Skip to main content

CWE archive

CWE-522 CVEs

Programmatic archive

1,422 CVEs tagged with CWE-522222 Critical, 495 High, 655 Medium, 48 Low, 2 Unrated.

CVE-2019-4335

Published Dec 30, 2019

IBM Watson Studio Local 1.2.3 stores key files in the user's home directory which could be obtained by another local user. IBM X-Force ID: 161413.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6024

Published Dec 26, 2019

Rakuma App for Android version 7.15.0 and earlier, and for iOS version 7.16.4 and earlier allows an attacker to bypass authentication and obtain the user's authentication informat…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3431

Published Dec 23, 2019

All versions up to V4.01.01.02 of ZTE ZXCLOUD GoldenData VAP product have encryption problems vulnerability. Attackers could sniff unencrypted account and password through the net…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-18615

Published Dec 19, 2019

In CloudVision Portal (CVP) for all releases in the 2018.2 Train, under certain conditions, the application logs user passwords in plain text for certain API calls, potentially le…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-16572

Published Dec 17, 2019

Jenkins Weibo Plugin 1.0.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the m…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-16557

Published Dec 17, 2019

Jenkins Redgate SQL Change Automation Plugin 2.0.3 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-16556

Published Dec 17, 2019

Jenkins Rundeck Plugin 3.6.5 and earlier stores credentials unencrypted in its global configuration file and in job config.xml files on the Jenkins master where they can be viewed…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19687

Published Dec 9, 2019

OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API. Any user with a role on a project is able to list any credentials with the /v3/creden…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10224

Published Nov 25, 2019

A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as th…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-16544

Published Nov 21, 2019

Jenkins QMetry for JIRA - Test Management Plugin 1.12 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users wi…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-16543

Published Nov 21, 2019

Jenkins Spira Importer Plugin 3.2.2 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-16542

Published Nov 21, 2019

Jenkins Anchore Container Image Scanner Plugin 1.0.19 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users wi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-21031

Published Nov 18, 2019

Tautulli versions 2.1.38 and below allows remote attackers to bypass intended access control in Plex Media Server because the X-Plex-Token is mishandled and can be retrieved from…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3663

Published Nov 14, 2019

Unprotected Storage of Credentials vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows local attacker to gain access to the root password via accessing sensi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1,051-1,075 of 1,422 CVEsPage 43 of 57