CWE-523 · 22 kayıt
Unprotected Transport of Credentials
Bu sınıftaki CVE’ler
22 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2020-25175İstismar yok | GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.gehealthcare · 3.0t signa hdxt firmware · CWE-523 | Kritik9,8 | — | %1,2 | 14 Ara 2020 |
36İzleyin | CVE-2026-8673İstismar yok | Password re-initialization mechanism sends passwords in plain textavantra · avantra · CWE-523 | Kritik9,1 | — | %0,3 | 22 May 2026 |
35İzleyin | CVE-2017-16731İstismar yok | An Unprotected Transport of Credentials issue was discovered in ABB Ellipse 8.3 through Ellipse 8.9 released prior to December 2017 (includihitachienergy · ellipse · CWE-523 | Yüksek8,8 | — | %0,7 | 20 Ara 2017 |
35İzleyin | CVE-2025-57800İstismar yok | Audiobookshelf vulnerable to OIDC token exfiltration and account takeoveraudiobookshelf · audiobookshelf · CWE-523 | Yüksek8,8 | — | %0,5 | 22 Ağu 2025 |
31İzleyin | CVE-2021-38460İstismar yok | Moxa MXview Network Management Softwaremoxa · mxview · CWE-523 | Yüksek7,5 | — | %1,8 | 12 Eki 2021 |
30İzleyin | CVE-2022-31805İstismar yok | Insecure transmission of credentialscodesys · development system · CWE-523 | Yüksek7,5 | — | %1,0 | 24 Haz 2022 |
30İzleyin | CVE-2023-31277İstismar yok | PiiGAB M-Bus Unprotected Transport of Credentialspiigab · m-bus 900s firmware · CWE-523 | Yüksek7,5 | — | %0,6 | 6 Tem 2023 |
30İzleyin | CVE-2023-22862İstismar yok | IBM Aspera information disclosureibm · aspera cargo · CWE-523 | Yüksek7,5 | — | %0,5 | 4 Haz 2023 |
30İzleyin | CVE-2024-1509İstismar yok | Brocade ASCG 3.2.0 web interface does not enforce HSTS, as defined by RFC 6797 for ports 8030 and 8100broadcom · brocade active support connectivity gateway · CWE-523 | Yüksek7,6 | — | %0,4 | 28 Şub 2025 |
30İzleyin | CVE-2025-61121İstismar yok | Mobile Scanner Android App version 2.12.38 (package name com.glority.everlens), developed by Glority Global Group Ltd., contains a credentiaCWE-523 | Yüksek7,5 | — | %0,3 | 30 Eki 2025 |
29İzleyin | CVE-2024-20395İstismar yok | A vulnerability in the media retrieval functionality of Cisco Webex App could allow an unauthenticated, adjacent attacker to gain access to cisco · webex teams · CWE-523 | Yüksek7,3 | — | %0,2 | 17 Tem 2024 |
28İzleyin | CVE-2025-64308İstismar yok | Brightpick Mission Control / Internal Logic Control Unprotected Transport of Credentialsbrightpick ai · brightpick mission control / internal logic control · CWE-523 | Yüksek7,1 | — | %0,2 | 14 Kas 2025 |
28İzleyin | CVE-2024-4188İstismar yok | Security vulnerability exists in Documentum server cloud releases that could allow access to sensitive information which can impact system Operation.opentext™ · documentum™ server · CWE-523 | Yüksek7,1 | — | %0,2 | 30 Tem 2024 |
27İzleyin | CVE-2025-41705İstismar yok | Phoenix Contact: WebSocket Message Interception Leaks Webfrontend Credentialsphoenix contact · quint4-ups/24dc/24dc/5/eip · CWE-523 | Orta6,8 | — | %0,5 | 14 Eki 2025 |
26İzleyin | CVE-2024-1102İstismar yok | Jberet: jberet-core logging database credentialsjberet · jberet · CWE-523 | Orta6,5 | — | %0,8 | 25 Nis 2024 |
26İzleyin | CVE-2026-23635İstismar yok | Kiteworks Secure Data Forms has a potential Unprotected Transport of Credentialsaccellion · kiteworks · CWE-523 | Orta6,5 | — | %0,3 | 25 Mar 2026 |
24İzleyin | CVE-2025-64309İstismar yok | Brightpick Mission Control / Internal Logic Control Unprotected Transport of Credentialsbrightpick ai · brightpick mission control / internal logic control · CWE-523 | Orta6,0 | — | %0,2 | 14 Kas 2025 |
22İzleyin | CVE-2021-32003İstismar yok | Configuration service port remains open 10 minutes after reboot even when already provisionedsecomea · sitemanager firmware · CWE-523 | Orta5,5 | — | %0,2 | 5 Ağu 2021 |
21İzleyin | CVE-2026-17620İstismar yok | IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilitiesibm · financial transaction manager (ftm) for redhat openshift · CWE-523 | Orta5,3 | — | %0,1 | 22 Eyl 2026 |
18İzleyin | CVE-2023-28708İstismar yok | Apache Tomcat: JSESSIONID Cookie missing secure attribute in some configurationsapache · tomcat · CWE-523 | Orta4,3 | — | %1,8 | 22 Mar 2023 |
14İzleyin | CVE-2026-56587İstismar yok | HCL IEM was affected with Strict transport security not enforcedhcltech · intelliops event management · CWE-523 | Düşük3,7 | — | %0,2 | 21 Tem 2026 |
9İzleyin | CVE-2026-8668İstismar yok | Hardcoded credentials in embedded contentprogress chef · chef360 · CWE-523 | Düşük2,3 | — | %0,3 | 18 Haz 2026 |
- CVE-2020-2517539İzleyin
GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.
