Show filters
216 Total Results
Displaying 11-20 of 216
Sort by:
Attacker Value
Unknown
CVE-2021-20410
Disclosure Date: February 11, 2021 (last updated February 22, 2025)
IBM Security Verify Information Queue 1.0.6 and 1.0.7 sends user credentials in plain clear text which can be read by an authenticated user using man in the middle techniques. IBM X-Force ID: 198190.
0
Attacker Value
Unknown
CVE-2020-14391
Disclosure Date: February 08, 2021 (last updated February 22, 2025)
A flaw was found in the GNOME Control Center in Red Hat Enterprise Linux 8 versions prior to 8.2, where it improperly uses Red Hat Customer Portal credentials when a user registers a system through the GNOME Settings User Interface. This flaw allows a local attacker to discover the Red Hat Customer Portal password. The highest threat from this vulnerability is to confidentiality.
0
Attacker Value
Unknown
CVE-2020-10554
Disclosure Date: February 05, 2021 (last updated February 22, 2025)
An issue was discovered in Psyprax beforee 3.2.2. Passwords used to encrypt the data are stored in the database in an obfuscated format, which can be easily reverted. For example, the password AAAAAAAA is stored in the database as MMMMMMMM.
0
Attacker Value
Unknown
CVE-2020-29005
Disclosure Date: January 29, 2021 (last updated February 22, 2025)
The API in the Push extension for MediaWiki through 1.35 used cleartext for ApiPush credentials, allowing for potential information disclosure.
0
Attacker Value
Unknown
CVE-2020-27270
Disclosure Date: January 19, 2021 (last updated February 22, 2025)
SOOIL Developments CoLtd DiabecareRS, AnyDana-i ,AnyDana-A, communication protocol of the insulin pump & AnyDana-i,AnyDana-A mobile apps doesnt use adequate measures to protect encryption keys in transit which allows unauthenticated physically proximate attacker to sniff keys via (BLE).
0
Attacker Value
Unknown
CVE-2021-22132
Disclosure Date: January 14, 2021 (last updated February 22, 2025)
Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API. Users who execute an async search will improperly store the HTTP headers. An Elasticsearch user with the ability to read the .tasks index could obtain sensitive request headers of other users in the cluster. This issue is fixed in Elasticsearch 7.10.2
0
Attacker Value
Unknown
CVE-2021-0212
Disclosure Date: January 13, 2021 (last updated February 22, 2025)
An Information Exposure vulnerability in Juniper Networks Contrail Networking allows a locally authenticated attacker able to read files to retrieve administrator credentials stored in plaintext thereby elevating their privileges over the system. This issue affects: Juniper Networks Contrail Networking versions prior to 1911.31.
0
Attacker Value
Unknown
CVE-2021-0220
Disclosure Date: January 13, 2021 (last updated February 22, 2025)
The Junos Space Network Management Platform has been found to store shared secrets in a recoverable format that can be exposed through the UI. An attacker who is able to execute arbitrary code in the victim browser (for example via XSS) or access cached contents may be able to obtain a copy of credentials managed by Junos Space. The impact of a successful attack includes, but is not limited to, obtaining access to other servers connected to the Junos Space Management Platform. This issue affects Juniper Networks Junos Space versions prior to 20.3R1.
0
Attacker Value
Unknown
CVE-2021-21614
Disclosure Date: January 13, 2021 (last updated February 22, 2025)
Jenkins Bumblebee HP ALM Plugin 4.1.5 and earlier stores credentials unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
0
Attacker Value
Unknown
CVE-2021-21612
Disclosure Date: January 13, 2021 (last updated February 22, 2025)
Jenkins TraceTronic ECU-TEST Plugin 2.23.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
0