<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Plaintext Password (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/plaintext-cred.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/plaintext-cred-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Plaintext Password (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:29 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-36609 – Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 uses a static au...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-36609</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-36609</guid>
    <pubDate>Wed, 03 Jun 2026 18:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-36609</strong></p>
  <p>Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 uses a static authentication nonce that does not change between requests from the same source IP. Combined with the predictable XOR-based password encoding (securityEncode function), this allows an attacker to reverse captured authentication tokens to recover the plaintext password.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-36609">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35675 – phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in the pas...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35675</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35675</guid>
    <pubDate>Thu, 28 May 2026 16:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35675</strong></p>
  <p>phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in the password reset endpoint that allows unauthenticated attackers to reset any user account password without token verification or email confirmation. Attackers can enumerate valid usernames, obtain plaintext passwords via email, and achieve complete account takeover including administrative access.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-307</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35675">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-43948 – wger is a free, open-source workout and fitness manager. Prior to 2.6, the reset...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43948</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43948</guid>
    <pubDate>Tue, 12 May 2026 22:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-43948</strong></p>
  <p>wger is a free, open-source workout and fitness manager. Prior to 2.6, the reset_user_password and gym_permissions_user_edit views in wger perform a gym-scope authorization check using Python object comparison (!=) that evaluates None != None as False, silently bypassing the guard when both the attacker and victim have no gym assignment (gym=None). A user with gym.manage_gym permission and gym=No…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43948">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5086 – Crypt::SecretBuffer versions before 0.019 for Perl is suseceptible to timing att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5086</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5086</guid>
    <pubDate>Mon, 13 Apr 2026 23:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5086</strong></p>
  <p>Crypt::SecretBuffer versions before 0.019 for Perl is suseceptible to timing attacks.  For example, if Crypt::SecretBuffer was used to store and compare plaintext passwords, then discrepencies in timing could be used to guess the secret password.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-208</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5086">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34833 – Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34833</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34833</guid>
    <pubDate>Thu, 02 Apr 2026 20:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34833</strong></p>
  <p>Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to version 1.4.10, the GET /api/auth/session endpoint previously included the user's plaintext password in the JSON response. This exposed credentials to browser logs, local caches, and network proxie. This issue has been patched in version 1.4.10.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34833">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25605 – EquityPandit 1.0 contains an insecure logging vulnerability that allows attacker...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25605</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25605</guid>
    <pubDate>Sun, 22 Mar 2026 14:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25605</strong></p>
  <p>EquityPandit 1.0 contains an insecure logging vulnerability that allows attackers to capture sensitive user credentials by accessing developer console logs via Android Debug Bridge. Attackers can use adb logcat to extract plaintext passwords logged during the forgot password function, exposing user account credentials.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-612</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25605">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-29128 – IDC SFX2100 Satellite Receiver firmware ships with multiple daemon configuration...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29128</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29128</guid>
    <pubDate>Thu, 05 Mar 2026 06:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-29128</strong></p>
  <p>IDC SFX2100 Satellite Receiver firmware ships with multiple daemon configuration files for routing components (e.g., zebra, bgpd, ospfd, and ripd) that are owned by root but world-readable. The configuration files (e.g., zebra.conf, bgpd.conf, ospfd.conf, ripd.conf) contain hardcoded or otherwise insecure plaintext passwords (including “enable”/privileged-mode credentials). A remote actor is able…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29128">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27520 – Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27520</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27520</guid>
    <pubDate>Tue, 24 Feb 2026 16:24:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27520</strong></p>
  <p>Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209 store a user password in a client-side cookie as a Base64-encoded value accessible via the web interface. Because Base64 is reversible and provides no confidentiality, an attacker who can access the cookie value can recover the plaintext password.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27520">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-70147 – Missing authentication in /admin/student.php and /admin/teacher.php in ProjectWo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-70147</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-70147</guid>
    <pubDate>Wed, 18 Feb 2026 17:21:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-70147</strong></p>
  <p>Missing authentication in /admin/student.php and /admin/teacher.php in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to obtain sensitive information (including plaintext password field values) via direct HTTP GET requests to these endpoints without a valid session.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-70147">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37097 – Edimax EW-7438RPn 1.13 contains an information disclosure vulnerability that exp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37097</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37097</guid>
