Show filters
593 Total Results
Displaying 181-190 of 593
Sort by:
Attacker Value
Unknown

CVE-2022-35411

Disclosure Date: July 08, 2022 (last updated February 24, 2025)
rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header is sent. In other words, although JSON (not Pickle) is the default data format, an unauthenticated client can cause the data to be processed with unpickle.
Attacker Value
Unknown

CVE-2022-1794

Disclosure Date: July 06, 2022 (last updated February 24, 2025)
The CODESYS OPC DA Server prior V3.5.18.20 stores PLC passwords as plain text in its configuration file so that it is visible to all authorized Microsoft Windows users of the system.
0
Attacker Value
Unknown

CVE-2022-27548

Disclosure Date: July 01, 2022 (last updated February 24, 2025)
HCL Launch stores user credentials in plain clear text which can be read by a local user.
Attacker Value
Unknown

CVE-2022-23725

Disclosure Date: June 30, 2022 (last updated February 24, 2025)
PingID Windows Login prior to 2.8 does not properly set permissions on the Windows Registry entries used to store sensitive API keys under some circumstances.
Attacker Value
Unknown

CVE-2022-34816

Disclosure Date: June 30, 2022 (last updated February 24, 2025)
Jenkins HPE Network Virtualization Plugin 1.0 stores passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
Attacker Value
Unknown

CVE-2022-34809

Disclosure Date: June 30, 2022 (last updated February 24, 2025)
Jenkins RQM Plugin 2.8 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
Attacker Value
Unknown

CVE-2022-34808

Disclosure Date: June 30, 2022 (last updated February 24, 2025)
Jenkins Cisco Spark Plugin 1.1.1 and earlier stores bearer tokens unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
Attacker Value
Unknown

CVE-2022-34807

Disclosure Date: June 30, 2022 (last updated February 24, 2025)
Jenkins Elasticsearch Query Plugin 1.2 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
Attacker Value
Unknown

CVE-2022-34806

Disclosure Date: June 30, 2022 (last updated February 24, 2025)
Jenkins Jigomerge Plugin 0.9 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.
Attacker Value
Unknown

CVE-2022-34805

Disclosure Date: June 30, 2022 (last updated February 24, 2025)
Jenkins Skype notifier Plugin 1.1.0 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.