CWE-522 · 1 156 записей
Insufficiently Protected Credentials
CVE этого класса
1 158 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
96Срочно | CVE-2020-29583Готовый эксплойт | Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password.zyxel · usg20-vpn firmware · CWE-522 | Критическая9,8 | KEV | 90,2 % | 22 дек. 2020 г. |
95Срочно | CVE-2021-30116Готовый эксплойт | Unauthenticated credential leak and business logic flaw in Kaseya VSA <= v9.5.6kaseya · vsa agent · CWE-522 | Критическая9,8 | KEV | 85,7 % | 9 июл. 2021 г. |
92Срочно | CVE-2017-9248Готовый эксплойт | Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Teprogress · sitefinity · CWE-522 | Критическая9,8 | KEV | 75,1 % | 3 июл. 2017 г. |
88Срочно | CVE-2021-22681Готовый эксплойт | Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controckwellautomation · factorytalk services platform · CWE-522 | Критическая9,8 | KEV | 63,6 % | 3 мар. 2021 г. |
64На этой неделе | CVE-2024-44000Готовый эксплойт | WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerabilitylitespeedtech · litespeed cache · CWE-522 | Критическая9,8 | — | 82,3 % | 20 окт. 2024 г. |
62На этой неделе | CVE-2018-9160Готовый эксплойт | SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.sickrage · sickrage · CWE-522 | Критическая9,8 | — | 75,6 % | 31 мар. 2018 г. |
55В плане | CVE-2024-32238Proof of concept | H3C ER8300G2-X is vulnerable to Incorrect Access Control.CWE-522 | Критическая9,8 | — | 52,9 % | 22 апр. 2024 г. |
54В плане | CVE-2022-37109Proof of concept | patrickfuller camp up to and including commit bbd53a256ed70e79bd8758080936afbf6d738767 is vulnerable to Incorrect Access Control.camp project · camp · CWE-522 | Критическая9,8 | — | 49,5 % | 14 нояб. 2022 г. |
53В плане | CVE-2022-35411Proof of concept | rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header is sent.rpc.py project · rpc.py · CWE-522 | Критическая9,8 | — | 45,7 % | 8 июл. 2022 г. |
51В плане | CVE-2014-6039Готовый эксплойт | ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability.zohocorp · manageengine eventlog analyzer · CWE-522 | Высокая7,5 | — | 68,8 % | 13 янв. 2020 г. |
51В плане | CVE-2017-3192Эксплойта нет | D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 do not sufficiently protect administrator credentials.d-link · dir-130 firmware · CWE-522 | Критическая9,8 | — | 39,5 % | 15 дек. 2017 г. |
50В плане | CVE-2017-8225Proof of concept | On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is not correctly checked.wificam · wireless ip camera \(p2p\) firmware · CWE-522 | Критическая9,8 | — | 35,4 % | 25 апр. 2017 г. |
46В плане | CVE-2013-7052Proof of concept | D-Link DIR-100 4.03B07: security bypass via an error in the cliget.cgi scriptdlink · dir-100 firmware · CWE-522 | Критическая9,8 | — | 24,7 % | 4 февр. 2020 г. |
45В плане | CVE-2023-28131Эксплойта нет | A vulnerability in the expo.io framework allows an attacker to take over accounts and steal credentials on an application/website that confiexpo · expo software development kit · CWE-522 | Критическая9,6 | — | 23,2 % | 24 апр. 2023 г. |
44В плане | CVE-2017-17106Эксплойта нет | Credentials for Zivif PR115-204-P-RS V2.3.4.2103 Webcams can be obtained by an unauthenticated remote attacker using a standard web /cgi-binzivif · pr115-204-p-rs firmware · CWE-522 | Критическая9,8 | — | 15,3 % | 18 дек. 2017 г. |
43В плане | CVE-2018-11742Proof of concept | NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI.nec · univerge sv9100 webpro firmware · CWE-522 | Критическая9,8 | — | 14,3 % | 26 дек. 2018 г. |
42В плане | CVE-2000-0944Proof of concept | CGI Script Center News Update 1.1 does not properly validate the original news administration password during a password change operation, wcgi · script center news update · CWE-522 | Критическая9,8 | — | 11,3 % | 19 дек. 2000 г. |
41В плане | CVE-2019-1384Эксплойта нет | A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages.To exploit this microsoft · windows 10 · CWE-522 | Критическая9,9 | — | 7,6 % | 12 нояб. 2019 г. |
41В плане | CVE-2014-5381Proof of concept | Grand MA 300 allows a brute-force attack on the PIN.granding · grand ma300 firmware · CWE-522 | Критическая9,8 | — | 7,1 % | 13 янв. 2020 г. |
41В плане | CVE-2013-7055Proof of concept | D-Link DIR-100 4.03B07 has PPTP and poe information disclosuredlink · dir-100 firmware · CWE-522 | Критическая9,8 | — | 7,0 % | 4 февр. 2020 г. |
41В плане | CVE-2022-28005Эксплойта нет | An issue was discovered in the 3CX Phone System Management Console prior to version 18 Update 3 FINAL.3cx · 3cx · CWE-522 | Критическая9,8 | — | 6,7 % | 6 мая 2022 г. |
41В плане | CVE-2019-7260Эксплойта нет | Linear eMerge E3-Series devices have Cleartext Credentials in a Database.nortekcontrol · linear emerge essential firmware · CWE-522 | Критическая9,8 | — | 6,6 % | 2 июл. 2019 г. |
41В плане | CVE-2014-3445Эксплойта нет | backup.php in HandsomeWeb SOS Webpages before 1.1.12 does not require knowledge of the cleartext password, which allows remote attackers to handsomeweb · sos webpages · CWE-522 | Критическая9,8 | — | 5,3 % | 28 янв. 2020 г. |
41В плане | CVE-2007-0681Proof of concept | profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without providing the original pextcalendar project · extcalendar · CWE-522 | Критическая9,8 | — | 5,2 % | 2 февр. 2007 г. |
40В плане | CVE-2017-8837Proof of concept | Cleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hwpeplink · b305hw2 firmware · CWE-522 | Критическая9,8 | — | 4,9 % | 5 июн. 2017 г. |
- CVE-2020-2958396Срочно
Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 90 %zyxel · usg20-vpn firmware22 дек. 2020 г.
