CWE-260 · 23 записей
Password in Configuration File
CVE этого класса
23 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
54В плане | CVE-2017-7925Proof of concept | A Password in Configuration File issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-Idahuasecurity · dh-ipc-hdbw23a0rn-zs firmware · CWE-260 | Критическая9,8 | — | 51,4 % | 5 мая 2017 г. |
39Наблюдать | CVE-2016-7043Эксплойта нет | It has been reported that KIE server and Busitess Central before version 7.21.0.Final contain username and password as plaintext Java properredhat · kie-server · CWE-260 | Критическая9,8 | — | 1,5 % | 15 мая 2019 г. |
39Наблюдать | CVE-2023-34128Эксплойта нет | Tomcat application credentials are hardcoded in SonicWall GMS and Analytics configuration file.sonicwall · analytics · CWE-260 | Критическая9,8 | — | 0,7 % | 12 июл. 2023 г. |
39Наблюдать | CVE-2023-53739Эксплойта нет | Tinycontrol LAN Controller v3 LK3 1.58a Unauthenticated Configuration Backup Disclosuretinycontrol · tinycontrol lan controller v · CWE-260 | Критическая9,9 | — | 0,6 % | 9 дек. 2025 г. |
39Наблюдать | CVE-2025-57754Эксплойта нет | eslint-ban-moment exposed a sensitive Supabase URI in .env (Credential leak)kristoferfannar · eslint-ban-moment · CWE-260 | Критическая9,8 | — | 0,4 % | 21 авг. 2025 г. |
37Наблюдать | CVE-2025-6513Эксплойта нет | BRAIN2 Configuration file for database access not sufficiently securedbizerba se & co. kg · brain2 · CWE-260 | Критическая9,3 | — | 0,2 % | 23 июн. 2025 г. |
36Наблюдать | CVE-2017-7923Эксплойта нет | A Password in Configuration File issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xhikvision · ds-2cd2032-i firmware · CWE-260 | Высокая8,8 | — | 2,4 % | 5 мая 2017 г. |
35Наблюдать | CVE-2019-3780Эксплойта нет | Cloud Foundry Container Runtime Leaks IAAS Credentialscloudfoundry · container runtime · CWE-260 | Высокая8,8 | — | 1,4 % | 8 мар. 2019 г. |
35Наблюдать | CVE-2025-25022Эксплойта нет | IBM QRadar Suite Software and IBM Cloud Pak for Security information disclosureibm · cloud pak for security · CWE-260 | Высокая8,8 | — | 0,3 % | 3 июн. 2025 г. |
34Наблюдать | CVE-2023-53770Эксплойта нет | MiniDVBLinux 5.4 Unauthenticated Configuration Download via Backup Endpointminidvblinux · minidvblinux · CWE-260 | Высокая8,7 | — | 0,5 % | 9 дек. 2025 г. |
34Наблюдать | CVE-2019-25465Эксплойта нет | Hisilicon HiIpcam V100R003 Information Disclosure via Directory Traversalhisilicon · hiipcam · CWE-260 | Высокая8,7 | — | 0,5 % | 11 мар. 2026 г. |
34Наблюдать | CVE-2025-32111Эксплойта нет | The Docker image from acme.sh before 40b6db6 is based on a .github/workflows/dockerhub.yml file that lacks "persist-credentials: false" for acme.sh project · acme.sh · CWE-260 | Высокая8,7 | — | 0,4 % | 4 апр. 2025 г. |
31Наблюдать | CVE-2021-35033Эксплойта нет | A vulnerability in specific versions of Zyxel NBG6818, NBG7815, WSQ20, WSQ50, WSQ60, and WSR30 firmware with pre-configured password managemzyxel · nbg6818 firmware · CWE-260 | Высокая7,8 | — | 0,4 % | 23 нояб. 2021 г. |
30Наблюдать | CVE-2025-33093Эксплойта нет | IBM Sterling Partner Engagement Manager information disclosureibm · sterling partner engagement manager · CWE-260 | Высокая7,5 | — | 0,4 % | 7 мая 2025 г. |
26Наблюдать | CVE-2025-33119Эксплойта нет | IBM QRadar SIEM Information Disclosureibm · qradar security information and event manager · CWE-260 | Средняя6,5 | — | 0,2 % | 12 нояб. 2025 г. |
22Наблюдать | CVE-2020-5721Эксплойта нет | MikroTik WinBox 3.22 and below stores the user's cleartext password in the settings.cfg.viw configuration file when the Keep Password field mikrotik · winbox · CWE-260 | Средняя5,5 | — | 0,4 % | 15 апр. 2020 г. |
22Наблюдать | CVE-2023-2790Эксплойта нет | TOTOLINK N200RE Telnet Service custom.conf password in configuration filetotolink · n200re firmware · CWE-260 | Средняя5,5 | — | 0,3 % | 18 мая 2023 г. |
22Наблюдать | CVE-2025-36002Эксплойта нет | IBM Sterling B2B Integrator information disclosureibm · sterling b2b integrator · CWE-260 | Средняя5,5 | — | 0,2 % | 16 окт. 2025 г. |
22Наблюдать | CVE-2024-45673Эксплойта нет | IBM Security Verify Bridge information disclosureibm · security verify bridge directory sync · CWE-260 | Средняя5,5 | — | 0,1 % | 21 февр. 2025 г. |
22Наблюдать | CVE-2025-36100Эксплойта нет | IBM MQ information disclosureibm · mq · CWE-260 | Средняя5,5 | — | 0,1 % | 6 сент. 2025 г. |
21Наблюдать | CVE-2025-51540Эксплойта нет | EzGED3 3.5.0 stores user passwords using an insecure hashing scheme: md5(md5(password)).CWE-260 | Средняя5,3 | — | 0,2 % | 19 авг. 2025 г. |
17Наблюдать | CVE-2024-49817Эксплойта нет | IBM Security Guardium Key Lifecycle Manager information disclosureibm · security guardium key lifecycle manager · CWE-260 | Средняя4,4 | — | 0,2 % | 17 дек. 2024 г. |
8Наблюдать | CVE-2014-5400Эксплойта нет | Hospira MedNet Password in Configuration Filehospira · mednet · CWE-260 | Низкая2,1 | — | 0,3 % | 3 апр. 2015 г. |
- CVE-2017-792554В плане
A Password in Configuration File issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-I
КритическаяCVSS 9,8Proof of conceptEPSS 51 %dahuasecurity · dh-ipc-hdbw23a0rn-zs firmware5 мая 2017 г.
