Show filters
507 Total Results
Displaying 141-150 of 507
Sort by:
Attacker Value
Unknown
CVE-2022-22557
Disclosure Date: April 19, 2022 (last updated February 23, 2025)
PowerStore contains Plain-Text Password Storage Vulnerability in PowerStore X & T environments running versions 2.0.0.x and 2.0.1.x A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.
0
Attacker Value
Unknown
CVE-2022-29457
Disclosure Date: April 18, 2022 (last updated February 23, 2025)
Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure during certain storage-path configuration steps.
0
Attacker Value
Unknown
CVE-2021-3681
Disclosure Date: April 18, 2022 (last updated February 23, 2025)
A flaw was found in Ansible Galaxy Collections. When collections are built manually, any files in the repository directory that are not explicitly excluded via the ``build_ignore`` list in "galaxy.yml" include files in the ``.tar.gz`` file. This contains sensitive info, such as the user's Ansible Galaxy API key and any secrets in ``ansible`` or ``ansible-playbook`` verbose output without the``no_log`` redaction. Currently, there is no way to deprecate a Collection Or delete a Collection Version. Once published, anyone who downloads or installs the collection can view the secrets.
0
Attacker Value
Unknown
CVE-2022-27179
Disclosure Date: April 14, 2022 (last updated February 23, 2025)
A malicious actor having access to the exported configuration file may obtain the stored credentials and thereby gain access to the protected resource. If the same passwords were used for other resources, further such assets may be compromised.
0
Attacker Value
Unknown
CVE-2022-29052
Disclosure Date: April 12, 2022 (last updated February 23, 2025)
Jenkins Google Compute Engine Plugin 4.3.8 and earlier stores private keys unencrypted in cloud agent config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.
0
Attacker Value
Unknown
CVE-2022-24978
Disclosure Date: April 05, 2022 (last updated February 23, 2025)
Zoho ManageEngine ADAudit Plus before 7055 allows authenticated Privilege Escalation on Integrated products. This occurs because a password field is present in a JSON response.
0
Attacker Value
Unknown
CVE-2022-28651
Disclosure Date: April 05, 2022 (last updated February 23, 2025)
In JetBrains IntelliJ IDEA before 2021.3.3 it was possible to get passwords from protected fields
0
Attacker Value
Unknown
CVE-2021-45892
Disclosure Date: April 05, 2022 (last updated February 23, 2025)
An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4. There is storage of Passwords in a Recoverable Format.
0
Attacker Value
Unknown
CVE-2021-32978
Disclosure Date: April 04, 2022 (last updated February 23, 2025)
The programming protocol allows for a previously entered password and lock state to be read by an attacker. If the previously entered password was successful, the attacker can then use the password to unlock Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00.
0
Attacker Value
Unknown
CVE-2022-26856
Disclosure Date: April 04, 2022 (last updated February 23, 2025)
Dell EMC Repository Manager version 3.4.0 contains a plain-text password storage vulnerability. A local attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application's database with privileges of the compromised account.
0