Vulnerabilities > Insufficiently Protected Credentials

DATE CVE VULNERABILITY TITLE RISK
2020-04-10 CVE-2020-5406 Insufficiently Protected Credentials vulnerability in VMWare Tanzu Application Service for VMS
VMware Tanzu Application Service for VMs, 2.6.x versions prior to 2.6.18, 2.7.x versions prior to 2.7.11, and 2.8.x versions prior to 2.8.5, includes a version of PCF Autoscaling that writes database connection properties to its log, including database username and password.
network
low complexity
vmware CWE-522
6.5
2020-04-09 CVE-2020-5263 Insufficiently Protected Credentials vulnerability in Auth0 Auth0.Js
auth0.js (NPM package auth0-js) greater than version 8.0.0 and before version 9.12.3 has a vulnerability.
network
low complexity
auth0 CWE-522
4.9
2020-04-09 CVE-2020-11557 Insufficiently Protected Credentials vulnerability in Castlerock Snmpc Online 12.10.10
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28.
network
low complexity
castlerock CWE-522
7.5
2020-04-09 CVE-2020-11555 Insufficiently Protected Credentials vulnerability in Castlerock Snmpc Online 12.10.10
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28.
network
low complexity
castlerock CWE-522
7.5
2020-04-08 CVE-2020-1978 Insufficiently Protected Credentials vulnerability in Paloaltonetworks Pan-Os and Vm-Series
TechSupport files generated on Palo Alto Networks VM Series firewalls for Microsoft Azure platform configured with high availability (HA) inadvertently collect Azure dashboard service account credentials.
local
low complexity
paloaltonetworks CWE-522
4.4
2020-04-08 CVE-2020-11629 Insufficiently Protected Credentials vulnerability in Primekey Ejbca
An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2.
network
low complexity
primekey CWE-522
7.2
2020-04-07 CVE-2020-11560 Insufficiently Protected Credentials vulnerability in Nchsoftware Express Invoice 7.25
NCH Express Invoice 7.25 allows local users to discover the cleartext password by reading the configuration file.
local
low complexity
nchsoftware CWE-522
7.8
2020-04-07 CVE-2017-18695 Insufficiently Protected Credentials vulnerability in Google Android
An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.0) software.
network
low complexity
google CWE-522
6.5
2020-04-07 CVE-2016-11029 Insufficiently Protected Credentials vulnerability in Google Android
An issue was discovered on Samsung mobile devices with L(5.0/5.1), M(6.0), and N(7.0) software.
network
low complexity
google CWE-522
7.5
2020-04-02 CVE-2019-19096 Insufficiently Protected Credentials vulnerability in Hitachienergy Esoms 6.0/6.0.2
The Redis data structure component used in ABB eSOMS versions 6.0 to 6.0.2 stores credentials in clear text.
local
low complexity
hitachienergy CWE-522
6.1