All CVEs (12)
CVE-2020-25175
CRITICALGE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.
CVE-2017-16731
HIGHAn Unprotected Transport of Credentials issue was discovered in ABB Ellipse 8.3 through Ellipse 8.9 released prior to December 2017 (including Ellipse Select). A vulnerability exists in the authentica...
CVE-2023-31277
HIGHPiiGAB M-Bus transmits credentials in plaintext format.
CVE-2023-22862
HIGHIBM Aspera Connect 4.2.5 and IBM Aspera Cargo 4.2.5 transmits authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CVE-2022-31805
HIGHIn the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected.
CVE-2021-38460
HIGHA path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs o...
CVE-2024-1102
MEDIUMA vulnerability was found in jberet-core logging. An exception in 'dbProperties' might display user credentials such as the username and password for the database-connection.
CVE-2024-20395
MEDIUMA vulnerability in the media retrieval functionality of Cisco Webex App could allow an unauthenticated, adjacent attacker to gain access to sensitive session information. This vulnerability is due to ...
CVE-2021-32003
MEDIUMUnprotected Transport of Credentials vulnerability in SiteManager provisioning service allows local attacker to capture credentials if the service is used after provisioning. This issue affects: Secom...
CVE-2023-28708
MEDIUMWhen using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11.0.0-M1 to 11.0.0....
CVE-2024-4188
HIGHUnprotected Transport of Credentials vulnerability in OpenTextâ„¢ Documentumâ„¢ Server could allow Credential Stuffing.This issue affects Documentumâ„¢ Server: from 16.7 through 23.4.
CVE-2024-1509
HIGHBrocade ASCG before 3.2.0 Web Interface is not enforcing HSTS, as defined by RFC 6797. HSTS is an optional response header that can be configured on the server to instruct the browser to only communic...