CWE-257 · 67 записей
Storing Passwords in a Recoverable Format
CVE этого класса
67 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
62На этой неделе | CVE-2026-20128Готовый эксплойт | Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerabilitycisco · catalyst sd-wan manager · CWE-257 | Высокая7,5 | KEV | 7,1 % | 25 февр. 2026 г. |
39Наблюдать | CVE-2022-32519Эксплойта нет | A CWE-257: Storing Passwords in a Recoverable Format vulnerability exists that could result in unwanted access to a DCE instance when perforschneider-electric · data center expert · CWE-257 | Критическая9,8 | — | 0,5 % | 30 янв. 2023 г. |
39Наблюдать | CVE-2023-0353Эксплойта нет | Akuvox E11 uses a weak encryption algorithm for stored passwords and uses a hard-coded password for decryption which could allow the encryptakuvox · e11 firmware · CWE-257 | Критическая9,8 | — | 0,4 % | 13 мар. 2023 г. |
36Наблюдать | CVE-2025-8904Эксплойта нет | Privilege escalation issue in Amazon EMR Secret Agent componentamazon · emr · CWE-257 | Критическая9,0 | — | 0,4 % | 13 авг. 2025 г. |
36Наблюдать | CVE-2025-8095Эксплойта нет | Recoverable obfuscation using the OECH1 prefix encoding in OpenEdgeprogress software corporation · openedge · CWE-257 | Критическая9,1 | — | 0,2 % | 14 апр. 2026 г. |
34Наблюдать | CVE-2016-15058Эксплойта нет | Hirschmann HiLCOS Classic Platform Password Exposure via SNMPbelden · hirschmann hilcos classic platform · CWE-257 | Высокая8,6 | — | 0,2 % | 3 апр. 2026 г. |
33Наблюдать | CVE-2025-6995Эксплойта нет | Improper Encryption in Ivanti Endpoint Managerivanti · endpoint manager · CWE-257 | Высокая8,4 | — | 0,2 % | 8 июл. 2025 г. |
33Наблюдать | CVE-2025-6996Эксплойта нет | Improper Encryption in Ivanti Endpoint Managerivanti · endpoint manager · CWE-257 | Высокая8,4 | — | 0,2 % | 8 июл. 2025 г. |
33Наблюдать | CVE-2025-34180Эксплойта нет | NetSupport Manager < 14.12.0001 Gateway Key Reversible Encoding Credential Recoverynetsupport software · manager · CWE-257 | Высокая8,4 | — | 0,2 % | 15 дек. 2025 г. |
33Наблюдать | CVE-2022-34838Эксплойта нет | ABB Ability TM Operations Data Management Zenon Zenon Log Server file access controlabb · zenon · CWE-257 | Высокая8,4 | — | 0,2 % | 24 авг. 2022 г. |
32Наблюдать | CVE-2023-38738Эксплойта нет | IBM OpenPages with Watson information disclosureibm · openpages with watson · CWE-257 | Высокая8,1 | — | 0,5 % | 18 янв. 2024 г. |
32Наблюдать | CVE-2026-30785Эксплойта нет | RustDesk Encrypts Local Passwords with World-Readable Machine ID and Fixed Zero Nonce (XSalsa20-Poly1305)rustdesk · rustdesk · CWE-257 | Высокая8,2 | — | 0,1 % | 5 мар. 2026 г. |
31Наблюдать | CVE-2023-21726Эксплойта нет | Windows Credential Manager User Interface Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1607 · CWE-257 | Высокая7,8 | — | 0,5 % | 10 янв. 2023 г. |
31Наблюдать | CVE-2017-9942Эксплойта нет | A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with local access to thsiemens · sipass integrated · CWE-257 | Высокая7,8 | — | 0,3 % | 7 авг. 2017 г. |
31Наблюдать | CVE-2022-22251Эксплойта нет | cSRX Series: Storing Passwords in a Recoverable Format and software permissions issues allows a local attacker to elevate privilegesjuniper · junos · CWE-257 | Высокая7,8 | — | 0,2 % | 17 окт. 2022 г. |
30Наблюдать | CVE-2021-27485Эксплойта нет | ZOLL Defibrillator Dashboard, v prior to 2.2,The application allows users to store their passwords in a recoverable format, which could allozoll · defibrillator dashboard · CWE-257 | Высокая7,5 | — | 1,2 % | 16 июн. 2021 г. |
30Наблюдать | CVE-2021-35050Эксплойта нет | User Credentials Stored in a Recoverable Format within Fidelis Network and Deceptionfidelissecurity · deception · CWE-257 | Высокая7,5 | — | 1,0 % | 25 июн. 2021 г. |
30Наблюдать | CVE-2024-1480Эксплойта нет | Unitronics Vision Standard Unauthenticated Password Retrievalunitronics · vision230 · CWE-257 | Высокая7,5 | — | 0,5 % | 19 апр. 2024 г. |
30Наблюдать | CVE-2024-32042Эксплойта нет | CyberPower PowerPanel business Storing Passwords in a Recoverable Formatcyberpower · powerpanel · CWE-257 | Высокая7,5 | — | 0,4 % | 15 мая 2024 г. |
30Наблюдать | CVE-2025-44958Эксплойта нет | RUCKUS Network Director (RND) before 4.5 stores passwords in a recoverable format.commscope · ruckus network director · CWE-257 | Высокая7,5 | — | 0,3 % | 4 авг. 2025 г. |
30Наблюдать | CVE-2024-8774Эксплойта нет | Privilege Escalation in SIMPLE.ERPsimple sa · simple.erp · CWE-257 | Высокая7,7 | — | 0,3 % | 24 мар. 2025 г. |
30Наблюдать | CVE-2023-5627Эксплойта нет | Incorrect Implementation of Authentication Algorithm Vulnerabilitymoxa · nport 6150-t firmware · CWE-257 | Высокая7,5 | — | 0,3 % | 1 нояб. 2023 г. |
30Наблюдать | CVE-2024-3543Эксплойта нет | LoadMaster Reversible Password Encryption Algorithmprogress · loadmaster · CWE-257 | Высокая7,5 | — | 0,3 % | 2 мая 2024 г. |
30Наблюдать | CVE-2026-65309Эксплойта нет | Storage of passwords in a reversible formatandritz · hipase-250 · CWE-257 | Высокая7,5 | — | 0,2 % | 31 июл. 2026 г. |
30Наблюдать | CVE-2025-27459Эксплойта нет | The VNC application stores its passwords encrypted within the registry but uses DES for encryption.endress · meac300-fnade4 firmware · CWE-257 | Высокая7,5 | — | 0,2 % | 3 июл. 2025 г. |
- CVE-2026-2012862На этой неделе
Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 7 %cisco · catalyst sd-wan manager25 февр. 2026 г.
