Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2023-48010
STMicroelectronics SPC58 is vulnerable to Missing Protection Mechanism for Alternate Hardware Interface. Code running as Supervisor on the SPC58 Powe…
Mitigation only
HIGH 7.5
CVE-2024-51546
Credentials Disclosure vulnerabilities allow access to on board project back-up bundles.
Affected products:
ABB ASPECT - Enterprise v3.08.02;
NEX…
Aspect Ent 12 Firmware
3.08.03+
CRITICAL 9.8
CVE-2024-51545
Username Enumeration vulnerabilities allow access to application level username add, delete, modify and list functions.
Affected products:
ABB ASP…
Aspect Ent 12 Firmware
3.08.03+
MEDIUM 6.5
CVE-2024-42457
A vulnerability in Veeam Backup & Replication allows users with certain operator roles to expose saved credentials by leveraging a combination of met…
Veeam Backup \& Replication
12.3.0.310+
CRITICAL 9.0
CVE-2019-17082
Insufficiently Protected Credentials vulnerability in OpenText™ AccuRev allows Authentication Bypass. When installed on a Linux or Solaris system
th…
Mitigation only
MEDIUM 5.7
CVE-2024-11703
On Android, Firefox may have inadvertently allowed viewing saved passwords without the required device PIN authentication. This vulnerability affects…
Firefox
133.0+
MEDIUM 6.3
CVE-2024-6749
Seth Fogie, member of the AXIS Camera Station Pro Bug Bounty Program, has found that the Incident report feature may expose sensitive credentials on …
Mitigation only
MEDIUM 5.5
CVE-2024-47142
AIPHONE IXG SYSTEM IXG-2C7 firmware Ver.2.03 and earlier and IXG-2C7-L firmware Ver.2.03 and earlier contain an issue with insufficiently protected c…
Mitigation only
MEDIUM 6.5
CVE-2024-39290
Insufficiently protected credentials issue exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent unauthenticated attacker may obtain sensiti…
Mitigation only
MEDIUM 6.5
CVE-2021-1232
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to read arb…
Catalyst Sd Wan Manager
Mitigation only
CRITICAL 9.1
CVE-2022-45157
A vulnerability has been identified in the way that Rancher stores vSphere's CPI (Cloud Provider Interface) and CSI (Container Storage Interface) cre…
Mitigation only
HIGH 8.0
CVE-2024-51240
An issue in the luci-mod-rpc package in OpenWRT Luci LTS allows for privilege escalation from an admin account to root via the JSON-RPC-API, which is…
Mitigation only
MEDIUM 6.8
CVE-2024-34885
Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to read SMTP accounts pass…
Bitrix24
No fix yet
HIGH 7.5
CVE-2023-50310
IBM CICS Transaction Gateway for Multiplatforms 9.2 and 9.3 transmits or stores authentication credentials, but it uses an insecure method that is su…
Cics Transaction Gateway
Mitigation only
HIGH 8.4
CVE-2024-43812
Kieback & Peter's DDC4000 series has an insufficiently protected credentials vulnerability, which may allow an unauthenticated attacker with access t…
Mitigation only
HIGH 7.8
CVE-2024-9677
The insufficiently protected credentials vulnerability in the CLI command of the USG FLEX H series uOS firmware version V1.21 and earlier versions co…
Uos
1.30+
CRITICAL 9.8
CVE-2024-44000EPSS 82%
Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Authentication Bypass.This issue …
Litespeed Cache
6.5.0.1+
HIGH 8.2
CVE-2024-7755
The EWON FLEXY 202 transmits credentials using a weak encoding method base64. An attacker who is present in the network can sniff the traffic and dec…
Mitigation only
HIGH 8.7
CVE-2024-49396
The affected product is vulnerable due to insufficiently protected credentials, which may allow an attacker to impersonate Elvaco and send false info…
Mitigation only
MEDIUM 5.5
CVE-2024-20462
A vulnerability in the web-based management interface of Cisco ATA 190 Series Multiplatform Analog Telephone Adapter firmware could allow an authenti…
Ata 191 Firmware
11.2.5 / 12.0.2+
MEDIUM 6.5
CVE-2024-47161
In JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST API
Teamcity
2024.07.3+
HIGH 7.5
CVE-2024-47805
Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentials using…
Credentials
1371.1373.v4eb_fa_b_7161e9 / 1380.va_435002fa_924+
MEDIUM 5.7
CVE-2024-34542
Advantech ADAM-5630 shares user credentials plain text between the device and the user source device during the login process.
Adam 5630 Firmware
2.5.2+
MEDIUM 5.7
CVE-2024-37187
Advantech ADAM-5550 share user credentials with a low level of encryption, consisting of base 64 encoding.
Adam 5550 Firmware
Mitigation only
MEDIUM 6.5
CVE-2024-9014EPSS 10%
pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially ob…
Pgadmin 4
8.12+
MEDIUM 5.5
CVE-2024-40703
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and IBM Cognos Analytics Reports for iOS 11.0.0.7 could …
Cognos Analytics
12.0.3+
MEDIUM 5.3
CVE-2024-47162
In JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports page
Youtrack
2024.3.44799+
CRITICAL 9.1
CVE-2024-8986
The grafana plugin SDK bundles build metadata into the binaries it compiles; this metadata includes the repository URI for the plugin being built, as…
Mitigation only
HIGH 7.5
CVE-2024-8777
OMFLOW from The SYSCOM Group has an information leakage vulnerability, allowing unauthorized remote attackers to read arbitrary system configurations…
Omflow
1.2.1.3+
HIGH 8.1
CVE-2024-31415
The Eaton Foreseer software provides the feasibility for the user to configure external servers for multiple purposes such as network management, use…
Foreseer Electrical Power Monitoring System
7.8.600+