CWE-522 · 1.156 kayıt
Insufficiently Protected Credentials
Bu sınıftaki CVE’ler
1.158 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
96Hemen | CVE-2020-29583Silahlaştırılmış | Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password.zyxel · usg20-vpn firmware · CWE-522 | Kritik9,8 | KEV | %90,2 | 22 Ara 2020 |
95Hemen | CVE-2021-30116Silahlaştırılmış | Unauthenticated credential leak and business logic flaw in Kaseya VSA <= v9.5.6kaseya · vsa agent · CWE-522 | Kritik9,8 | KEV | %85,7 | 9 Tem 2021 |
92Hemen | CVE-2017-9248Silahlaştırılmış | Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Teprogress · sitefinity · CWE-522 | Kritik9,8 | KEV | %75,1 | 3 Tem 2017 |
88Hemen | CVE-2021-22681Silahlaştırılmış | Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controckwellautomation · factorytalk services platform · CWE-522 | Kritik9,8 | KEV | %63,6 | 3 Mar 2021 |
64Bu hafta | CVE-2024-44000Silahlaştırılmış | WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerabilitylitespeedtech · litespeed cache · CWE-522 | Kritik9,8 | — | %82,3 | 20 Eki 2024 |
62Bu hafta | CVE-2018-9160Silahlaştırılmış | SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.sickrage · sickrage · CWE-522 | Kritik9,8 | — | %75,6 | 31 Mar 2018 |
55Planlayın | CVE-2024-32238Kavram kanıtı | H3C ER8300G2-X is vulnerable to Incorrect Access Control.CWE-522 | Kritik9,8 | — | %52,9 | 22 Nis 2024 |
54Planlayın | CVE-2022-37109Kavram kanıtı | patrickfuller camp up to and including commit bbd53a256ed70e79bd8758080936afbf6d738767 is vulnerable to Incorrect Access Control.camp project · camp · CWE-522 | Kritik9,8 | — | %49,5 | 14 Kas 2022 |
53Planlayın | CVE-2022-35411Kavram kanıtı | rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header is sent.rpc.py project · rpc.py · CWE-522 | Kritik9,8 | — | %45,7 | 8 Tem 2022 |
51Planlayın | CVE-2014-6039Silahlaştırılmış | ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability.zohocorp · manageengine eventlog analyzer · CWE-522 | Yüksek7,5 | — | %68,8 | 13 Oca 2020 |
51Planlayın | CVE-2017-3192İstismar yok | D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 do not sufficiently protect administrator credentials.d-link · dir-130 firmware · CWE-522 | Kritik9,8 | — | %39,5 | 15 Ara 2017 |
50Planlayın | CVE-2017-8225Kavram kanıtı | On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is not correctly checked.wificam · wireless ip camera \(p2p\) firmware · CWE-522 | Kritik9,8 | — | %35,4 | 25 Nis 2017 |
46Planlayın | CVE-2013-7052Kavram kanıtı | D-Link DIR-100 4.03B07: security bypass via an error in the cliget.cgi scriptdlink · dir-100 firmware · CWE-522 | Kritik9,8 | — | %24,7 | 4 Şub 2020 |
45Planlayın | CVE-2023-28131İstismar yok | A vulnerability in the expo.io framework allows an attacker to take over accounts and steal credentials on an application/website that confiexpo · expo software development kit · CWE-522 | Kritik9,6 | — | %23,2 | 24 Nis 2023 |
44Planlayın | CVE-2017-17106İstismar yok | Credentials for Zivif PR115-204-P-RS V2.3.4.2103 Webcams can be obtained by an unauthenticated remote attacker using a standard web /cgi-binzivif · pr115-204-p-rs firmware · CWE-522 | Kritik9,8 | — | %15,3 | 18 Ara 2017 |
43Planlayın | CVE-2018-11742Kavram kanıtı | NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI.nec · univerge sv9100 webpro firmware · CWE-522 | Kritik9,8 | — | %14,3 | 26 Ara 2018 |
42Planlayın | CVE-2000-0944Kavram kanıtı | CGI Script Center News Update 1.1 does not properly validate the original news administration password during a password change operation, wcgi · script center news update · CWE-522 | Kritik9,8 | — | %11,3 | 19 Ara 2000 |
41Planlayın | CVE-2019-1384İstismar yok | A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages.To exploit this microsoft · windows 10 · CWE-522 | Kritik9,9 | — | %7,6 | 12 Kas 2019 |
41Planlayın | CVE-2014-5381Kavram kanıtı | Grand MA 300 allows a brute-force attack on the PIN.granding · grand ma300 firmware · CWE-522 | Kritik9,8 | — | %7,1 | 13 Oca 2020 |
41Planlayın | CVE-2013-7055Kavram kanıtı | D-Link DIR-100 4.03B07 has PPTP and poe information disclosuredlink · dir-100 firmware · CWE-522 | Kritik9,8 | — | %7,0 | 4 Şub 2020 |
41Planlayın | CVE-2022-28005İstismar yok | An issue was discovered in the 3CX Phone System Management Console prior to version 18 Update 3 FINAL.3cx · 3cx · CWE-522 | Kritik9,8 | — | %6,7 | 6 May 2022 |
41Planlayın | CVE-2019-7260İstismar yok | Linear eMerge E3-Series devices have Cleartext Credentials in a Database.nortekcontrol · linear emerge essential firmware · CWE-522 | Kritik9,8 | — | %6,6 | 2 Tem 2019 |
41Planlayın | CVE-2014-3445İstismar yok | backup.php in HandsomeWeb SOS Webpages before 1.1.12 does not require knowledge of the cleartext password, which allows remote attackers to handsomeweb · sos webpages · CWE-522 | Kritik9,8 | — | %5,3 | 28 Oca 2020 |
41Planlayın | CVE-2007-0681Kavram kanıtı | profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without providing the original pextcalendar project · extcalendar · CWE-522 | Kritik9,8 | — | %5,2 | 2 Şub 2007 |
40Planlayın | CVE-2017-8837Kavram kanıtı | Cleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hwpeplink · b305hw2 firmware · CWE-522 | Kritik9,8 | — | %4,9 | 5 Haz 2017 |
- CVE-2020-2958396Hemen
Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %90zyxel · usg20-vpn firmware22 Ara 2020
- CVE-2021-3011695Hemen
Unauthenticated credential leak and business logic flaw in Kaseya VSA <= v9.5.6
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %86kaseya · vsa agent9 Tem 2021
- CVE-2017-924892Hemen
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Te
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %75progress · sitefinity3 Tem 2017
- CVE-2021-2268188Hemen
Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix cont
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %64rockwellautomation · factorytalk services platform3 Mar 2021
- CVE-2024-4400064Bu hafta
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
KritikCVSS 9,8SilahlaştırılmışEPSS %82litespeedtech · litespeed cache20 Eki 2024
- CVE-2018-916062Bu hafta
SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.
