CVE-2025-13187Medium· 5.3▾ SunlitA security vulnerability has been detected in Intelbras ICIP 2.0.20. Affected is an unknown function of the file /xml/sistema/acessodeusuario.xml. Such manipulation of the argument NomeUsuario/SenhaAcess leads to unprotected storage of c…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
A security vulnerability has been detected in Intelbras ICIP 2.0.20. Affected is an unknown function of the file /xml/sistema/acessodeusuario.xml. Such manipulation of the argument NomeUsuario/SenhaAcess leads to unprotected storage of credentials. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.
icip_30_firmware = 2.0.20Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-13221Medium· 5.3A weakness has been identified in Intelbras UnniTI 24.07.11
CVE-2025-14183Medium· 4.3A vulnerability was found in SGAI Space1 NAS N1211DS up to 1.0.915
CVE-2025-15128Medium· 5.3A vulnerability was detected in ZKTeco BioTime up to 9.0.3/9.0.4/9.5.2
CVE-2024-45636Medium· 4.1IBM Security QRadar EDR 3.12 through 3.12.24 stores user credentials in plain text which can be read by a local privileged user.
CVE-2026-55765High· 8.5CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments
CVE-2020-5404Medium· 5.9The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorrectly, leading to a credentials leak during a redirect to a different domain