Show filters
458 Total Results
Displaying 91-100 of 458
Sort by:
Attacker Value
Unknown

CVE-2022-1342

Disclosure Date: April 21, 2022 (last updated February 23, 2025)
A lack of password masking in Devolutions Remote Desktop Manager allows physically proximate attackers to observe sensitive data. A caching issue can cause sensitive fields to sometimes stay revealed when closing and reopening a panel, which could lead to involuntarily disclosing sensitive information. This issue affects: Devolutions Remote Desktop Manager 2022.1.24 version and prior versions.
Attacker Value
Unknown

CVE-2022-22557

Disclosure Date: April 19, 2022 (last updated February 23, 2025)
PowerStore contains Plain-Text Password Storage Vulnerability in PowerStore X & T environments running versions 2.0.0.x and 2.0.1.x A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.
Attacker Value
Unknown

CVE-2022-29457

Disclosure Date: April 18, 2022 (last updated February 23, 2025)
Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure during certain storage-path configuration steps.
Attacker Value
Unknown

CVE-2021-3681

Disclosure Date: April 18, 2022 (last updated February 23, 2025)
A flaw was found in Ansible Galaxy Collections. When collections are built manually, any files in the repository directory that are not explicitly excluded via the ``build_ignore`` list in "galaxy.yml" include files in the ``.tar.gz`` file. This contains sensitive info, such as the user's Ansible Galaxy API key and any secrets in ``ansible`` or ``ansible-playbook`` verbose output without the``no_log`` redaction. Currently, there is no way to deprecate a Collection Or delete a Collection Version. Once published, anyone who downloads or installs the collection can view the secrets.
Attacker Value
Unknown

CVE-2022-27179

Disclosure Date: April 14, 2022 (last updated February 23, 2025)
A malicious actor having access to the exported configuration file may obtain the stored credentials and thereby gain access to the protected resource. If the same passwords were used for other resources, further such assets may be compromised.
Attacker Value
Unknown

CVE-2022-29052

Disclosure Date: April 12, 2022 (last updated February 23, 2025)
Jenkins Google Compute Engine Plugin 4.3.8 and earlier stores private keys unencrypted in cloud agent config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.
Attacker Value
Unknown

CVE-2022-24978

Disclosure Date: April 05, 2022 (last updated February 23, 2025)
Zoho ManageEngine ADAudit Plus before 7055 allows authenticated Privilege Escalation on Integrated products. This occurs because a password field is present in a JSON response.
Attacker Value
Unknown

CVE-2022-28651

Disclosure Date: April 05, 2022 (last updated February 23, 2025)
In JetBrains IntelliJ IDEA before 2021.3.3 it was possible to get passwords from protected fields
Attacker Value
Unknown

CVE-2021-45892

Disclosure Date: April 05, 2022 (last updated February 23, 2025)
An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4. There is storage of Passwords in a Recoverable Format.
Attacker Value
Unknown

CVE-2021-32978

Disclosure Date: April 04, 2022 (last updated February 23, 2025)
The programming protocol allows for a previously entered password and lock state to be read by an attacker. If the previously entered password was successful, the attacker can then use the password to unlock Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00.