- CVE-2021-3011695Срочно
Unauthenticated credential leak and business logic flaw in Kaseya VSA <= v9.5.6
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 86 %kaseya · vsa agent9 июл. 2021 г.
- CVE-2017-924892Срочно
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Te
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 75 %progress · sitefinity3 июл. 2017 г.
- CVE-2021-2268188Срочно
Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix cont
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 64 %rockwellautomation · factorytalk services platform3 мар. 2021 г.
- CVE-2024-4400064На этой неделе
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
КритическаяCVSS 9,8Готовый эксплойтEPSS 82 %litespeedtech · litespeed cache20 окт. 2024 г.
- CVE-2018-916062На этой неделе
SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.
КритическаяCVSS 9,8Готовый эксплойтEPSS 76 %sickrage · sickrage31 мар. 2018 г.
- CVE-2024-3223855В плане
H3C ER8300G2-X is vulnerable to Incorrect Access Control.
КритическаяCVSS 9,8Proof of conceptEPSS 53 %22 апр. 2024 г.
- CVE-2022-3710954В плане
patrickfuller camp up to and including commit bbd53a256ed70e79bd8758080936afbf6d738767 is vulnerable to Incorrect Access Control.
КритическаяCVSS 9,8Proof of conceptEPSS 49 %camp project · camp14 нояб. 2022 г.
- CVE-2022-3541153В плане
rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header is sent.
КритическаяCVSS 9,8Proof of conceptEPSS 46 %rpc.py project · rpc.py8 июл. 2022 г.
- CVE-2014-603951В плане
ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability.
ВысокаяCVSS 7,5Готовый эксплойтEPSS 69 %zohocorp · manageengine eventlog analyzer13 янв. 2020 г.
- CVE-2017-319251В плане
D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 do not sufficiently protect administrator credentials.
КритическаяCVSS 9,8Эксплойта нетEPSS 39 %d-link · dir-130 firmware15 дек. 2017 г.
- CVE-2017-822550В плане
On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is not correctly checked.
КритическаяCVSS 9,8Proof of conceptEPSS 35 %wificam · wireless ip camera \(p2p\) firmware25 апр. 2017 г.
- CVE-2013-705246В плане
D-Link DIR-100 4.03B07: security bypass via an error in the cliget.cgi script
КритическаяCVSS 9,8Proof of conceptEPSS 25 %dlink · dir-100 firmware4 февр. 2020 г.
- CVE-2023-2813145В плане
A vulnerability in the expo.io framework allows an attacker to take over accounts and steal credentials on an application/website that confi
КритическаяCVSS 9,6Эксплойта нетEPSS 23 %expo · expo software development kit24 апр. 2023 г.
- CVE-2017-1710644В плане
Credentials for Zivif PR115-204-P-RS V2.3.4.2103 Webcams can be obtained by an unauthenticated remote attacker using a standard web /cgi-bin
КритическаяCVSS 9,8Эксплойта нетEPSS 15 %zivif · pr115-204-p-rs firmware18 дек. 2017 г.
- CVE-2018-1174243В плане
NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI.
КритическаяCVSS 9,8Proof of conceptEPSS 14 %nec · univerge sv9100 webpro firmware26 дек. 2018 г.
- CVE-2000-094442В плане
CGI Script Center News Update 1.1 does not properly validate the original news administration password during a password change operation, w
КритическаяCVSS 9,8Proof of conceptEPSS 11 %cgi · script center news update19 дек. 2000 г.
- CVE-2019-138441В плане
A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages.To exploit this
КритическаяCVSS 9,9Эксплойта нетEPSS 8 %microsoft · windows 1012 нояб. 2019 г.
- CVE-2014-538141В плане
Grand MA 300 allows a brute-force attack on the PIN.
КритическаяCVSS 9,8Proof of conceptEPSS 7 %granding · grand ma300 firmware13 янв. 2020 г.
- CVE-2013-705541В плане
D-Link DIR-100 4.03B07 has PPTP and poe information disclosure
КритическаяCVSS 9,8Proof of conceptEPSS 7 %dlink · dir-100 firmware4 февр. 2020 г.
- CVE-2022-2800541В плане
An issue was discovered in the 3CX Phone System Management Console prior to version 18 Update 3 FINAL.
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %3cx · 3cx6 мая 2022 г.
- CVE-2019-726041В плане
Linear eMerge E3-Series devices have Cleartext Credentials in a Database.
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %nortekcontrol · linear emerge essential firmware2 июл. 2019 г.
- CVE-2014-344541В плане
backup.php in HandsomeWeb SOS Webpages before 1.1.12 does not require knowledge of the cleartext password, which allows remote attackers to
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %handsomeweb · sos webpages28 янв. 2020 г.
- CVE-2007-068141В плане
profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without providing the original p
КритическаяCVSS 9,8Proof of conceptEPSS 5 %extcalendar project · extcalendar2 февр. 2007 г.
- CVE-2017-883740В плане
Cleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw
КритическаяCVSS 9,8Proof of conceptEPSS 5 %peplink · b305hw2 firmware5 июн. 2017 г.