Перейти к содержимому
Noroxi

CWE-260 · 23 записей

Password in Configuration File

CVE этого класса

23 записей

  • CVE-2017-7925
    54В плане

    A Password in Configuration File issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-I

    КритическаяCVSS 9,8Proof of conceptEPSS 51 %

    dahuasecurity · dh-ipc-hdbw23a0rn-zs firmware5 мая 2017 г.

  • CVE-2016-7043
    39Наблюдать

    It has been reported that KIE server and Busitess Central before version 7.21.0.Final contain username and password as plaintext Java proper

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    redhat · kie-server15 мая 2019 г.

  • CVE-2023-34128
    39Наблюдать

    Tomcat application credentials are hardcoded in SonicWall GMS and Analytics configuration file.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    sonicwall · analytics12 июл. 2023 г.

  • CVE-2023-53739
    39Наблюдать

    Tinycontrol LAN Controller v3 LK3 1.58a Unauthenticated Configuration Backup Disclosure

    КритическаяCVSS 9,9Эксплойта нетEPSS 1 %

    tinycontrol · tinycontrol lan controller v9 дек. 2025 г.

  • CVE-2025-57754
    39Наблюдать

    eslint-ban-moment exposed a sensitive Supabase URI in .env (Credential leak)

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    kristoferfannar · eslint-ban-moment21 авг. 2025 г.

  • CVE-2025-6513
    37Наблюдать

    BRAIN2 Configuration file for database access not sufficiently secured

    КритическаяCVSS 9,3Эксплойта нетEPSS 0 %

    bizerba se & co. kg · brain223 июн. 2025 г.

  • CVE-2017-7923
    36Наблюдать

    A Password in Configuration File issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2x

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    hikvision · ds-2cd2032-i firmware5 мая 2017 г.

  • CVE-2019-3780
    35Наблюдать

    Cloud Foundry Container Runtime Leaks IAAS Credentials

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    cloudfoundry · container runtime8 мар. 2019 г.

  • CVE-2025-25022
    35Наблюдать

    IBM QRadar Suite Software and IBM Cloud Pak for Security information disclosure

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    ibm · cloud pak for security3 июн. 2025 г.

  • CVE-2023-53770
    34Наблюдать

    MiniDVBLinux 5.4 Unauthenticated Configuration Download via Backup Endpoint

    ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %

    minidvblinux · minidvblinux9 дек. 2025 г.

  • CVE-2019-25465
    34Наблюдать

    Hisilicon HiIpcam V100R003 Information Disclosure via Directory Traversal

    ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %

    hisilicon · hiipcam11 мар. 2026 г.

  • CVE-2025-32111
    34Наблюдать

    The Docker image from acme.sh before 40b6db6 is based on a .github/workflows/dockerhub.yml file that lacks "persist-credentials: false" for

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    acme.sh project · acme.sh4 апр. 2025 г.

  • CVE-2021-35033
    31Наблюдать

    A vulnerability in specific versions of Zyxel NBG6818, NBG7815, WSQ20, WSQ50, WSQ60, and WSR30 firmware with pre-configured password managem

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    zyxel · nbg6818 firmware23 нояб. 2021 г.

  • CVE-2025-33093
    30Наблюдать

    IBM Sterling Partner Engagement Manager information disclosure

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    ibm · sterling partner engagement manager7 мая 2025 г.

  • CVE-2025-33119
    26Наблюдать

    IBM QRadar SIEM Information Disclosure

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    ibm · qradar security information and event manager12 нояб. 2025 г.

  • CVE-2020-5721
    22Наблюдать

    MikroTik WinBox 3.22 and below stores the user's cleartext password in the settings.cfg.viw configuration file when the Keep Password field

    СредняяCVSS 5,5Эксплойта нетEPSS 0 %

    mikrotik · winbox15 апр. 2020 г.

  • CVE-2023-2790
    22Наблюдать

    TOTOLINK N200RE Telnet Service custom.conf password in configuration file

    СредняяCVSS 5,5Эксплойта нетEPSS 0 %

    totolink · n200re firmware18 мая 2023 г.

  • CVE-2025-36002
    22Наблюдать

    IBM Sterling B2B Integrator information disclosure

    СредняяCVSS 5,5Эксплойта нетEPSS 0 %

    ibm · sterling b2b integrator16 окт. 2025 г.

  • CVE-2024-45673
    22Наблюдать

    IBM Security Verify Bridge information disclosure

    СредняяCVSS 5,5Эксплойта нетEPSS 0 %

    ibm · security verify bridge directory sync21 февр. 2025 г.

  • CVE-2025-36100
    22Наблюдать

    IBM MQ information disclosure

    СредняяCVSS 5,5Эксплойта нетEPSS 0 %

    ibm · mq6 сент. 2025 г.

  • CVE-2025-51540
    21Наблюдать

    EzGED3 3.5.0 stores user passwords using an insecure hashing scheme: md5(md5(password)).

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    19 авг. 2025 г.

  • CVE-2024-49817
    17Наблюдать

    IBM Security Guardium Key Lifecycle Manager information disclosure

    СредняяCVSS 4,4Эксплойта нетEPSS 0 %

    ibm · security guardium key lifecycle manager17 дек. 2024 г.

  • CVE-2014-5400
    8Наблюдать

    Hospira MedNet Password in Configuration File

    НизкаяCVSS 2,1Эксплойта нетEPSS 0 %

    hospira · mednet3 апр. 2015 г.

Все классы уязвимостей