- CVE-2022-3251939Наблюдать
A CWE-257: Storing Passwords in a Recoverable Format vulnerability exists that could result in unwanted access to a DCE instance when perfor
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %schneider-electric · data center expert30 янв. 2023 г.
- CVE-2023-035339Наблюдать
Akuvox E11 uses a weak encryption algorithm for stored passwords and uses a hard-coded password for decryption which could allow the encrypt
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %akuvox · e11 firmware13 мар. 2023 г.
- CVE-2025-890436Наблюдать
Privilege escalation issue in Amazon EMR Secret Agent component
КритическаяCVSS 9,0Эксплойта нетEPSS 0 %amazon · emr13 авг. 2025 г.
- CVE-2025-809536Наблюдать
Recoverable obfuscation using the OECH1 prefix encoding in OpenEdge
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %progress software corporation · openedge14 апр. 2026 г.
- CVE-2016-1505834Наблюдать
Hirschmann HiLCOS Classic Platform Password Exposure via SNMP
ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %belden · hirschmann hilcos classic platform3 апр. 2026 г.
- CVE-2025-699533Наблюдать
Improper Encryption in Ivanti Endpoint Manager
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %ivanti · endpoint manager8 июл. 2025 г.
- CVE-2025-699633Наблюдать
Improper Encryption in Ivanti Endpoint Manager
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %ivanti · endpoint manager8 июл. 2025 г.
- CVE-2025-3418033Наблюдать
NetSupport Manager < 14.12.0001 Gateway Key Reversible Encoding Credential Recovery
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %netsupport software · manager15 дек. 2025 г.
- CVE-2022-3483833Наблюдать
ABB Ability TM Operations Data Management Zenon Zenon Log Server file access control
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %abb · zenon24 авг. 2022 г.
- CVE-2023-3873832Наблюдать
IBM OpenPages with Watson information disclosure
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %ibm · openpages with watson18 янв. 2024 г.
- CVE-2026-3078532Наблюдать
RustDesk Encrypts Local Passwords with World-Readable Machine ID and Fixed Zero Nonce (XSalsa20-Poly1305)
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %rustdesk · rustdesk5 мар. 2026 г.
- CVE-2023-2172631Наблюдать
Windows Credential Manager User Interface Elevation of Privilege Vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %microsoft · windows 10 160710 янв. 2023 г.
- CVE-2017-994231Наблюдать
A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with local access to th
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %siemens · sipass integrated7 авг. 2017 г.
- CVE-2022-2225131Наблюдать
cSRX Series: Storing Passwords in a Recoverable Format and software permissions issues allows a local attacker to elevate privileges
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %juniper · junos17 окт. 2022 г.
- CVE-2021-2748530Наблюдать
ZOLL Defibrillator Dashboard, v prior to 2.2,The application allows users to store their passwords in a recoverable format, which could allo
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %zoll · defibrillator dashboard16 июн. 2021 г.
- CVE-2021-3505030Наблюдать
User Credentials Stored in a Recoverable Format within Fidelis Network and Deception
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %fidelissecurity · deception25 июн. 2021 г.
- CVE-2024-148030Наблюдать
Unitronics Vision Standard Unauthenticated Password Retrieval
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %unitronics · vision23019 апр. 2024 г.
- CVE-2024-3204230Наблюдать
CyberPower PowerPanel business Storing Passwords in a Recoverable Format
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %cyberpower · powerpanel15 мая 2024 г.
- CVE-2025-4495830Наблюдать
RUCKUS Network Director (RND) before 4.5 stores passwords in a recoverable format.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %commscope · ruckus network director4 авг. 2025 г.
- CVE-2024-877430Наблюдать
Privilege Escalation in SIMPLE.ERP
ВысокаяCVSS 7,7Эксплойта нетEPSS 0 %simple sa · simple.erp24 мар. 2025 г.
- CVE-2023-562730Наблюдать
Incorrect Implementation of Authentication Algorithm Vulnerability
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %moxa · nport 6150-t firmware1 нояб. 2023 г.
- CVE-2024-354330Наблюдать
LoadMaster Reversible Password Encryption Algorithm
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %progress · loadmaster2 мая 2024 г.
- CVE-2026-6530930Наблюдать
Storage of passwords in a reversible format
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %andritz · hipase-25031 июл. 2026 г.
- CVE-2025-2745930Наблюдать
The VNC application stores its passwords encrypted within the registry but uses DES for encryption.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %endress · meac300-fnade4 firmware3 июл. 2025 г.