Vulnerabilities (CVE)

Filtered by CWE-261
Total 25 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-28270 2026-06-17 N/A 8.1 HIGH
An issue discovered in web-flash v3.0 allows attackers to reset passwords for arbitrary users via crafted POST request to /prod-api/user/resetPassword.
CVE-2024-24279 1 Secdiskapp 1 Secdiskapp 2026-06-17 N/A 8.8 HIGH
An issue in secdiskapp 1.5.1 (management program for NewQ Fingerprint Encryption Super Speed Flash Disk) allows attackers to gain escalated privileges via vsVerifyPassword and vsSetFingerPrintPower functions.
CVE-2024-23492 2026-06-17 N/A 5.7 MEDIUM
A weak encoding is used to transmit credentials for WS203VICM.
CVE-2024-0556 1 Xantech 2 Wic1200, Wic1200 Firmware 2026-06-17 N/A 7.1 HIGH
A Weak Cryptography for Passwords vulnerability has been detected on WIC200 affecting version 1.1. This vulnerability allows a remote user to intercept the traffic and retrieve the credentials from another user and decode it in base64 allowing the attacker to see the credentials in plain text.
CVE-2023-0356 1 Socomec 2 Modulys Gp, Net Vision 2026-06-17 N/A 5.7 MEDIUM
SOCOMEC MODULYS GP Netvision versions 7.20 and prior lack strong encryption for credentials on HTTP connections, which could result in threat actors obtaining sensitive information.