Skip to main content

CWE archive

CWE-522 CVEs

Programmatic archive

1,394 CVEs tagged with CWE-522217 Critical, 485 High, 645 Medium, 45 Low, 2 Unrated.

CVE-2024-20489

Published Sep 11, 2024

A vulnerability in the storage method of the PON Controller configuration file could allow an authenticated, local attacker with low privileges to obtain the MongoDB credentials.…

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-40710

Published Sep 7, 2024

A series of related high-severity vulnerabilities, the most notable enabling remote code execution (RCE) as the service account and extraction of sensitive information (savedcrede…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2024-39278

Published Sep 5, 2024

Credentials to access device configuration information stored unencrypted in flash memory. These credentials would allow read-only access to network configuration information and…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-49233

Published Sep 3, 2024

Insufficient access checks in Visual Planning Admin Center 8 before v.1 Build 240207 allow attackers in possession of a non-administrative Visual Planning account to utilize funct…

CVSS 8.8 · High

CVE-2024-40704

Published Aug 15, 2024

IBM InfoSphere Information Server 11.7 could allow a privileged user to obtain sensitive information from authentication request headers. IBM X-Force ID: 298277.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-36460

Published Aug 12, 2024

The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain text.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-7389

Published Aug 2, 2024

The Forminator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.29.1 via class-forminator-addon-hubspot-wp-api.php. Thi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6492

Published Jul 16, 2024

Exposure of Sensitive Information in edge browser session proxy feature in Devolutions Remote Desktop Manager 2024.2.14.0 and earlier on Windows allows an attacker to intercept pr…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-39733

Published Jul 14, 2024

IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 295972.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-38453

Published Jul 3, 2024

The Avalara for Salesforce CPQ app before 7.0 for Salesforce allows attackers to read an API key. NOTE: the current version is 11 as of mid-2024.

CVSS 7.5 · High

CVE-2023-41926

Published Jul 2, 2024

The webserver utilizes basic authentication for its user login to the configuration interface. As encryption is disabled on port 80, it enables potential eavesdropping on user tra…

CVSS 8.8 · High

CVE-2024-39879

Published Jul 1, 2024

In JetBrains TeamCity before 2024.03.3 application token could be exposed in EC2 Cloud Profile settings

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-39878

Published Jul 1, 2024

In JetBrains TeamCity before 2024.03.3 private key could be exposed via testing GitHub App Connection

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-38505

Published Jun 18, 2024

In JetBrains YouTrack before 2024.2.34646 user access token was sent to the third-party site

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30119

Published Jun 14, 2024

HCL DRYiCE Optibot Reset Station is impacted by a missing Strict Transport Security Header.  This could allow an attacker to intercept or manipulate data during redirection.

CVSS 3.7 · Low

CVE-2024-38285

Published Jun 13, 2024

Logs storing credentials are insufficiently protected and can be decoded through the use of open source tools.

CVSS 7.0 · High

CVE-2024-38282

Published Jun 13, 2024

Utilizing default credentials, an attacker is able to log into the camera's operating system which could allow changes to be made to the operations or shutdown the camera requirin…

CVSS 8.5 · High

CVE-2024-26330

Published Jun 11, 2024

An issue was discovered in Kape CyberGhostVPN 8.4.3.12823 on Windows. After a successful logout, user credentials remain in memory while the process is still open, and can be obta…

CVSS 6.5 · Medium
Showing 326-350 of 1,394 CVEsPage 14 of 56