All vulnerabilities
1515 / 1515
Sort
9.8
CVE-2020-29583CVE KEV
Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unc…
2020-01-01KEV
EPSS94.3%
pct 99
6.5
CVE-2024-9014ANC
pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. T…
2024-01-01
EPSS92.9%
pct 99
9.8
CVE-2024-44000ANC
Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache al…
2024-01-01Pre-auth
EPSS92.8%
pct 99
9.8
CVE-2019-17444CVE
Jfrog Artifactory uses default passwords (such as "password") for administrative accounts and d…
2019-01-01Pre-auth
EPSS92.5%
pct 99
9.8
CVE-2017-9248CVE KEV
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity be…
2017-01-01KEV
EPSS89.4%
pct 99
9.8
CVE-2024-32238
H3C ER8300G2-X is vulnerable to Incorrect Access Control. The password for the router's managem…
2024-01-01Pre-auth
EPSS87.8%
pct 99
8.6
CVE-2022-1026CVE
Kyocera multifunction printers running vulnerable versions of Net View unintentionally expose s…
2022-01-01Pre-auth
EPSS85.8%
pct 99
7.5
CVE-2014-6039CVE
ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vu…
2014-01-01Pre-auth
EPSS83.6%
pct 99
6.5
CVE-2021-44451CVE
Apache Superset up to and including 1.3.2 allowed for registered database connections password …
2021-01-01
EPSS83.4%
pct 99
7.5
CVE-2023-6421CVE
The Download Manager WordPress plugin before 3.2.83 does not protect file download's passwords,…
2023-01-01Pre-auth
EPSS82.4%
pct 99
9.8
CVE-2018-9160CVE
SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.
2018-01-01Pre-auth
EPSS74.2%
pct 98
9.8
CVE-2022-35411CVE
rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializ…
2022-01-01Pre-auth
EPSS71.3%
pct 98
9.8
CVE-2017-8225CVE
On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is n…
2017-01-01Pre-auth
EPSS58.5%
pct 98
9.8
CVE-2013-7055CVE
D-Link DIR-100 4.03B07 has PPTP and poe information disclosure
2013-01-01Pre-auth
EPSS56.7%
pct 98
9.8
CVE-2021-30116CVE KEV
Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By…
2021-01-01KEV
EPSS54.1%
pct 98
9.8
CVE-2013-7052CVE
D-Link DIR-100 4.03B07: security bypass via an error in the cliget.cgi script
2013-01-01Pre-auth
EPSS50.4%
pct 97
9.8
CVE-2024-42850CVE
An issue in the password change function of Silverpeas v6.4.2 and lower allows for the bypassin…
2024-01-01Pre-auth
EPSS49.8%
pct 97
9.8
CVE-2014-5381CVE
Grand MA 300 allows a brute-force attack on the PIN.
2014-01-01Pre-auth
EPSS46.4%
pct 97
6.5
CVE-2022-38121CVE
UPSMON PRO configuration file stores user password in plaintext under public user directory. A …
2022-01-01
EPSS44.3%
pct 97
9.8
CVE-2022-28005CVE
An issue was discovered in the 3CX Phone System Management Console prior to version 18 Update 3…
2022-01-01Pre-auth
EPSS38.2%
pct 97
7.5
CVE-2020-5260AST
Affected versions of Git have a vulnerability whereby Git can be tricked into sending private c…
2020-01-01Pre-auth
EPSS37.3%
pct 97
9.8
CVE-2018-11742CVE
NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI.
2018-01-01Pre-auth
EPSS36.4%
pct 97
9.8
CVE-2017-3191CVE
D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 are vulnerable to authen…
2017-01-01Pre-auth
EPSS33.8%
pct 97
4.8
CVE-2015-8140DEB
The ntpq protocol in NTP before 4.2.8p7 allows remote attackers to conduct replay attacks by sn…
2015-01-01Pre-auth
EPSS29.9%
pct 96
7.5
CVE-2019-19823CVE
A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc2…
2019-01-01Pre-auth
EPSS28.7%
pct 96
9.8
CVE-2017-3192CVE
D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 do not sufficiently prot…
2017-01-01Pre-auth
EPSS27.7%
pct 96
5.9
CVE-2021-29262DEB
When starting Apache Solr versions prior to 8.8.2, configured with the SaslZkACLProvider or VMP…
2021-01-01Pre-auth
EPSS26.2%
pct 96
8.5
CVE-2012-2441CVE
RuggedCom Rugged Operating System (ROS) before 3.3 has a factory account with a password derive…
2012-01-01
EPSS25.1%
pct 96
9.8
CVE-2017-17106CVE
Credentials for Zivif PR115-204-P-RS V2.3.4.2103 Webcams can be obtained by an unauthenticated …
2017-01-01Pre-auth
EPSS25.1%
pct 96
7.5
CVE-2012-6663CVE
General Electric D20ME devices are not properly configured and reveal plaintext passwords.
2012-01-01Pre-auth
EPSS23.1%
pct 96
9.0
CVE-2024-3596AST
RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can mo…
2024-01-01MicrosoftPre-auth
EPSS22.2%
pct 95
9.8
CVE-2025-25570
Vue Vben Admin 2.10.1 allows unauthorized login to the backend due to an issue with hardcoded c…
2025-01-01Pre-auth
EPSS20.6%
pct 95
8.8
CVE-2021-43397CVE
LiquidFiles before 3.6.3 allows remote attackers to elevate their privileges from Admin (or Use…
2021-01-01
EPSS18.3%
pct 95
9.8
CVE-2021-22681CVE KEV
Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions…
2021-01-01KEV
EPSS18.2%
pct 95
7.5
CVE-2024-23733
The /WmAdmin/,/invoke/vm.server/login login page in the Integration Server in Software AG webMe…
2024-01-01Pre-auth
EPSS18.1%
pct 95
8.1
CVE-2018-3609CVE
A vulnerability in the Trend Micro InterScan Messaging Security Virtual Appliance 9.0 and 9.1 m…
2018-01-01Pre-auth
EPSS16.3%
pct 94
9.8
CVE-2018-19466CVE
A vulnerability was found in Portainer before 1.20.0. Portainer stores LDAP credentials, corres…
2018-01-01Pre-auth
EPSS12.8%
pct 94
7.5
CVE-2002-0054CVE
SMTP service in (1) Microsoft Windows 2000 and (2) Internet Mail Connector (IMC) in Exchange Se…
2002-01-01
EPSS12.5%
pct 94
9.8
CVE-2014-5093CVE
Status2k does not remove the install directory allowing credential reset.
2014-01-01Pre-auth
EPSS12.2%
pct 93
8.8
CVE-2017-11786MSR
Skype for Business in Microsoft Lync 2013 SP1 and Skype for Business 2016 allows an attacker to…
2017-01-01MicrosoftPre-auth
EPSS11.5%
pct 93
Select a vulnerability on the left to open the preview.