Skip to main content

CWE archive

CWE-532 CVEs

Programmatic archive

1,163 CVEs tagged with CWE-53256 Critical, 259 High, 703 Medium, 145 Low, 0 Unrated.

CVE-2019-14782

Published Dec 17, 2019

CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.856 through 0.9.8.864 allows an attacker to get a victim's session file name from the /tmp directory, and the victim's token v…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10695

Published Dec 12, 2019

When using the cd4pe::root_configuration task to configure a Continuous Delivery for PE installation, the root user’s username and password were exposed in the job’s Job Details p…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3649

Published Nov 13, 2019

Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attackers to gain access to hashed credentials via carefully…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-16206

Published Nov 8, 2019

The authentication mechanism, in Brocade SANnav versions before v2.0, logs plaintext account credentials at the ‘trace’ and the 'debug' logging level; which could allow a local au…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10084

Published Nov 5, 2019

In Apache Impala 2.7.0 to 3.2.0, an authenticated user with access to the IDs of active Impala queries or sessions can interact with those sessions or queries via a specially-cons…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-17395

Published Oct 15, 2019

In the Rapid Gator application 0.7.1 for Android, the username and password are stored in the log during authentication, and may be available to attackers via logcat.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-17398

Published Oct 15, 2019

In the Dark Horse Comics application 1.3.21 for Android, token information (equivalent to the username and password) is stored in the log during authentication, and may be availab…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-17396

Published Oct 15, 2019

In the PowerSchool Mobile application 1.1.8 for Android, the username and password are stored in the log during authentication, and may be available to attackers via logcat.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-17394

Published Oct 15, 2019

In the Seesaw Parent and Family application 6.2.5 for Android, the username and password are stored in the log during authentication, and may be available to attackers via logcat.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-17355

Published Oct 15, 2019

In the Orbitz application 19.31.1 for Android, the username and password are stored in the log during authentication, and may be available to attackers via logcat.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-17397

Published Oct 15, 2019

In the DoorDash application through 11.5.2 for Android, the username and password are stored in the log during authentication, and may be available to attackers via logcat.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-4572

Published Oct 14, 2019

IBM FileNet Content Manager 5.5.2 and 5.5.3 in specific configurations, could log the web service user credentials into a log file that could be accessed by an administrator on th…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 951-975 of 1,163 CVEsPage 39 of 47