KritikCVSS 9,8SilahlaştırılmışEPSS %76sickrage · sickrage31 Mar 2018
- CVE-2024-3223855Planlayın
H3C ER8300G2-X is vulnerable to Incorrect Access Control.
KritikCVSS 9,8Kavram kanıtıEPSS %5322 Nis 2024
- CVE-2022-3710954Planlayın
patrickfuller camp up to and including commit bbd53a256ed70e79bd8758080936afbf6d738767 is vulnerable to Incorrect Access Control.
KritikCVSS 9,8Kavram kanıtıEPSS %49camp project · camp14 Kas 2022
- CVE-2022-3541153Planlayın
rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header is sent.
KritikCVSS 9,8Kavram kanıtıEPSS %46rpc.py project · rpc.py8 Tem 2022
- CVE-2014-603951Planlayın
ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability.
YüksekCVSS 7,5SilahlaştırılmışEPSS %69zohocorp · manageengine eventlog analyzer13 Oca 2020
- CVE-2017-319251Planlayın
D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 do not sufficiently protect administrator credentials.
KritikCVSS 9,8İstismar yokEPSS %39d-link · dir-130 firmware15 Ara 2017
- CVE-2017-822550Planlayın
On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is not correctly checked.
KritikCVSS 9,8Kavram kanıtıEPSS %35wificam · wireless ip camera \(p2p\) firmware25 Nis 2017
- CVE-2013-705246Planlayın
D-Link DIR-100 4.03B07: security bypass via an error in the cliget.cgi script
KritikCVSS 9,8Kavram kanıtıEPSS %25dlink · dir-100 firmware4 Şub 2020
- CVE-2023-2813145Planlayın
A vulnerability in the expo.io framework allows an attacker to take over accounts and steal credentials on an application/website that confi
KritikCVSS 9,6İstismar yokEPSS %23expo · expo software development kit24 Nis 2023
- CVE-2017-1710644Planlayın
Credentials for Zivif PR115-204-P-RS V2.3.4.2103 Webcams can be obtained by an unauthenticated remote attacker using a standard web /cgi-bin
KritikCVSS 9,8İstismar yokEPSS %15zivif · pr115-204-p-rs firmware18 Ara 2017
- CVE-2018-1174243Planlayın
NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI.
KritikCVSS 9,8Kavram kanıtıEPSS %14nec · univerge sv9100 webpro firmware26 Ara 2018
- CVE-2000-094442Planlayın
CGI Script Center News Update 1.1 does not properly validate the original news administration password during a password change operation, w
KritikCVSS 9,8Kavram kanıtıEPSS %11cgi · script center news update19 Ara 2000
- CVE-2019-138441Planlayın
A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages.To exploit this
KritikCVSS 9,9İstismar yokEPSS %8microsoft · windows 1012 Kas 2019
- CVE-2014-538141Planlayın
Grand MA 300 allows a brute-force attack on the PIN.
KritikCVSS 9,8Kavram kanıtıEPSS %7granding · grand ma300 firmware13 Oca 2020
- CVE-2013-705541Planlayın
D-Link DIR-100 4.03B07 has PPTP and poe information disclosure
KritikCVSS 9,8Kavram kanıtıEPSS %7dlink · dir-100 firmware4 Şub 2020
- CVE-2022-2800541Planlayın
An issue was discovered in the 3CX Phone System Management Console prior to version 18 Update 3 FINAL.
KritikCVSS 9,8İstismar yokEPSS %73cx · 3cx6 May 2022
- CVE-2019-726041Planlayın
Linear eMerge E3-Series devices have Cleartext Credentials in a Database.
KritikCVSS 9,8İstismar yokEPSS %7nortekcontrol · linear emerge essential firmware2 Tem 2019
- CVE-2014-344541Planlayın
backup.php in HandsomeWeb SOS Webpages before 1.1.12 does not require knowledge of the cleartext password, which allows remote attackers to
KritikCVSS 9,8İstismar yokEPSS %5handsomeweb · sos webpages28 Oca 2020
- CVE-2007-068141Planlayın
profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without providing the original p
KritikCVSS 9,8Kavram kanıtıEPSS %5extcalendar project · extcalendar2 Şub 2007
- CVE-2017-883740Planlayın
Cleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw
KritikCVSS 9,8Kavram kanıtıEPSS %5peplink · b305hw2 firmware5 Haz 2017