Skip to main content

CWE archive

CWE-549 CVEs

Programmatic archive

16 CVEs tagged with CWE-5490 Critical, 0 High, 12 Medium, 4 Low, 0 Unrated.

CVE-2026-3314

Published May 26, 2026

Missing password field masking vulnerability in Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view, Hitachi Ops Center Analyzer probe modules), Hitachi Ops Cente…

CVSS 4.6 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-13175

Published Jan 14, 2026

Y Soft SafeQ 6 renders the Workflow Connector password field in a way that allows an administrator with UI access to reveal the value using browser developer/inspection tools. The…

CVSS 5.1 · Medium
evidence mentions
3
Buzz score
25.4

CVE-2025-42904

Published Dec 9, 2025

Due to an Information Disclosure vulnerability in Application Server ABAP, an authenticated attacker could read unmasked values displayed in ABAP Lists. Successful exploitation co…

CVSS 6.5 · Medium

CVE-2025-64170

Published Nov 12, 2025

sudo-rs is a memory safe implementation of sudo and su written in Rust. Starting in version 0.2.7 and prior to version 0.2.10, if a user begins entering a password but does not pr…

CVSS 3.8 · Low

CVE-2025-4526

Published May 11, 2025

A vulnerability was identified in Dígitro NGC Explorer up to 3.44.15/3.48.21. The affected element is an unknown function of the component Configuration Page. Such manipulation le…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-31728

Published Apr 2, 2025

Jenkins AsakusaSatellite Plugin 0.1.1 and earlier does not mask AsakusaSatellite API keys displayed on the job configuration form, increasing the potential for attackers to observ…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-31727

Published Apr 2, 2025

Jenkins AsakusaSatellite Plugin 0.1.1 and earlier stores AsakusaSatellite API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-30197

Published Mar 19, 2025

Jenkins Zoho QEngine Plugin 1.0.29.vfa_cc23396502 and earlier does not mask the QEngine API Key form field, increasing the potential for attackers to observe and capture it.

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-0148

Published Feb 3, 2025

Missing password field masking in the Zoom Jenkins Marketplace plugin before version 1.6 may allow an unauthenticated user to conduct a disclosure of information via adjacent netw…

CVSS 2.6 · Low
evidence mentions
1
Buzz score
11.9

CVE-2024-10122

Published Oct 18, 2024

A vulnerability was found in Topdata Inner Rep Plus WebServer 2.01. It has been classified as problematic. Affected is an unknown function of the file /InnerRepPlus.html of the co…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-2062

Published Jun 2, 2023

Missing Password Field Masking vulnerability in Mitsubishi Electric Corporation EtherNet/IP configuration tools SW1DNN-EIPCT-BD and SW1DNN-EIPCTFX5-BD allows a remote unauthentica…

CVSS 6.2 · Medium

CVE-2022-20914

Published Aug 10, 2022

A vulnerability in the External RESTful Services (ERS) API of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker to obtain sensitive infor…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1342

Published Jun 15, 2022

A lack of password masking in Devolutions Remote Desktop Manager allows physically proximate attackers to observe sensitive data. A caching issue can cause sensitive fields to som…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-22550

Published Apr 12, 2022

Dell PowerScale OneFS, versions 8.2.2 and above, contain a password disclosure vulnerability. An unprivileged local attacker could potentially exploit this vulnerability, leading…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-16 of 16 CVEsPage 1 of 1