CWE-549 · 15 records
Missing Password Field Masking
CVEs in this class
15 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
30Monitor | CVE-2023-49106No exploit | Missing Password Field Masking Vulnerability in Hitachi Device Managerhitachi · device manager · CWE-549 | High7.5 | — | 0.4% | Jan 15, 2024 |
26Monitor | CVE-2025-42904No exploit | Information Disclosure vulnerability in Application Server ABAPsap_se · application server abap · CWE-549 | Medium6.5 | — | 0.3% | Dec 9, 2025 |
26Monitor | CVE-2023-1763No exploit | Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (supported OS: OS X 1canon · ij network tool · CWE-549 | Medium6.5 | — | 0.3% | May 16, 2023 |
26Monitor | CVE-2022-22550No exploit | Dell PowerScale OneFS, versions 8.2.2 and above, contain a password disclosure vulnerability.dell · emc powerscale onefs · CWE-549 | Medium6.7 | — | 0.2% | Apr 12, 2022 |
24Monitor | CVE-2023-2062No exploit | Information Disclosure vulnerability in EtherNet/IP Configuration toolsmitsubishielectric · fx5-enet\/ip firmware · CWE-549 | Medium6.2 | — | 0.3% | Jun 2, 2023 |
22Monitor | CVE-2025-31727No exploit | Jenkins AsakusaSatellite Plugin 0.1.1 and earlier stores AsakusaSatellite API keys unencrypted in job config.xml files on the Jenkins controjenkins · asakusasatellite · CWE-549 | Medium5.5 | — | 0.3% | Apr 2, 2025 |
22Monitor | CVE-2025-31728No exploit | Jenkins AsakusaSatellite Plugin 0.1.1 and earlier does not mask AsakusaSatellite API keys displayed on the job configuration form, increasinjenkins · asakusasatellite · CWE-549 | Medium5.5 | — | 0.3% | Apr 2, 2025 |
20Monitor | CVE-2024-10122No exploit | Topdata Inner Rep Plus WebServer Operator Details Form InnerRepPlus.html missing password field maskingtopdata · inner rep plus · CWE-549 | Medium5.1 | — | 0.5% | Oct 18, 2024 |
20Monitor | CVE-2025-13175No exploit | Insecure Password Storage in Y Soft SafeQ 6ysoft · safeq 6 · CWE-549 | Medium5.1 | — | 0.3% | Jan 14, 2026 |
19Monitor | CVE-2022-20914No exploit | Cisco Identity Services Engine Sensitive Information Disclosure Vulnerabilitycisco · identity services engine · CWE-549 | Medium4.9 | — | 1.0% | Aug 10, 2022 |
18Monitor | CVE-2022-1342No exploit | A lack of password masking in Devolutions Remote Desktop Manager allows physically proximate attackers to observe sensitive data.devolutions · remote desktop manager · CWE-549 | Medium4.6 | — | 0.4% | Jun 15, 2022 |
18Monitor | CVE-2026-3314No exploit | Missing Password Masking in Hitachi Infrastructure Analytics Advisor, Hitachi Ops Center Analyzer and Hitachi Ops Center Analyzer viewpointhitachi · hitachi ops center analyzer · CWE-549 | Medium4.6 | — | 0.2% | May 26, 2026 |
15Monitor | CVE-2025-64170No exploit | sudo-rs: Partial password reveal is possible after timeouttrifectatechfoundation · sudo-rs · CWE-549 | Low3.8 | — | 0.1% | Nov 12, 2025 |
12Monitor | CVE-2025-30197No exploit | Jenkins Zoho QEngine Plugin 1.0.29.vfa_cc23396502 and earlier does not mask the QEngine API Key form field, increasing the potential for attjenkins · zoho qengine · CWE-549 | Low3.1 | — | 0.3% | Mar 19, 2025 |
10Monitor | CVE-2025-0148No exploit | Zoom Jenkins Marketplace plugin - Missing Password Field Maskingzoom communications, inc · zoom jenkins marketplace plugin · CWE-549 | Low2.6 | — | 0.2% | Feb 3, 2025 |
- CVE-2023-4910630Monitor
Missing Password Field Masking Vulnerability in Hitachi Device Manager
HighCVSS 7.5No exploitEPSS 0%hitachi · device managerJan 15, 2024
- CVE-2025-4290426Monitor
Information Disclosure vulnerability in Application Server ABAP
MediumCVSS 6.5No exploitEPSS 0%sap_se · application server abapDec 9, 2025
- CVE-2023-176326Monitor
Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (supported OS: OS X 1
MediumCVSS 6.5No exploitEPSS 0%canon · ij network toolMay 16, 2023
- CVE-2022-2255026Monitor
Dell PowerScale OneFS, versions 8.2.2 and above, contain a password disclosure vulnerability.
