Export limit exceeded: 35373 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (4556 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-24454 1 Jenkins 1 Testquality Updater 2025-04-02 5.5 Medium
Jenkins TestQuality Updater Plugin 1.3 and earlier stores the TestQuality Updater password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
CVE-2023-24450 1 Jenkins 1 View-cloner 2025-04-02 6.5 Medium
Jenkins view-cloner Plugin 1.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.
CVE-2023-24442 1 Jenkins 1 Github Pull Request Coverage Status 2025-04-02 5.5 Medium
Jenkins GitHub Pull Request Coverage Status Plugin 2.2.0 and earlier stores the GitHub Personal Access Token, Sonar access token and Sonar password unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
CVE-2023-24440 1 Jenkins 1 Jira Pipeline Steps 2025-04-02 5.5 Medium
Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier transmits the private key in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.
CVE-2023-24439 1 Jenkins 1 Jira Pipeline Steps 2025-04-02 5.5 Medium
Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier stores the private keys unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
CVE-2025-25758 1 Kukufm 1 Kukufm 2025-04-01 7.5 High
An issue in KukuFM Android v1.12.7 (11207) allows attackers to access sensitive cleartext data via the android:allowBackup="true" in the ANdroidManifest.xml
CVE-2021-39342 1 Credova 1 Financial 2025-03-31 5.3 Medium
The Credova_Financial WordPress plugin discloses a site's associated Credova API account username and password in plaintext via an AJAX action whenever a site user goes to checkout on a page that has the Credova Financing option enabled. This affects versions up to, and including, 1.4.8.
CVE-2021-39341 1 Optinmonster 1 Optinmonster 2025-03-31 8.2 High
The OptinMonster WordPress plugin is vulnerable to sensitive information disclosure and unauthorized setting updates due to insufficient authorization validation via the logged_in_or_has_api_key function in the ~/OMAPI/RestApi.php file that can used to exploit inject malicious web scripts on sites with the plugin installed. This affects versions up to, and including, 2.6.4.
CVE-2025-23060 1 Arubanetworks 1 Clearpass Policy Manager 2025-03-28 6.6 Medium
A vulnerability in HPE Aruba Networking ClearPass Policy Manager may, under certain circumstances, expose sensitive unencrypted information. Exploiting this vulnerability could allow an attacker to perform a man-in-the-middle attack, potentially granting unauthorized access to network resources as well as enabling data tampering.
CVE-2022-48073 1 Phicomm 2 K2, K2 Firmware 2025-03-28 7.5 High
Phicomm K2G v22.6.3.20 was discovered to store the root and admin passwords in plaintext.
CVE-2022-48071 1 Phicomm 2 K2, K2 Firmware 2025-03-28 7.5 High
Phicomm K2 v22.6.534.263 was discovered to store the root and admin passwords in plaintext.
CVE-2022-45897 1 Xerox 2 Workcentre 3550, Workcentre 3550 Firmware 2025-03-28 6.5 Medium
On Xerox WorkCentre 3550 25.003.03.000 devices, an authenticated attacker can view the SMB server settings and can obtain the stored cleartext credentials associated with those settings.
CVE-2024-21993 1 Netapp 1 Snapcenter 2025-03-27 5.7 Medium
SnapCenter versions prior to 5.0p1 are susceptible to a vulnerability which could allow an authenticated attacker to discover plaintext credentials.
CVE-2022-47715 1 Lastyard 1 Last Yard 2025-03-27 5.3 Medium
In Last Yard 22.09.8-1, the cookie can be stolen via via unencrypted traffic.
CVE-2022-47714 1 Lastyard 1 Last Yard 2025-03-27 9.8 Critical
Last Yard 22.09.8-1 does not enforce HSTS headers
CVE-2022-45098 1 Dell 1 Emc Powerscale Onefs 2025-03-26 6.1 Medium
Dell PowerScale OneFS, 9.0.0.x-9.4.0.x, contain a cleartext storage of sensitive information vulnerability in S3 component. An authenticated local attacker could potentially exploit this vulnerability, leading to information disclosure.
CVE-2020-36248 1 Owncloud 1 Owncloud Client 2025-03-26 3.9 Low
The ownCloud application before 2.15 for Android allows attackers to use adb to include a PIN preferences value in a backup archive, and consequently bypass the PIN lock feature by restoring from this archive.
CVE-2022-34388 1 Dell 2 Supportassist For Business Pcs, Supportassist For Home Pcs 2025-03-26 7.1 High
Dell SupportAssist for Home PCs (version 3.11.4 and prior) and  SupportAssist for Business PCs (version 3.2.0 and prior) contain information disclosure vulnerability. A local malicious user with low privileges could exploit this vulnerability to view and modify sensitive information in the database of the affected application.
CVE-2023-25016 1 Couchbase 1 Couchbase Server 2025-03-25 7.5 High
Couchbase Server before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2 exposes Sensitive Information to an Unauthorized Actor.
CVE-2022-43757 1 Suse 1 Rancher 2025-03-25 9.9 Critical
A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows users on managed clusters to gain access to credentials. The impact depends on the credentials exposed This issue affects: SUSE Rancher Rancher versions prior to 2.5.17; Rancher versions prior to 2.6.10; Rancher versions prior to 2.7.1.