Show filters
225 Total Results
Displaying 51-60 of 225
Sort by:
Attacker Value
Unknown

CVE-2021-35526

Disclosure Date: August 31, 2021 (last updated February 23, 2025)
Backup file without encryption vulnerability is found in Hitachi ABB Power Grids System Data Manager – SDM600 allows attacker to gain access to sensitive information. This issue affects: Hitachi ABB Power Grids System Data Manager – SDM600 1.2 versions prior to FP2 HF6 (Build Nr. 1.2.14002.257).
Attacker Value
Unknown

CVE-2021-31989

Disclosure Date: August 25, 2021 (last updated February 23, 2025)
A user with permission to log on to the machine hosting the AXIS Device Manager client could under certain conditions extract a memory dump from the built-in Windows Task Manager application. The memory dump may potentially contain credentials of connected Axis devices.
Attacker Value
Unknown

CVE-2021-40087

Disclosure Date: August 25, 2021 (last updated February 23, 2025)
An issue was discovered in PrimeKey EJBCA before 7.6.0. When audit logging changes to the alias configurations of various protocols that use an enrollment secret, any modifications to the secret were logged in cleartext in the audit log (that can only be viewed by an administrator). This affects use of any of the following protocols: SCEP, CMP, or EST.
Attacker Value
Unknown

CVE-2021-30997

Disclosure Date: August 24, 2021 (last updated February 23, 2025)
A S/MIME issue existed in the handling of encrypted email. This issue was addressed by not automatically loading some MIME parts. This issue is fixed in iOS 15.2 and iPadOS 15.2. An attacker may be able to recover plaintext contents of an S/MIME-encrypted e-mail.
Attacker Value
Unknown

CVE-2021-31820

Disclosure Date: August 18, 2021 (last updated February 23, 2025)
In Octopus Server after version 2018.8.2 if the Octopus Server Web Request Proxy is configured with authentication, the password is shown in plaintext in the UI.
Attacker Value
Unknown

CVE-2020-36473

Disclosure Date: August 14, 2021 (last updated February 23, 2025)
UCWeb UC 12.12.3.1219 through 12.12.3.1226 uses cleartext HTTP, and thus man-in-the-middle attackers can discover visited URLs.
Attacker Value
Unknown

CVE-2020-18759

Disclosure Date: August 13, 2021 (last updated February 23, 2025)
An information disclosure vulnerability exists in the EPA protocol of Dut Computer Control Engineering Co.'s PLC MAC1100.
Attacker Value
Unknown

CVE-2021-37548

Disclosure Date: August 06, 2021 (last updated February 23, 2025)
In JetBrains TeamCity before 2021.1, passwords in cleartext sometimes could be stored in VCS.
Attacker Value
Unknown

CVE-2021-33323

Disclosure Date: August 03, 2021 (last updated February 23, 2025)
The Dynamic Data Mapping module in Liferay Portal 7.1.0 through 7.3.2, and Liferay DXP 7.1 before fix pack 19, and 7.2 before fix pack 7, autosaves form values for unauthenticated users, which allows remote attackers to view the autosaved values by viewing the form as an unauthenticated user.
Attacker Value
Unknown

CVE-2021-33325

Disclosure Date: August 03, 2021 (last updated February 23, 2025)
The Portal Workflow module in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 93, 7.1 before fix pack 19, and 7.2 before fix pack 7, user's clear text passwords are stored in the database if workflow is enabled for user creation, which allows attackers with access to the database to obtain a user's password.