVSS 7.8
CVE-2018-1000610
HIGH
Jenkins Configuration as Code Plugin <0.7-alpha - Info Disclosure
CVSS 8.8
CVE-2018-1000608
HIGH
Jenkins z/OS Connector Plugin <1.2.6.1 - Info Disclosure
CVSS 7.2
CVE-2018-12260
MEDIUM
Momentum Axel 720P <5.1.8 - Info Disclosure
CVSS 6.7
CVE-2018-1075
MEDIUM
ovirt-engine < 4.2.3 - Unfiltered Password Exposure in Manual Database Provisioning
CVSS 5.0
CVE-2018-4190
HIGH
Safari < 11.1.1 - Credential Exposure via CSS Mask-Image Fetch
CVSS 8.8
CVE-2018-0335
HIGH
Cisco Prime Collaboration Provisioning - Unauthenticated Sensitive Data Exposure via World-Readable Log File
CVSS 7.8
Details
Vulnerabilities
1,363