    <pubDate>Tue, 03 Feb 2026 22:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37097</strong></p>
  <p>Edimax EW-7438RPn 1.13 contains an information disclosure vulnerability that exposes WiFi network configuration details through the wlencrypt_wiz.asp file. Attackers can access the script to retrieve sensitive information including WiFi network name and plaintext password stored in device configuration variables.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37097">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22240 – The vulnerability exists in BLUVOYIX due to an improper password storage impleme...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22240</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22240</guid>
    <pubDate>Wed, 14 Jan 2026 15:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22240</strong></p>
  <p>The vulnerability exists in BLUVOYIX due to an improper password storage implementation and subsequent exposure via unauthenticated APIs. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable users API to retrieve the plaintext passwords of all user users. Successful exploitation of this vulnerability could allow the attac…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22240">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-56527 – Plaintext password storage in Kotaemon 0.11.0 in the client's localStorage.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-56527</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-56527</guid>
    <pubDate>Tue, 18 Nov 2025 17:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-56527</strong></p>
  <p>Plaintext password storage in Kotaemon 0.11.0 in the client's localStorage.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-256</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-56527">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54593 – FreshRSS is a free, self-hostable RSS aggregator. In versions 1.26.1 and below, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54593</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54593</guid>
    <pubDate>Fri, 01 Aug 2025 18:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54593</strong></p>
  <p>FreshRSS is a free, self-hostable RSS aggregator. In versions 1.26.1 and below, an authenticated administrator user can execute arbitrary code on the FreshRSS server by modifying the update URL to one they control, and gain code execution after running an update. After successfully executing code, user data including hashed passwords can be exfiltrated, the instance can be defaced when file permi…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54593">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-5462 – If Brocade Fabric OS before Fabric OS 9.2.0 configuration settings are not set t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5462</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5462</guid>
    <pubDate>Sat, 15 Feb 2025 00:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-5462</strong></p>
  <p>If Brocade Fabric OS before Fabric OS 9.2.0 configuration settings are not set to encrypt SNMP passwords, then the SNMP privsecret / authsecret fields can be exposed in plaintext. The plaintext passwords can be exposed in a configupload capture or a supportsave capture if encryption of passwords is not enabled. An attacker can use these passwords to fetch values of the supported OIDs via SNMPv3 q…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-319</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5462">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-11982 – Certain models of routers from Billion Electric has a Plaintext Storage of a Pas...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-11982</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-11982</guid>
    <pubDate>Fri, 29 Nov 2024 08:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-11982</strong></p>
  <p>Certain models of routers from Billion Electric has a Plaintext Storage of a Password vulnerability. Remote attackers with administrator privileges can access the user settings page to retrieve plaintext passwords.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-256</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11982">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-48353 – Yealink Meeting Server before V26.0.0.67 allows attackers to obtain static key i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-48353</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-48353</guid>
    <pubDate>Fri, 01 Nov 2024 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-48353</strong></p>
  <p>Yealink Meeting Server before V26.0.0.67 allows attackers to obtain static key information from a front-end JS file and decrypt the plaintext passwords based on the obtained key information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-922</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-48353">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-8455 – The swctrl service is used to detect and remotely manage PLANET Technology devic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-8455</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-8455</guid>
    <pubDate>Mon, 30 Sep 2024 08:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-8455</strong></p>
  <p>The swctrl service is used to detect and remotely manage PLANET Technology devices. For certain switch models, the authentication tokens used during communication with this service are encoded user passwords. Due to insufficient strength, unauthorized remote attackers who intercept the packets can directly crack them to obtain plaintext passwords.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-261</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8455">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-36460 – The front-end audit log allows viewing of unprotected plaintext passwords, where...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36460</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36460</guid>
    <pubDate>Mon, 12 Aug 2024 13:38:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-36460</strong></p>
  <p>The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain text.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-256</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36460">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23091 – Weak password hashing using MD5 in funzioni.php in HotelDruid before 1.32 allows...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23091</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23091</guid>
    <pubDate>Tue, 30 Jul 2024 14:15:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23091</strong></p>
  <p>Weak password hashing using MD5 in funzioni.php in HotelDruid before 1.32 allows an attacker to obtain plaintext passwords from hash values.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-916</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23091">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-40116 – An issue in Solar-Log 1000 before v2.8.2 and build 52-23.04.2013 was discovered ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-40116</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-40116</guid>
    <pubDate>Fri, 26 Jul 2024 20:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-40116</strong></p>
