Skip to main content

CWE archive

CWE-522 CVEs

Programmatic archive

1,395 CVEs tagged with CWE-522217 Critical, 485 High, 646 Medium, 45 Low, 2 Unrated.

CVE-2023-38548

Published Nov 7, 2023

A vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client the ability to acquire the NTLM hash of the account used by the Veeam ONE Repor…

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2023-38328

Published Oct 26, 2023

An issue was discovered in eGroupWare 17.1.20190111. An Improper Password Storage vulnerability affects the setup panel of under setup/manageheader.php, which allows authenticated…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-17477

Published Oct 26, 2023

Incorrect LDAP ACLs in ucs-school-ldap-acls-master in UCS@school before 4.4v5-errata allow remote teachers, staff, and school administrators to read LDAP password hashes (sambaNTP…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43905

Published Oct 26, 2023

Incorrect access control in writercms v1.1.0 allows attackers to directly obtain backend account passwords via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-46651

Published Oct 25, 2023

Jenkins Warnings Plugin 10.5.0 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture cre…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-46115

Published Oct 20, 2023

Tauri is a framework for building binaries for all major desktop platforms. This advisory is not describing a vulnerability in the Tauri code base itself but a commonly used misco…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-5552

Published Oct 18, 2023

A password disclosure vulnerability in the Secure PDF eXchange (SPX) feature allows attackers with full email access to decrypt PDFs in Sophos Firewall version 19.5 MR3 (19.5.3) a…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27132

Published Oct 17, 2023

TSplus Remote Work 16.0.0.0 places a cleartext password on the "var pass" line of the HTML source code for the secure single sign-on web portal. NOTE: CVE-2023-31069 is only about…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-43777

Published Oct 17, 2023

Eaton easySoft software is used to program easy controllers and displays for configuring, programming and defining parameters for all the intelligent relays. This software has a p…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-27315

Published Oct 12, 2023

SnapGathers versions prior to 4.9 are susceptible to a vulnerability which could allow a local authenticated attacker to discover plaintext domain user credentials

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-42451

Published Oct 11, 2023

Certain credentials within the BigFix Patch Management Download Plug-ins are stored insecurely and could be exposed to a local privileged user.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23370

Published Oct 6, 2023

An insufficiently protected credentials vulnerability has been reported to affect QVPN Device Client. If exploited, the vulnerability could allow local authenticated administrator…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43634

Published Sep 21, 2023

When sealing/unsealing the “vault” key, a list of PCRs is used, which defines which PCRs are used. In a previous project, CYMOTIVE found that the configuration is not protected b…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-43633

Published Sep 21, 2023

On boot, the Pillar eve container checks for the existence and content of “/config/GlobalConfig/global.json”. If the file exists, it overrides the existing configuration on the d…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-25532

Published Sep 20, 2023

NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause insufficient protection of credentials. A successful exploit of this vulnerability may lead to in…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-25531

Published Sep 20, 2023

NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause insufficient protection of credentials. A successful exploit of this vulnerability may lead to co…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort
Showing 426-450 of 1,395 CVEsPage 18 of 56