İçeriğe atla
Noroxi

CWE-523 · 22 kayıt

Unprotected Transport of Credentials

Bu sınıftaki CVE’ler

22 kayıt

  • CVE-2020-25175
    39İzleyin

    GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.

    KritikCVSS 9,8İstismar yokEPSS %1

    gehealthcare · 3.0t signa hdxt firmware14 Ara 2020

  • CVE-2026-8673
    36İzleyin

    Password re-initialization mechanism sends passwords in plain text

    KritikCVSS 9,1İstismar yokEPSS %0

    avantra · avantra22 May 2026

  • CVE-2017-16731
    35İzleyin

    An Unprotected Transport of Credentials issue was discovered in ABB Ellipse 8.3 through Ellipse 8.9 released prior to December 2017 (includi

    YüksekCVSS 8,8İstismar yokEPSS %1

    hitachienergy · ellipse20 Ara 2017

  • CVE-2025-57800
    35İzleyin

    Audiobookshelf vulnerable to OIDC token exfiltration and account takeover

    YüksekCVSS 8,8İstismar yokEPSS %0

    audiobookshelf · audiobookshelf22 Ağu 2025

  • CVE-2021-38460
    31İzleyin

    Moxa MXview Network Management Software

    YüksekCVSS 7,5İstismar yokEPSS %2

    moxa · mxview12 Eki 2021

  • CVE-2022-31805
    30İzleyin

    Insecure transmission of credentials

    YüksekCVSS 7,5İstismar yokEPSS %1

    codesys · development system24 Haz 2022

  • CVE-2023-31277
    30İzleyin

    PiiGAB M-Bus Unprotected Transport of Credentials

    YüksekCVSS 7,5İstismar yokEPSS %1

    piigab · m-bus 900s firmware6 Tem 2023

  • CVE-2023-22862
    30İzleyin

    IBM Aspera information disclosure

    YüksekCVSS 7,5İstismar yokEPSS %1

    ibm · aspera cargo4 Haz 2023

  • CVE-2024-1509
    30İzleyin

    Brocade ASCG 3.2.0 web interface does not enforce HSTS, as defined by RFC 6797 for ports 8030 and 8100

    YüksekCVSS 7,6İstismar yokEPSS %0

    broadcom · brocade active support connectivity gateway28 Şub 2025

  • CVE-2025-61121
    30İzleyin

    Mobile Scanner Android App version 2.12.38 (package name com.glority.everlens), developed by Glority Global Group Ltd., contains a credentia

    YüksekCVSS 7,5İstismar yokEPSS %0

    30 Eki 2025

  • CVE-2024-20395
    29İzleyin

    A vulnerability in the media retrieval functionality of Cisco Webex App could allow an unauthenticated, adjacent attacker to gain access to

    YüksekCVSS 7,3İstismar yokEPSS %0

    cisco · webex teams17 Tem 2024

  • CVE-2025-64308
    28İzleyin

    Brightpick Mission Control / Internal Logic Control Unprotected Transport of Credentials

    YüksekCVSS 7,1İstismar yokEPSS %0

    brightpick ai · brightpick mission control / internal logic control14 Kas 2025

  • CVE-2024-4188
    28İzleyin

    Security vulnerability exists in Documentum server cloud releases that could allow access to sensitive information which can impact system Operation.

    YüksekCVSS 7,1İstismar yokEPSS %0

    opentext™ · documentum™ server30 Tem 2024

  • CVE-2025-41705
    27İzleyin

    Phoenix Contact: WebSocket Message Interception Leaks Webfrontend Credentials

    OrtaCVSS 6,8İstismar yokEPSS %0

    phoenix contact · quint4-ups/24dc/24dc/5/eip14 Eki 2025

  • CVE-2024-1102
    26İzleyin

    Jberet: jberet-core logging database credentials

    OrtaCVSS 6,5İstismar yokEPSS %1

    jberet · jberet25 Nis 2024

  • CVE-2026-23635
    26İzleyin

    Kiteworks Secure Data Forms has a potential Unprotected Transport of Credentials

    OrtaCVSS 6,5İstismar yokEPSS %0

    accellion · kiteworks25 Mar 2026

  • CVE-2025-64309
    24İzleyin

    Brightpick Mission Control / Internal Logic Control Unprotected Transport of Credentials

    OrtaCVSS 6,0İstismar yokEPSS %0

    brightpick ai · brightpick mission control / internal logic control14 Kas 2025

  • CVE-2021-32003
    22İzleyin

    Configuration service port remains open 10 minutes after reboot even when already provisioned

    OrtaCVSS 5,5İstismar yokEPSS %0

    secomea · sitemanager firmware5 Ağu 2021

  • CVE-2026-17620
    21İzleyin

    IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities

    OrtaCVSS 5,3İstismar yokEPSS %0

    ibm · financial transaction manager (ftm) for redhat openshift22 Eyl 2026

  • CVE-2023-28708
    18İzleyin

    Apache Tomcat: JSESSIONID Cookie missing secure attribute in some configurations

    OrtaCVSS 4,3İstismar yokEPSS %2

    apache · tomcat22 Mar 2023

  • CVE-2026-56587
    14İzleyin

    HCL IEM was affected with Strict transport security not enforced

    DüşükCVSS 3,7İstismar yokEPSS %0

    hcltech · intelliops event management21 Tem 2026

  • CVE-2026-8668
    9İzleyin

    Hardcoded credentials in embedded content

    DüşükCVSS 2,3İstismar yokEPSS %0

    progress chef · chef36018 Haz 2026

Tüm zafiyet sınıfları