Skip to main content

CWE archive

CWE-522 CVEs

Programmatic archive

1,395 CVEs tagged with CWE-522217 Critical, 485 High, 646 Medium, 45 Low, 2 Unrated.

CVE-2024-26330

Published Jun 11, 2024

An issue was discovered in Kape CyberGhostVPN 8.4.3.12823 on Windows. After a successful logout, user credentials remain in memory while the process is still open, and can be obta…

CVSS 6.5 · Medium

CVE-2024-35208

Published Jun 11, 2024

A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server stored the password in cleartext. This could allo…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37051

Published Jun 10, 2024

GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3;…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
20.4

CVE-2024-5657

Published Jun 6, 2024

The CraftCMS plugin Two-Factor Authentication in versions 3.3.1, 3.3.2 and 3.3.3 discloses the password hash of the currently authenticated user after submitting a valid TOTP.

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-36127

Published Jun 3, 2024

apko is an apk-based OCI image builder. apko exposures HTTP basic auth credentials from repository and keyring URLs in log output. This vulnerability is fixed in v0.14.5.

CVSS 7.5 · High

CVE-2024-5176

Published May 31, 2024

Insufficiently Protected Credentials vulnerability in Baxter Welch Allyn Configuration Tool may allow Remote Services with Stolen Credentials.This issue affects Welch Allyn Config…

CVSS 9.4 · Critical

CVE-2024-35192

Published May 20, 2024

Trivy is a security scanner. Prior to 0.51.2, if a malicious actor is able to trigger Trivy to scan container images from a crafted malicious registry, it could result in the leak…

CVSS 5.5 · Medium

CVE-2024-36081

Published May 19, 2024

Westermo EDW-100 devices through 2024-05-03 allow an unauthenticated user to download a configuration file containing a cleartext password. NOTE: this is a serial-to-Ethernet conv…

CVSS 9.8 · Critical

CVE-2024-27109

Published May 14, 2024

Insufficiently protected credentials in GE HealthCare EchoPAC products

CVSS 7.6 · High

CVE-2024-33497

Published May 14, 2024

A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions < V3.0.…

CVSS 4.8 · Medium

CVE-2024-33496

Published May 14, 2024

A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions < V3.0.…

CVSS 4.8 · Medium

CVE-2024-22345

Published May 14, 2024

IBM TXSeries for Multiplatforms 8.2 transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieva…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-42955

Published May 14, 2024

Claris International has successfully resolved an issue of potentially exposing password information to front-end websites when signed in to the Admin Console with an administrato…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-22266

Published May 8, 2024

VMware Avi Load Balancer contains an information disclosure vulnerability. A malicious actor with access to the system logs can view cloud connection credentials in plaintext.

CVSS 6.5 · Medium

CVE-2024-23551

Published May 7, 2024

Database scanning using username and password stores the credentials in plaintext or encoded format within files at the endpoint. This has been identified as a significant securit…

CVSS 6.5 · Medium

CVE-2024-4536

Published May 7, 2024

In Eclipse Dataspace Components from version 0.2.1 to 0.6.2, in the EDC Connector component ( https://github.com/eclipse-edc/Connector ), an attacker might obtain OAuth2 client se…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-29941

Published May 6, 2024

Insecure storage of the ICT MIFARE and DESFire encryption keys in the firmware binary allows malicious actors to create credentials for any site code and card number that is using…

CVSS 8.0 · High

CVE-2023-40511

Published May 3, 2024

LG Simple Editor checkServer Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of LG Simple Editor…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-40510

Published May 3, 2024

LG Simple Editor getServerSetting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of LG Simple E…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-3543

Published May 2, 2024

Use of reversible password encryption algorithm allows attackers to decrypt passwords.  Sensitive information can be easily unencrypted by the attacker, stolen credentials can be…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34147

Published May 2, 2024

Jenkins Telegram Bot Plugin 1.4.0 and earlier stores the Telegram Bot token unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-28961

Published Apr 29, 2024

Dell OpenManage Enterprise, versions 4.0.0 and 4.0.1, contains a sensitive information disclosure vulnerability. A local low privileged malicious user could potentially exploit th…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 351-375 of 1,395 CVEsPage 15 of 56