  <p>An issue in Solar-Log 1000 before v2.8.2 and build 52-23.04.2013 was discovered to store plaintext passwords in the export.html, email.html, and sms.html files -- fixed with 3.0.0-60 11.10.2013 for SL 200, 500, 1000 / not existing for SL 250, 300, 1200, 2000, SL 50 Gateway, SL Base.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-256</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-40116">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-38994 – The 'check_univention_joinstatus' prometheus monitoring script (and other script...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38994</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38994</guid>
    <pubDate>Tue, 31 Oct 2023 12:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-38994</strong></p>
  <p>The 'check_univention_joinstatus' prometheus monitoring script (and other scripts) in UCS 5.0-5 revealed the LDAP plaintext password of the machine account in the process list allowing attackers with local ssh access to gain higher privileges and perform followup attacks. By default, the configuration of UCS does not allow local ssh access for regular users.</p>
  <p><strong>CVSS:</strong> 7.9 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38994">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-0525 – Weak Encoding for Password vulnerability in Mitsubishi Electric Corporation GOT2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0525</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0525</guid>
    <pubDate>Fri, 04 Aug 2023 00:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-0525</strong></p>
  <p>Weak Encoding for Password vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT27 model versions 01.49.000 and prior, GT25 model versions 01.49.000 and prior, GT23 model versions 01.49.000 and prior, GT21 model versions 01.49.000 and prior, GOT SIMPLE Series GS25 model versions 01.49.000 and prior, GS21 model versions 01.49.000 and prior, GT Designer3 Version1 (GOT2000) versions 1.2…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-261</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0525">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-30275 – The Motorola MOSCAD Toolbox software through 2022-05-02 relies on a cleartext pa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-30275</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-30275</guid>
    <pubDate>Tue, 26 Jul 2022 22:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-30275</strong></p>
  <p>The Motorola MOSCAD Toolbox software through 2022-05-02 relies on a cleartext password. It utilizes an MDLC driver to communicate with MOSCAD/ACE RTUs for engineering purposes. Access to these communications is protected by a password stored in cleartext in the wmdlcdrv.ini driver configuration file. In addition, this password is used for access control to MOSCAD/STS projects protected with the L…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-30275">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-39614 – D-Link DVX-2000MS contains hard-coded credentials for undocumented user accounts...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-39614</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-39614</guid>
    <pubDate>Mon, 23 Aug 2021 22:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-39614</strong></p>
  <p>D-Link DVX-2000MS contains hard-coded credentials for undocumented user accounts in the '/etc/passwd' file. As weak passwords have been used, the plaintext passwords can be recovered from the hash values.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39614">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-39613 – D-Link DVG-3104MS version 1.0.2.0.3, 1.0.2.0.4, and 1.0.2.0.4E contains hard-cod...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-39613</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-39613</guid>
    <pubDate>Mon, 23 Aug 2021 22:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-39613</strong></p>
  <p>D-Link DVG-3104MS version 1.0.2.0.3, 1.0.2.0.4, and 1.0.2.0.4E contains hard-coded credentials for undocumented user accounts in the '/etc/passwd' file. As weak passwords have been used, the plaintext passwords can be recovered from the hash values. NOTE: This vulnerability only affects products that are no longer supported by the maintainer</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39613">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-13952 – In the course of work on the open source project it was discovered that authenti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13952</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13952</guid>
    <pubDate>Wed, 30 Sep 2020 21:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-13952</strong></p>
  <p>In the course of work on the open source project it was discovered that authenticated users running queries against Hive and Presto database engines could access information via a number of templated fields including the contents of query description metadata database, the hashed version of the authenticated users’ password, and access to connection information including the plaintext password fo…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13952">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-16211 – Brocade SANnav versions before v2.1.0, contain a Plaintext Password Storage vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-16211</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-16211</guid>
    <pubDate>Fri, 25 Sep 2020 14:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-16211</strong></p>
  <p>Brocade SANnav versions before v2.1.0, contain a Plaintext Password Storage vulnerability.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-16211">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-6663 – General Electric D20ME devices are not properly configured and reveal plaintext ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-6663</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-6663</guid>
    <pubDate>Thu, 23 Jan 2020 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-6663</strong></p>
  <p>General Electric D20ME devices are not properly configured and reveal plaintext passwords.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-6663">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-13378 – An information disclosure vulnerability in Fortinet FortiSIEM 5.2.0 and below ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-13378</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-13378</guid>
    <pubDate>Wed, 17 Apr 2019 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-13378</strong></p>
  <p>An information disclosure vulnerability in Fortinet FortiSIEM 5.2.0 and below versions exposes the LDAP server plaintext password via the HTML source code.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-13378">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-10630 – A plaintext password vulnerability in the Zyxel NAS 326 through 5.21 allows an e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10630</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10630</guid>
    <pubDate>Tue, 09 Apr 2019 05:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-10630</strong></p>
  <p>A plaintext password vulnerability in the Zyxel NAS 326 through 5.21 allows an elevated privileged user to get the admin password of the device.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10630">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-6518 – Moxa IKS and EDS store plaintext passwords, which may allow sensitive informatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-6518</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-6518</guid>
