Vulnerabilities (CVE)

Filtered by CWE-522
Total 1355 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2013-3313 1 Loftek 2 Nexus 543, Nexus 543 Firmware 2026-06-16 5.0 MEDIUM 7.5 HIGH
The Loftek Nexus 543 IP Camera stores passwords in cleartext, which allows remote attackers to obtain sensitive information via an HTTP GET request to check_users.cgi. NOTE: cleartext passwords can also be obtained from proc/kcore when leveraging the directory traversal vulnerability in CVE-2013-3311.
CVE-2013-2672 1 Brother 2 Mfc-9970cdw, Mfc-9970cdw Firmware 2026-06-16 5.0 MEDIUM 7.5 HIGH
Brother MFC-9970CDW devices with firmware 0D allow cleartext submission of passwords.
CVE-2013-2106 2 Debian, Stanford 2 Debian Linux, Webauth 2026-06-16 5.0 MEDIUM 7.5 HIGH
webauth before 4.6.1 has authentication credential disclosure
CVE-2012-6663 1 Ge 4 D200, D200 Firmware, D20me and 1 more 2026-06-16 5.0 MEDIUM 7.5 HIGH
General Electric D20ME devices are not properly configured and reveal plaintext passwords.
CVE-2012-5627 2 Mariadb, Oracle 2 Mariadb, Mysql 2026-06-16 4.0 MEDIUM N/A
Oracle MySQL and MariaDB 5.5.x before 5.5.29, 5.3.x before 5.3.12, and 5.2.x before 5.2.14 does not modify the salt during multiple executions of the change_user command within the same connection which makes it easier for remote authenticated users to conduct brute force password guessing attacks.
CVE-2012-5527 1 Claws-mail 1 Vcalendar 2026-06-16 2.1 LOW 5.5 MEDIUM
Claws Mail vCalendar plugin: credentials exposed on interface
CVE-2012-4028 1 Tridium 1 Niagara Ax 2026-06-16 7.8 HIGH N/A
Tridium Niagara AX Framework does not properly store credential data, which allows context-dependent attackers to bypass intended access restrictions by using the stored information for authentication.
CVE-2012-3823 1 Arialsoftware 1 Campaign Enterprise 2026-06-16 5.0 MEDIUM 7.5 HIGH
Arial Campaign Enterprise before 11.0.551 stores passwords in clear text and these may be retrieved.
CVE-2012-3268 2 Hp, Huawei 675 0150a129, 0150a12a, 0150a12b and 672 more 2026-06-16 3.5 LOW N/A
Certain HP Access Controller, Fabric Module, Firewall, Router, Switch, and UTM Appliance products; certain HP 3Com Access Controller, Router, and Switch products; certain HP H3C Access Controller, Firewall, Router, Switch, and Switch and Route Processing Unit products; and certain Huawei Firewall/Gateway, Router, Switch, and Wireless products do not properly implement access control as defined in h3c-user.mib 2.0 and hh3c-user.mib 2.0, which allows remote authenticated users to discover credentials in UserInfoEntry values via an SNMP request with the read-only community.
CVE-2012-3025 1 Tridium 1 Niagara Ax 2026-06-16 5.0 MEDIUM N/A
The default configuration of Tridium Niagara AX Framework through 3.6 uses a cleartext base64 format for transmission of credentials in cookies, which allows remote attackers to obtain sensitive information by sniffing the network.
CVE-2010-4178 2 Fedoraproject, Oracle 2 Fedora, Mysql-gui-tools 2026-06-16 2.1 LOW 5.5 MEDIUM
MySQL-GUI-tools (mysql-administrator) leaks passwords into process list after with launch of mysql text console
CVE-2007-0681 1 Extcalendar Project 1 Extcalendar 2026-06-16 7.5 HIGH 9.8 CRITICAL
profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without providing the original password, and possibly perform other unauthorized actions, via modified values to register.php.
CVE-2005-3435 1 Archilles 1 Newsworld 2026-06-16 7.5 HIGH 9.8 CRITICAL
admin_news.php in Archilles Newsworld up to 1.3.0 allows attackers to bypass authentication by obtaining the password hash for another user, for example through another Newsworld vulnerability, and specifying the hash in the pwd argument.
CVE-2000-0944 1 Cgi 1 Script Center News Update 2026-06-16 7.5 HIGH 9.8 CRITICAL
CGI Script Center News Update 1.1 does not properly validate the original news administration password during a password change operation, which allows remote attackers to modify the password without knowing the original password.
CVE-1999-0013 1 Ssh 1 Ssh 2026-06-16 7.5 HIGH 8.4 HIGH
Stolen credentials from SSH clients via ssh-agent program, allowing other local users to access remote accounts belonging to the ssh-agent user.