Show filters
150 Total Results
Displaying 11-20 of 150
Sort by:
Attacker Value
Unknown

CVE-2021-25644

Disclosure Date: May 19, 2021 (last updated February 22, 2025)
An issue was discovered in Couchbase Server 5.x and 6.x through 6.6.1 and 7.0.0 Beta. Incorrect commands to the REST API can result in leaked authentication information being stored in cleartext in the debug.log and info.log files, and is also shown in the UI visible to administrators.
Attacker Value
Unknown

CVE-2021-29683

Disclosure Date: May 19, 2021 (last updated February 22, 2025)
IBM Security Identity Manager 7.0.2 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 199998.
Attacker Value
Unknown

CVE-2021-30183

Disclosure Date: May 14, 2021 (last updated February 22, 2025)
Cleartext storage of sensitive information in multiple versions of Octopus Server where in certain situations when running import or export processes, the password used to encrypt and decrypt sensitive values would be written to the logs in plaintext.
Attacker Value
Unknown

CVE-2021-25645

Disclosure Date: May 10, 2021 (last updated February 22, 2025)
An issue was discovered in Couchbase Server before 6.0.5, 6.1.x through 6.5.x before 6.5.2, and 6.6.x before 6.6.1. An internal user with administrator privileges, @ns_server, leaks credentials in cleartext in the cbcollect_info.log, debug.log, ns_couchdb.log, indexer.log, and stats.log files. NOTE: updating the product does not automatically address leaks that occurred in the past.
Attacker Value
Unknown

CVE-2021-22206

Disclosure Date: May 06, 2021 (last updated February 22, 2025)
An issue has been discovered in GitLab affecting all versions starting from 11.6. Pull mirror credentials are exposed that allows other maintainers to be able to view the credentials in plain-text,
Attacker Value
Unknown

CVE-2021-20995

Disclosure Date: May 05, 2021 (last updated February 22, 2025)
In multiple managed switches by WAGO in different versions the webserver cookies of the web based UI contain user credentials.
Attacker Value
Unknown

CVE-2020-22783

Disclosure Date: April 28, 2021 (last updated February 22, 2025)
Etherpad <1.8.3 stored passwords used by users insecurely in the database and in log files. This affects every database backend supported by Etherpad.
Attacker Value
Unknown

CVE-2021-31791

Disclosure Date: April 23, 2021 (last updated February 22, 2025)
In Hardware Sentry KM before 10.0.01 for BMC PATROL, a cleartext password may be discovered after a failure or timeout of a command.
Attacker Value
Unknown

CVE-2021-25898

Disclosure Date: April 23, 2021 (last updated February 22, 2025)
An issue was discovered in svc-login.php in Void Aural Rec Monitor 9.0.0.1. Passwords are stored in unencrypted source-code text files. This was noted when accessing the svc-login.php file. The value is used to authenticate a high-privileged user upon authenticating with the server.
Attacker Value
Unknown

CVE-2021-31539

Disclosure Date: April 23, 2021 (last updated February 22, 2025)
Wowza Streaming Engine before 4.8.8.01 (in a default installation) has cleartext passwords stored in the conf/admin.password file. A regular local user is able to read usernames and passwords.