MediumCVSS 6.7No exploitEPSS 0%dell · emc powerscale onefsApr 12, 2022
- CVE-2023-206224Monitor
Information Disclosure vulnerability in EtherNet/IP Configuration tools
MediumCVSS 6.2No exploitEPSS 0%mitsubishielectric · fx5-enet\/ip firmwareJun 2, 2023
- CVE-2025-3172722Monitor
Jenkins AsakusaSatellite Plugin 0.1.1 and earlier stores AsakusaSatellite API keys unencrypted in job config.xml files on the Jenkins contro
MediumCVSS 5.5No exploitEPSS 0%jenkins · asakusasatelliteApr 2, 2025
- CVE-2025-3172822Monitor
Jenkins AsakusaSatellite Plugin 0.1.1 and earlier does not mask AsakusaSatellite API keys displayed on the job configuration form, increasin
MediumCVSS 5.5No exploitEPSS 0%jenkins · asakusasatelliteApr 2, 2025
- CVE-2024-1012220Monitor
Topdata Inner Rep Plus WebServer Operator Details Form InnerRepPlus.html missing password field masking
MediumCVSS 5.1No exploitEPSS 0%topdata · inner rep plusOct 18, 2024
- CVE-2025-1317520Monitor
Insecure Password Storage in Y Soft SafeQ 6
MediumCVSS 5.1No exploitEPSS 0%ysoft · safeq 6Jan 14, 2026
- CVE-2022-2091419Monitor
Cisco Identity Services Engine Sensitive Information Disclosure Vulnerability
MediumCVSS 4.9No exploitEPSS 1%cisco · identity services engineAug 10, 2022
- CVE-2022-134218Monitor
A lack of password masking in Devolutions Remote Desktop Manager allows physically proximate attackers to observe sensitive data.
MediumCVSS 4.6No exploitEPSS 0%devolutions · remote desktop managerJun 15, 2022
- CVE-2026-331418Monitor
Missing Password Masking in Hitachi Infrastructure Analytics Advisor, Hitachi Ops Center Analyzer and Hitachi Ops Center Analyzer viewpoint
MediumCVSS 4.6No exploitEPSS 0%hitachi · hitachi ops center analyzerMay 26, 2026
- CVE-2025-6417015Monitor
sudo-rs: Partial password reveal is possible after timeout
LowCVSS 3.8No exploitEPSS 0%trifectatechfoundation · sudo-rsNov 12, 2025
- CVE-2025-3019712Monitor
Jenkins Zoho QEngine Plugin 1.0.29.vfa_cc23396502 and earlier does not mask the QEngine API Key form field, increasing the potential for att
LowCVSS 3.1No exploitEPSS 0%jenkins · zoho qengineMar 19, 2025
- CVE-2025-014810Monitor
Zoom Jenkins Marketplace plugin - Missing Password Field Masking
LowCVSS 2.6No exploitEPSS 0%zoom communications, inc · zoom jenkins marketplace pluginFeb 3, 2025