Show filters
54 Total Results
Displaying 21-30 of 54
Sort by:
Attacker Value
Unknown

CVE-2020-8296

Disclosure Date: March 03, 2021 (last updated February 22, 2025)
Nextcloud Server prior to 20.0.0 stores passwords in a recoverable format even when external storage is not configured.
Attacker Value
Unknown

CVE-2021-25309

Disclosure Date: March 02, 2021 (last updated February 22, 2025)
The telnet administrator service running on port 650 on Gigaset DX600A v41.00-175 devices does not implement any lockout or throttling functionality. This situation (together with the weak password policy that forces a 4-digit password) allows remote attackers to easily obtain administrative access via brute-force attacks.
Attacker Value
Unknown

CVE-2020-29591

Disclosure Date: December 11, 2020 (last updated February 22, 2025)
Versions of the Official registry Docker images through 2.7.0 contain a blank password for the root user. Systems deployed using affected versions of the registry container may allow a remote attacker to achieve root access with a blank password.
Attacker Value
Unknown

CVE-2020-26201

Disclosure Date: December 10, 2020 (last updated February 22, 2025)
Askey AP5100W_Dual_SIG_1.01.097 and all prior versions use a weak password at the Operating System (rlx-linux) level. This allows an attacker to gain unauthorized access as an admin or root user to the device Operating System via Telnet or SSH.
Attacker Value
Unknown

CVE-2020-27587

Disclosure Date: November 30, 2020 (last updated February 22, 2025)
Quick Heal Total Security before 19.0 allows attackers with local admin rights to obtain access to files in the File Vault via a brute-force attack on the password.
Attacker Value
Unknown

CVE-2020-27585

Disclosure Date: November 30, 2020 (last updated February 22, 2025)
Quick Heal Total Security before 19.0 allows attackers with local admin rights to modify sensitive anti virus settings via a brute-attack on the settings password.
Attacker Value
Unknown

CVE-2020-8956

Disclosure Date: October 27, 2020 (last updated February 22, 2025)
Pulse Secure Desktop Client 9.0Rx before 9.0R5 and 9.1Rx before 9.1R4 on Windows reveals users' passwords if Save Settings is enabled.
Attacker Value
Unknown

CVE-2020-25153

Disclosure Date: October 13, 2020 (last updated February 22, 2025)
The built-in web service for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower does not require users to have strong passwords.
Attacker Value
Unknown

CVE-2019-17444

Disclosure Date: October 12, 2020 (last updated February 22, 2025)
Jfrog Artifactory uses default passwords (such as "password") for administrative accounts and does not require users to change them. This may allow unauthorized network-based attackers to completely compromise of Jfrog Artifactory. This issue affects Jfrog Artifactory versions prior to 6.17.0.
Attacker Value
Unknown

CVE-2020-15369

Disclosure Date: September 25, 2020 (last updated February 22, 2025)
Supportlink CLI in Brocade Fabric OS Versions v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c does not obfuscate the password field, which could expose users’ credentials of the remote server. An authenticated user could obtain the exposed password credentials to gain access to the remote host.