KritikCVSS 9,8İstismar yokEPSS %1gehealthcare · 3.0t signa hdxt firmware14 Ara 2020
- CVE-2026-867336İzleyin
Password re-initialization mechanism sends passwords in plain text
KritikCVSS 9,1İstismar yokEPSS %0avantra · avantra22 May 2026
- CVE-2017-1673135İzleyin
An Unprotected Transport of Credentials issue was discovered in ABB Ellipse 8.3 through Ellipse 8.9 released prior to December 2017 (includi
YüksekCVSS 8,8İstismar yokEPSS %1hitachienergy · ellipse20 Ara 2017
- CVE-2025-5780035İzleyin
Audiobookshelf vulnerable to OIDC token exfiltration and account takeover
YüksekCVSS 8,8İstismar yokEPSS %0audiobookshelf · audiobookshelf22 Ağu 2025
- CVE-2021-3846031İzleyin
Moxa MXview Network Management Software
YüksekCVSS 7,5İstismar yokEPSS %2moxa · mxview12 Eki 2021
- CVE-2022-3180530İzleyin
Insecure transmission of credentials
YüksekCVSS 7,5İstismar yokEPSS %1codesys · development system24 Haz 2022
- CVE-2023-3127730İzleyin
PiiGAB M-Bus Unprotected Transport of Credentials
YüksekCVSS 7,5İstismar yokEPSS %1piigab · m-bus 900s firmware6 Tem 2023
- CVE-2023-2286230İzleyin
IBM Aspera information disclosure
YüksekCVSS 7,5İstismar yokEPSS %1ibm · aspera cargo4 Haz 2023
- CVE-2024-150930İzleyin
Brocade ASCG 3.2.0 web interface does not enforce HSTS, as defined by RFC 6797 for ports 8030 and 8100
YüksekCVSS 7,6İstismar yokEPSS %0broadcom · brocade active support connectivity gateway28 Şub 2025
- CVE-2025-6112130İzleyin
Mobile Scanner Android App version 2.12.38 (package name com.glority.everlens), developed by Glority Global Group Ltd., contains a credentia
YüksekCVSS 7,5İstismar yokEPSS %030 Eki 2025
- CVE-2024-2039529İzleyin
A vulnerability in the media retrieval functionality of Cisco Webex App could allow an unauthenticated, adjacent attacker to gain access to
YüksekCVSS 7,3İstismar yokEPSS %0cisco · webex teams17 Tem 2024
- CVE-2025-6430828İzleyin
Brightpick Mission Control / Internal Logic Control Unprotected Transport of Credentials
YüksekCVSS 7,1İstismar yokEPSS %0brightpick ai · brightpick mission control / internal logic control14 Kas 2025
- CVE-2024-418828İzleyin
Security vulnerability exists in Documentum server cloud releases that could allow access to sensitive information which can impact system Operation.
YüksekCVSS 7,1İstismar yokEPSS %0opentext™ · documentum™ server30 Tem 2024
- CVE-2025-4170527İzleyin
Phoenix Contact: WebSocket Message Interception Leaks Webfrontend Credentials
OrtaCVSS 6,8İstismar yokEPSS %0phoenix contact · quint4-ups/24dc/24dc/5/eip14 Eki 2025
- CVE-2024-110226İzleyin
Jberet: jberet-core logging database credentials
OrtaCVSS 6,5İstismar yokEPSS %1jberet · jberet25 Nis 2024
- CVE-2026-2363526İzleyin
Kiteworks Secure Data Forms has a potential Unprotected Transport of Credentials
OrtaCVSS 6,5İstismar yokEPSS %0accellion · kiteworks25 Mar 2026
- CVE-2025-6430924İzleyin
Brightpick Mission Control / Internal Logic Control Unprotected Transport of Credentials
OrtaCVSS 6,0İstismar yokEPSS %0brightpick ai · brightpick mission control / internal logic control14 Kas 2025
- CVE-2021-3200322İzleyin
Configuration service port remains open 10 minutes after reboot even when already provisioned
OrtaCVSS 5,5İstismar yokEPSS %0secomea · sitemanager firmware5 Ağu 2021
- CVE-2026-1762021İzleyin
IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
OrtaCVSS 5,3İstismar yokEPSS %0ibm · financial transaction manager (ftm) for redhat openshift22 Eyl 2026
- CVE-2023-2870818İzleyin
Apache Tomcat: JSESSIONID Cookie missing secure attribute in some configurations
OrtaCVSS 4,3İstismar yokEPSS %2apache · tomcat22 Mar 2023
- CVE-2026-5658714İzleyin
HCL IEM was affected with Strict transport security not enforced
DüşükCVSS 3,7İstismar yokEPSS %0hcltech · intelliops event management21 Tem 2026
- CVE-2026-86689İzleyin
Hardcoded credentials in embedded content
DüşükCVSS 2,3İstismar yokEPSS %0progress chef · chef36018 Haz 2026