Skip to main content

CWE archive

CWE-522 CVEs

Programmatic archive

1,423 CVEs tagged with CWE-522223 Critical, 495 High, 655 Medium, 48 Low, 2 Unrated.

CVE-2019-19119

Published Feb 3, 2020

An issue was discovered in PRTG 7.x through 19.4.53. Due to insufficient access control on local registry keys for the Core Server Service, a non-administrative user on the local…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-7909

Published Jan 30, 2020

In JetBrains TeamCity before 2019.1.5, some server-stored passwords could be shown via the web UI.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-2107

Published Jan 29, 2020

Jenkins Fortify Plugin 19.1.29 and earlier stores proxy server passwords unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3445

Published Jan 28, 2020

backup.php in HandsomeWeb SOS Webpages before 1.1.12 does not require knowledge of the cleartext password, which allows remote attackers to bypass authentication by leveraging kno…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-19898

Published Jan 23, 2020

In IXP EasyInstall 6.2.13723, there are cleartext credentials in network communication on TCP port 20050 when using the Administrator console remotely.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-19843

Published Jan 22, 2020

Incorrect access control in the web interface in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote credential fetch via an unauthenticated HTTP request involving a s…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2019-19696

Published Jan 18, 2020

A RootCA vulnerability found in Trend Micro Password Manager for Windows and macOS exists where the localhost.key of RootCA.crt might be improperly accessed by an unauthorized par…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-12423

Published Jan 16, 2020

Apache CXF ships with a OpenId Connect JWK Keys service, which allows a client to obtain the public keys in JWK format, which can then be used to verify the signature of tokens is…

CVSS 7.5 · High

CVE-2020-2095

Published Jan 15, 2020

Jenkins Redgate SQL Change Automation Plugin 2.0.4 and earlier stored an API key unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6700

Published Jan 7, 2020

An information exposure vulnerability in the external authentication profile form of FortiSIEM 5.2.2 and earlier may allow an authenticated attacker to retrieve the external authe…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-5990

Published Jan 6, 2020

Access analysis CGI An-Analyzer released in 2019 June 24 and earlier allow remote attackers to obtain a login password via HTTP referer.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-19310

Published Jan 3, 2020

GitLab Enterprise Edition (EE) 9.0 and later through 12.5 allows Information Disclosure.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3620

Published Jan 2, 2020

Hardcoded WSMan credentials in Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before 3.15 (SMT_X9_315) and firmware for S…

CVSS 7.5 · High
Showing 1,026-1,050 of 1,423 CVEsPage 42 of 57