Show filters
684 Total Results
Displaying 261-270 of 684
Sort by:
Attacker Value
Unknown

CVE-2022-36307

Disclosure Date: August 16, 2022 (last updated February 24, 2025)
The AirVelocity 1500 prints SNMP credentials on its physically accessible serial port during boot. This was fixed in AirVelocity 1500 software version 15.18.00.2511 and may affect other AirVelocity and AirSpeed models.
Attacker Value
Unknown

CVE-2022-22983

Disclosure Date: August 10, 2022 (last updated February 24, 2025)
VMware Workstation (16.x prior to 16.2.4) contains an unprotected storage of credentials vulnerability. A malicious actor with local user privileges to the victim machine may exploit this vulnerability leading to the disclosure of user passwords of the remote server connected through VMware Workstation.
Attacker Value
Unknown

CVE-2022-34371

Disclosure Date: August 04, 2022 (last updated February 24, 2025)
Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.3, contain an unprotected transport of credentials vulnerability. A malicious unprivileged network attacker could potentially exploit this vulnerability, leading to full system compromise.
Attacker Value
Unknown

CVE-2022-20914

Disclosure Date: August 03, 2022 (last updated February 24, 2025)
A vulnerability in the External RESTful Services (ERS) API of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker to obtain sensitive information. This vulnerability is due to excessive verbosity in a specific REST API output. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to obtain sensitive information, including administrative credentials for an external authentication server. Note: To successfully exploit this vulnerability, the attacker must have valid ERS administrative credentials.
Attacker Value
Unknown

CVE-2021-27785

Disclosure Date: July 29, 2022 (last updated February 24, 2025)
HCL Commerce's Remote Store server could allow a local attacker to obtain sensitive personal information. The vulnerability requires the victim to first perform a particular operation on the website.
Attacker Value
Unknown

CVE-2022-33169

Disclosure Date: July 29, 2022 (last updated February 24, 2025)
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to insufficiently protected credentials for users created via a bulk upload. IBM X-Force ID: 228888.
Attacker Value
Unknown

CVE-2022-36901

Disclosure Date: July 27, 2022 (last updated February 24, 2025)
Jenkins HTTP Request Plugin 1.15 and earlier stores HTTP Request passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
Attacker Value
Unknown

CVE-2022-34837

Disclosure Date: July 26, 2022 (last updated February 24, 2025)
Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who successfully exploit the vulnerability may add more network clients that may monitor various activities of the Zenon.
Attacker Value
Unknown

CVE-2022-34838

Disclosure Date: July 26, 2022 (last updated February 24, 2025)
Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who successfully exploit the vulnerability may add or alter data points and corresponding attributes. Once such engineering data is used the data visualization will be altered for the end user.
Attacker Value
Unknown

CVE-2022-27544

Disclosure Date: July 18, 2022 (last updated February 24, 2025)
BigFix Web Reports authorized users may see SMTP credentials in clear text.