Search Results (4312 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-27210 1 Tp-link 2 Archer C5v, Archer C5v Firmware 2024-11-21 6.5 Medium
TP-Link Archer C5v 1.7_181221 devices allows remote attackers to retrieve cleartext credentials via [USER_CFG#0,0,0,0,0,0#0,0,0,0,0,0]0,0 to the /cgi?1&5 URI.
CVE-2021-27209 1 Tp-link 2 Archer C5v, Archer C5v Firmware 2024-11-21 7.1 High
In the management interface on TP-Link Archer C5v 1.7_181221 devices, credentials are sent in a base64 format over cleartext HTTP.
CVE-2021-27205 2 Apple, Telegram 2 Macos, Telegram 2024-11-21 5.5 Medium
Telegram before 7.4 (212543) Stable on macOS stores the local copy of self-destructed messages in a sandbox path, leading to sensitive information disclosure.
CVE-2021-27204 2 Apple, Telegram 2 Macos, Telegram 2024-11-21 5.5 Medium
Telegram before 7.4 (212543) Stable on macOS stores the local passcode in cleartext, leading to information disclosure.
CVE-2021-27194 2 Microsoft, Netop 2 Windows, Vision Pro 2024-11-21 8.8 High
Cleartext transmission of sensitive information in Netop Vision Pro up to and including 9.7.1 allows a remote unauthenticated attacker to gather credentials including Windows login usernames and passwords.
CVE-2021-27178 1 Fiberhome 2 Hg6245d, Hg6245d Firmware 2024-11-21 7.5 High
An issue was discovered on FiberHome HG6245D devices through RP2613. Some passwords are stored in cleartext in nvram.
CVE-2021-27176 1 Fiberhome 2 Hg6245d, Hg6245d Firmware 2024-11-21 7.5 High
An issue was discovered on FiberHome HG6245D devices through RP2613. wifictl_5g.cfg has cleartext passwords and 0644 permissions.
CVE-2021-27175 1 Fiberhome 2 Hg6245d, Hg6245d Firmware 2024-11-21 7.5 High
An issue was discovered on FiberHome HG6245D devices through RP2613. wifictl_2g.cfg has cleartext passwords and 0644 permissions.
CVE-2021-27174 1 Fiberhome 2 Hg6245d, Hg6245d Firmware 2024-11-21 7.5 High
An issue was discovered on FiberHome HG6245D devices through RP2613. wifi_custom.cfg has cleartext passwords and 0644 permissions.
CVE-2021-27140 1 Fiberhome 2 Hg6245d, Hg6245d Firmware 2024-11-21 7.5 High
An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to find passwords and authentication cookies stored in cleartext in the web.log HTTP logs.
CVE-2021-26595 1 Rangerstudio 1 Directus 2024-11-21 5.3 Medium
In Directus 8.x through 8.8.1, an attacker can learn sensitive information such as the version of the CMS, the PHP version used by the site, and the name of the DBMS, simply by view the result of the api-aa, called automatically upon a connection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
CVE-2021-26550 1 Smartfoxserver 1 Smartfoxserver 2024-11-21 5.5 Medium
An issue was discovered in SmartFoxServer 2.17.0. Cleartext password disclosure can occur via /config/server.xml.
CVE-2021-25898 1 Void 1 Aural Rec Monitor 2024-11-21 7.5 High
An issue was discovered in svc-login.php in Void Aural Rec Monitor 9.0.0.1. Passwords are stored in unencrypted source-code text files. This was noted when accessing the svc-login.php file. The value is used to authenticate a high-privileged user upon authenticating with the server.
CVE-2021-25692 1 Teradici 1 Pcoip Connection Manager And Security Gateway 2024-11-21 4.6 Medium
Sensitive smart card data is logged in default INFO logs by Teradici's PCoIP Connection Manager and Security Gateway prior to version 21.01.3.
CVE-2021-25645 1 Couchbase 1 Couchbase Server 2024-11-21 4.4 Medium
An issue was discovered in Couchbase Server before 6.0.5, 6.1.x through 6.5.x before 6.5.2, and 6.6.x before 6.6.1. An internal user with administrator privileges, @ns_server, leaks credentials in cleartext in the cbcollect_info.log, debug.log, ns_couchdb.log, indexer.log, and stats.log files. NOTE: updating the product does not automatically address leaks that occurred in the past.
CVE-2021-25644 1 Couchbase 1 Couchbase Server 2024-11-21 7.5 High
An issue was discovered in Couchbase Server 5.x and 6.x through 6.6.1 and 7.0.0 Beta. Incorrect commands to the REST API can result in leaked authentication information being stored in cleartext in the debug.log and info.log files, and is also shown in the UI visible to administrators.
CVE-2021-25643 1 Couchbase 1 Couchbase Server 2024-11-21 4.9 Medium
An issue was discovered in Couchbase Server 5.x and 6.x before 6.5.2 and 6.6.x before 6.6.2. Internal users with administrator privileges, @cbq-engine-cbauth and @index-cbauth, leak credentials in cleartext in the indexer.log file when they make a /listCreateTokens, /listRebalanceTokens, or /listMetadataTokens call.
CVE-2021-25502 1 Google 1 Android 2024-11-21 7.9 High
A vulnerability of storing sensitive information insecurely in Property Settings prior to SMR Nov-2021 Release 1 allows attackers to read ESN value without priviledge.
CVE-2021-25284 3 Debian, Fedoraproject, Saltstack 3 Debian Linux, Fedora, Salt 2024-11-21 4.4 Medium
An issue was discovered in through SaltStack Salt before 3002.5. salt.modules.cmdmod can log credentials to the info or error log level.
CVE-2021-23896 1 Mcafee 1 Database Security 2024-11-21 3.2 Low
Cleartext Transmission of Sensitive Information vulnerability in the administrator interface of McAfee Database Security (DBSec) prior to 4.8.2 allows an administrator to view the unencrypted password of the McAfee Insights Server used to pass data to the Insights Server. This user is restricted to only have access to DBSec data in the Insights Server.