- CVE-2016-704339Наблюдать
It has been reported that KIE server and Busitess Central before version 7.21.0.Final contain username and password as plaintext Java proper
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %redhat · kie-server15 мая 2019 г.
- CVE-2023-3412839Наблюдать
Tomcat application credentials are hardcoded in SonicWall GMS and Analytics configuration file.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %sonicwall · analytics12 июл. 2023 г.
- CVE-2023-5373939Наблюдать
Tinycontrol LAN Controller v3 LK3 1.58a Unauthenticated Configuration Backup Disclosure
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %tinycontrol · tinycontrol lan controller v9 дек. 2025 г.
- CVE-2025-5775439Наблюдать
eslint-ban-moment exposed a sensitive Supabase URI in .env (Credential leak)
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %kristoferfannar · eslint-ban-moment21 авг. 2025 г.
- CVE-2025-651337Наблюдать
BRAIN2 Configuration file for database access not sufficiently secured
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %bizerba se & co. kg · brain223 июн. 2025 г.
- CVE-2017-792336Наблюдать
A Password in Configuration File issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2x
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %hikvision · ds-2cd2032-i firmware5 мая 2017 г.
- CVE-2019-378035Наблюдать
Cloud Foundry Container Runtime Leaks IAAS Credentials
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %cloudfoundry · container runtime8 мар. 2019 г.
- CVE-2025-2502235Наблюдать
IBM QRadar Suite Software and IBM Cloud Pak for Security information disclosure
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %ibm · cloud pak for security3 июн. 2025 г.
- CVE-2023-5377034Наблюдать
MiniDVBLinux 5.4 Unauthenticated Configuration Download via Backup Endpoint
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %minidvblinux · minidvblinux9 дек. 2025 г.
- CVE-2019-2546534Наблюдать
Hisilicon HiIpcam V100R003 Information Disclosure via Directory Traversal
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %hisilicon · hiipcam11 мар. 2026 г.
- CVE-2025-3211134Наблюдать
The Docker image from acme.sh before 40b6db6 is based on a .github/workflows/dockerhub.yml file that lacks "persist-credentials: false" for
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %acme.sh project · acme.sh4 апр. 2025 г.
- CVE-2021-3503331Наблюдать
A vulnerability in specific versions of Zyxel NBG6818, NBG7815, WSQ20, WSQ50, WSQ60, and WSR30 firmware with pre-configured password managem
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %zyxel · nbg6818 firmware23 нояб. 2021 г.
- CVE-2025-3309330Наблюдать
IBM Sterling Partner Engagement Manager information disclosure
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %ibm · sterling partner engagement manager7 мая 2025 г.
- CVE-2025-3311926Наблюдать
IBM QRadar SIEM Information Disclosure
СредняяCVSS 6,5Эксплойта нетEPSS 0 %ibm · qradar security information and event manager12 нояб. 2025 г.
- CVE-2020-572122Наблюдать
MikroTik WinBox 3.22 and below stores the user's cleartext password in the settings.cfg.viw configuration file when the Keep Password field
СредняяCVSS 5,5Эксплойта нетEPSS 0 %mikrotik · winbox15 апр. 2020 г.
- CVE-2023-279022Наблюдать
TOTOLINK N200RE Telnet Service custom.conf password in configuration file
СредняяCVSS 5,5Эксплойта нетEPSS 0 %totolink · n200re firmware18 мая 2023 г.
- CVE-2025-3600222Наблюдать
IBM Sterling B2B Integrator information disclosure
СредняяCVSS 5,5Эксплойта нетEPSS 0 %ibm · sterling b2b integrator16 окт. 2025 г.
- CVE-2024-4567322Наблюдать
IBM Security Verify Bridge information disclosure
СредняяCVSS 5,5Эксплойта нетEPSS 0 %ibm · security verify bridge directory sync21 февр. 2025 г.
- CVE-2025-3610022Наблюдать
IBM MQ information disclosure
СредняяCVSS 5,5Эксплойта нетEPSS 0 %ibm · mq6 сент. 2025 г.
- CVE-2025-5154021Наблюдать
EzGED3 3.5.0 stores user passwords using an insecure hashing scheme: md5(md5(password)).
СредняяCVSS 5,3Эксплойта нетEPSS 0 %19 авг. 2025 г.
- CVE-2024-4981717Наблюдать
IBM Security Guardium Key Lifecycle Manager information disclosure
СредняяCVSS 4,4Эксплойта нетEPSS 0 %ibm · security guardium key lifecycle manager17 дек. 2024 г.
- CVE-2014-54008Наблюдать
Hospira MedNet Password in Configuration File
НизкаяCVSS 2,1Эксплойта нетEPSS 0 %hospira · mednet3 апр. 2015 г.