Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.5
CVE-2024-28981
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.8, including 8.3.x, discloses database passwords when searchi…
Mitigation only
MEDIUM 5.5
CVE-2024-20489
A vulnerability in the storage method of the PON Controller configuration file could allow an authenticated, local attacker with low privileges to ob…
Ios Xr
Mitigation only
HIGH 8.8
CVE-2024-40710
A series of related high-severity vulnerabilities, the most notable enabling remote code execution (RCE) as the service account and extraction of sen…
Veeam Backup \& Replication
12.2.0.334+
HIGH 8.8
CVE-2023-49233
Insufficient access checks in Visual Planning Admin Center 8 before v.1 Build 240207 allow attackers in possession of a non-administrative Visual Pla…
No fix yet
MEDIUM 6.8
CVE-2024-31800
Authentication Bypass in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to gain a privileged command shell via the U…
Gncc C2 Firmware
No fix yet
HIGH 7.5
CVE-2024-7813
A vulnerability, which was classified as problematic, has been found in SourceCodester Prison Management System 1.0. This issue affects some unknown …
Prison Management System
No fix yet
MEDIUM 6.5
CVE-2024-39818
Protection mechanism failure for some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct information disclosure via network acce…
Workplace Desktop
5.17.13 / 6.0.0+
HIGH 8.1
CVE-2024-36460
The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain text.
Zabbix
after 6.4.15
CRITICAL 9.1
CVE-2024-6118
A Plaintext Storage of a Password vulnerability in ebooknote function in Hamastar MeetingHub Paperless Meetings 2021 allows remote attackers to obtai…
Meetinghub Paperless Meetings
Mitigation only
HIGH 7.5
CVE-2024-7389
The Forminator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.29.1 via class-forminator…
Forminator
1.29.2+
HIGH 7.4
CVE-2024-6492
Exposure of Sensitive Information in edge browser session proxy feature in Devolutions Remote Desktop Manager 2024.2.14.0 and earlier on Windows allo…
Remote Desktop Manager
2024.2.15.0+
MEDIUM 5.5
CVE-2024-39733
IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 stores user credentials in plain clear text which can be read by a local user. IBM X-For…
Datacap
Mitigation only
HIGH 7.5
CVE-2024-38453
The Avalara for Salesforce CPQ app before 7.0 for Salesforce allows attackers to read an API key. NOTE: the current version is 11 as of mid-2024.
Mitigation only
HIGH 8.8
CVE-2023-41926
The webserver utilizes basic authentication for its user login to the configuration interface. As encryption is disabled on port 80, it enables poten…
Mitigation only
MEDIUM 5.3
CVE-2024-39878
In JetBrains TeamCity before 2024.03.3 private key could be exposed via testing GitHub App Connection
Teamcity
2024.03.3+
MEDIUM 5.3
CVE-2024-39879
In JetBrains TeamCity before 2024.03.3 application token could be exposed in EC2 Cloud Profile settings
Teamcity
2024.03.3+
HIGH 7.5
CVE-2024-38505
In JetBrains YouTrack before 2024.2.34646 user access token was sent to the third-party site
Youtrack
2024.2.34646+
HIGH 8.5
CVE-2024-38282
Utilizing default credentials, an attacker is able to log into the camera's operating system which could allow changes to be made to the operations o…
Mitigation only
HIGH 7.0
CVE-2024-38285
Logs storing credentials are insufficiently protected and can be decoded through the use of open source tools.
Mitigation only
MEDIUM 6.5
CVE-2024-26330
An issue was discovered in Kape CyberGhostVPN 8.4.3.12823 on Windows. After a successful logout, user credentials remain in memory while the process …
Mitigation only
MEDIUM 5.5
CVE-2024-35208
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server stored the password…
Sinec Traffic Analyzer
1.2+
HIGH 7.5
CVE-2024-37051
GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 202…
Aqua
2023.1.3 / 2023.1.6+
HIGH 8.1
CVE-2024-5657
The CraftCMS plugin Two-Factor Authentication in versions 3.3.1, 3.3.2 and 3.3.3 discloses the password hash of the currently authenticated user afte…
Two Factor Authentication
3.3.4+
HIGH 7.5
CVE-2024-36127
apko is an apk-based OCI image builder. apko exposures HTTP basic auth credentials from repository and keyring URLs in log output. This vulnerability…
Patch available
CRITICAL 9.4
CVE-2024-5176
Insufficiently Protected Credentials vulnerability in Baxter Welch Allyn Configuration Tool may allow Remote Services with Stolen Credentials.This is…
Mitigation only
MEDIUM 6.5
CVE-2024-33849
ci solution CI-Out-of-Office Manager through 6.0.0.77 uses a Hard-coded Cryptographic Key.
Mitigation only
MEDIUM 5.5
CVE-2024-35192
Trivy is a security scanner. Prior to 0.51.2, if a malicious actor is able to trigger Trivy to scan container images from a crafted malicious registr…
Patch available
CRITICAL 9.8
CVE-2024-36081
Westermo EDW-100 devices through 2024-05-03 allow an unauthenticated user to download a configuration file containing a cleartext password. NOTE: thi…
Mitigation only
MEDIUM 6.7
CVE-2024-23583
An attacker could potentially intercept credentials via the task manager and perform unauthorized access to the Client Deploy Tool on Windows systems.
Bigfix Platform
9.5.25 / 10.0.12+
HIGH 7.6
CVE-2024-27109
Insufficiently protected credentials in GE HealthCare EchoPAC products
Mitigation only