Vulnerabilities > Insufficiently Protected Credentials

DATE CVE VULNERABILITY TITLE RISK
2022-06-02 CVE-2022-29085 Insufficiently Protected Credentials vulnerability in Dell products
Dell Unity, Dell UnityVSA, and Dell Unity XT versions prior to 5.2.0.0.5.173 contain a plain-text password storage vulnerability when certain off-array tools are run on the system.
local
low complexity
dell CWE-522
6.7
2022-06-02 CVE-2022-22767 Insufficiently Protected Credentials vulnerability in BD products
Specific BD Pyxis™ products were installed with default credentials and may presently still operate with these credentials.
low complexity
bd CWE-522
8.8
2022-06-02 CVE-2022-27774 Insufficiently Protected Credentials vulnerability in multiple products
An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authentication could leak credentials to other services that exist on different protocols or port numbers.
network
low complexity
haxx debian netapp brocade splunk CWE-522
5.7
2022-06-02 CVE-2022-27776 Insufficiently Protected Credentials vulnerability in multiple products
A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.
6.5
2022-05-19 CVE-2022-1413 Insufficiently Protected Credentials vulnerability in Gitlab
Missing input masking in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 causes potentially sensitive integration properties to be disclosed in the web interface
network
low complexity
gitlab CWE-522
7.5
2022-05-19 CVE-2022-30018 Insufficiently Protected Credentials vulnerability in Mobotix Mxcontrolcenter 2.5.4.5
Mobotix Control Center (MxCC) through 2.5.4.5 has Insufficiently Protected Credentials, Storing Passwords in a Recoverable Format via the MxCC.ini config file.
network
low complexity
mobotix CWE-522
8.8
2022-05-17 CVE-2022-30952 Insufficiently Protected Credentials vulnerability in Jenkins Blue Ocean
Jenkins Pipeline SCM API for Blue Ocean Plugin 1.25.3 and earlier allows attackers with Job/Configure permission to access credentials with attacker-specified IDs stored in the private per-user credentials stores of any attacker-specified user in Jenkins.
network
low complexity
jenkins CWE-522
6.5
2022-05-16 CVE-2022-29588 Insufficiently Protected Credentials vulnerability in Konicaminolta products
Konica Minolta bizhub MFP devices before 2022-04-14 use cleartext password storage for the /var/log/nginx/html/ADMINPASS and /etc/shadow files.
network
low complexity
konicaminolta CWE-522
7.5
2022-05-06 CVE-2022-28005 Insufficiently Protected Credentials vulnerability in 3CX
An issue was discovered in the 3CX Phone System Management Console prior to version 18 Update 3 FINAL.
network
low complexity
3cx CWE-522
critical
9.8
2022-05-03 CVE-2021-46440 Insufficiently Protected Credentials vulnerability in Strapi
Storing passwords in a recoverable format in the DOCUMENTATION plugin component of Strapi before 3.6.9 and 4.x before 4.1.5 allows an attacker to access a victim's HTTP request, get the victim's cookie, perform a base64 decode on the victim's cookie, and obtain a cleartext password, leading to getting API documentation for further API attacks.
network
low complexity
strapi CWE-522
7.5