    <pubDate>Tue, 05 Mar 2019 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-6518</strong></p>
  <p>Moxa IKS and EDS store plaintext passwords, which may allow sensitive information to be read by someone with access to the device.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-256</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-6518">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-11325 – An issue was discovered in Joomla! Core before 3.8.8. The web install applicatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-11325</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-11325</guid>
    <pubDate>Tue, 22 May 2018 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-11325</strong></p>
  <p>An issue was discovered in Joomla! Core before 3.8.8. The web install application would autofill password fields after either a form validation error or navigating to a previous install step, and display the plaintext password for the administrator account at the confirmation screen.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-209</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-11325">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-0925 – Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently prot...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-0925</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-0925</guid>
    <pubDate>Wed, 21 Mar 2018 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-0925</strong></p>
  <p>Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration API endpoint resulting in an information disclosure of plaintext password.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-0925">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-9854 – An issue was discovered in SMA Solar Technology products. By sniffing for specif...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-9854</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-9854</guid>
    <pubDate>Sat, 05 Aug 2017 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-9854</strong></p>
  <p>An issue was discovered in SMA Solar Technology products. By sniffing for specific packets on the localhost, plaintext passwords can be obtained as they are typed into Sunny Explorer by the user. These passwords can then be used to compromise the overall device. NOTE: the vendor reports that exploitation likelihood is low because these packets are usually sent only once during installation. Also,…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-311</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-9854">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-7318 – Siklu EtherHaul devices before 7.4.0 are vulnerable to a remote command executio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-7318</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-7318</guid>
    <pubDate>Thu, 30 Mar 2017 07:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-7318</strong></p>
  <p>Siklu EtherHaul devices before 7.4.0 are vulnerable to a remote command execution (RCE) vulnerability. This vulnerability allows a remote attacker to execute commands and retrieve information such as usernames and plaintext passwords from the device with no authentication.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7318">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-6528 – An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is affected by pl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-6528</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-6528</guid>
    <pubDate>Thu, 09 Mar 2017 19:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-6528</strong></p>
  <p>An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is affected by plaintext password storage (the /home/dna/spool/.pfile file).</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-6528">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2005-4448 – FlatNuke 2.5.6 verifies authentication credentials based on an MD5 checksum of t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-4448</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-4448</guid>
    <pubDate>Wed, 21 Dec 2005 11:03:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2005-4448</strong></p>
  <p>FlatNuke 2.5.6 verifies authentication credentials based on an MD5 checksum of the admin name and the hashed password rather than the plaintext password, which allows attackers to gain privileges by obtaining the password hash (possibly via CVE-2005-2813), then calculating the credentials and including them in the secid cookie.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-4448">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2004-0823 – OpenLDAP 1.0 through 2.1.19, as used in Apple Mac OS 10.3.4 and 10.3.5 and possi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2004-0823</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2004-0823</guid>
    <pubDate>Tue, 07 Sep 2004 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2004-0823</strong></p>
  <p>OpenLDAP 1.0 through 2.1.19, as used in Apple Mac OS 10.3.4 and 10.3.5 and possibly other operating systems, may allow certain authentication schemes to use hashed (crypt) passwords in the userPassword attribute as if they were plaintext passwords, which allows remote attackers to re-use hashed passwords without decrypting them.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2004-0823">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2003-0414 – The installation of Sun ONE Application Server 7.0 for Windows 2000/XP creates a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2003-0414</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2003-0414</guid>
    <pubDate>Mon, 30 Jun 2003 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2003-0414</strong></p>
  <p>The installation of Sun ONE Application Server 7.0 for Windows 2000/XP creates a statefile with world-readable permissions, which allows local users to gain privileges by reading a plaintext password in the statefile.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2003-0414">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2000-0957 – The pluggable authentication module for mysql (pam_mysql) before 0.4.7 does not ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2000-0957</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2000-0957</guid>
    <pubDate>Tue, 19 Dec 2000 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2000-0957</strong></p>
  <p>The pluggable authentication module for mysql (pam_mysql) before 0.4.7 does not properly cleanse user input when constructing SQL statements, which allows attackers to obtain plaintext passwords or hashes.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2000-0957">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-1999-1073 – Excite for Web Servers (EWS) 1.1 records the first two characters of a plaintext...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-1999-1073</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-1999-1073</guid>
    <pubDate>Mon, 30 Nov 1998 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-1999-1073</strong></p>
  <p>Excite for Web Servers (EWS) 1.1 records the first two characters of a plaintext password in the beginning of the encrypted password, which makes it easier for an attacker to guess passwords via a brute force or dictionary attack.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-1999-1073">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
