Vulnerabilities > Insufficiently Protected Credentials

DATE CVE VULNERABILITY TITLE RISK
2022-04-21 CVE-2022-26856 Insufficiently Protected Credentials vulnerability in Dell EMC Repository Manager 3.4.0
Dell EMC Repository Manager version 3.4.0 contains a plain-text password storage vulnerability.
local
low complexity
dell CWE-522
7.8
2022-04-21 CVE-2022-24867 Insufficiently Protected Credentials vulnerability in Glpi-Project Glpi
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing.
network
low complexity
glpi-project CWE-522
7.5
2022-04-20 CVE-2022-27179 Insufficiently Protected Credentials vulnerability in Redlion Da50N Firmware
A malicious actor having access to the exported configuration file may obtain the stored credentials and thereby gain access to the protected resource.
network
low complexity
redlion CWE-522
6.5
2022-04-18 CVE-2022-29457 Insufficiently Protected Credentials vulnerability in Zohocorp products
Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure during certain storage-path configuration steps.
network
low complexity
zohocorp CWE-522
8.8
2022-04-18 CVE-2021-3681 Insufficiently Protected Credentials vulnerability in Redhat Ansible Automation Platform and Ansible Galaxy
A flaw was found in Ansible Galaxy Collections.
local
low complexity
redhat CWE-522
5.5
2022-04-12 CVE-2022-29052 Insufficiently Protected Credentials vulnerability in Jenkins Google Compute Engine
Jenkins Google Compute Engine Plugin 4.3.8 and earlier stores private keys unencrypted in cloud agent config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.
network
low complexity
jenkins CWE-522
4.3
2022-04-12 CVE-2022-22550 Insufficiently Protected Credentials vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS, versions 8.2.2 and above, contain a password disclosure vulnerability.
local
low complexity
dell CWE-522
6.7
2022-04-05 CVE-2022-24978 Insufficiently Protected Credentials vulnerability in Zohocorp Manageengine Adaudit Plus
Zoho ManageEngine ADAudit Plus before 7055 allows authenticated Privilege Escalation on Integrated products.
network
low complexity
zohocorp CWE-522
8.8
2022-04-05 CVE-2022-28651 Insufficiently Protected Credentials vulnerability in Jetbrains Intellij Idea
In JetBrains IntelliJ IDEA before 2021.3.3 it was possible to get passwords from protected fields
local
low complexity
jetbrains CWE-522
5.5
2022-04-05 CVE-2021-45892 Insufficiently Protected Credentials vulnerability in Zauner ARC 4.2.0.4
An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4.
network
high complexity
zauner CWE-522
5.9