Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2023-43777
Eaton easySoft software is used to program easy controllers and displays for configuring, programming and defining parameters for all the intelligent…
Easysoft
8.01+
MEDIUM 5.5
CVE-2023-27315
SnapGathers versions prior to 4.9 are susceptible to a vulnerability
which could allow a local authenticated attacker to discover plaintext
domain …
Snapgathers
4.9+
HIGH 8.2
CVE-2022-44757
BigFix Insights for Vulnerability Remediation (IVR) uses weak cryptography that can lead to credential exposure. An attacker could gain access to se…
Bigfix Insights For Vulnerability Remediation
2.0.3+
MEDIUM 5.3
CVE-2022-44758
BigFix Insights/IVR fixlet uses improper credential handling within certain fixlet content. An attacker can gain access to information that is not e…
Bigfix Insights For Vulnerability Remediation
2.0.3+
HIGH 7.5
CVE-2023-44158
Sensitive information disclosure due to insufficient token field masking. The following products are affected: Acronis Cyber Protect 15 (Linux, Windo…
Cyber Protect
15+
MEDIUM 5.5
CVE-2023-1633
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining acce…
Openstack Platform
Mitigation only
HIGH 8.8
CVE-2023-43633
On boot, the Pillar eve container checks for the existence and content of
“/config/GlobalConfig/global.json”.
If the file exists, it overrides the e…
Eve
8.6.0 / 9.5.0+
HIGH 8.8
CVE-2023-43634
When sealing/unsealing the “vault” key, a list of PCRs is used, which defines which PCRs
are used.
In a previous project, CYMOTIVE found that the co…
Eve
8.6.0 / 9.5.0+
HIGH 8.8
CVE-2023-43631
On boot, the Pillar eve container checks for the existence and content of
“/config/authorized_keys”.
If the file is present, and contains a supporte…
Edge Virtualization Engine
8.6.0 / 9.5.0+
HIGH 8.8
CVE-2023-43630
PCR14 is not in the list of PCRs that seal/unseal the “vault” key, but
due to the change that was implemented in commit
“7638364bc0acf8b5c481b5ce5fea…
Edge Virtualization Engine
9.5.0+
HIGH 8.8
CVE-2023-43635
Vault Key Sealed With SHA1 PCRs
The measured boot solution implemented in EVE OS leans on a PCR locking mechanism.
Different parts of the syst…
Edge Virtualization Engine
9.5.0+
MEDIUM 5.5
CVE-2022-47561
The web application stores credentials in clear text in the "admin.xml" file, which can be accessed without logging into the website, which could all…
Ekorccp Firmware
Mitigation only
CRITICAL 9.8
CVE-2023-25531
NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause insufficient protection of credentials. A successful exploit of thi…
Dgx H100 Firmware
23.08.18+
HIGH 7.5
CVE-2023-25532
NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause insufficient protection of credentials. A successful exploit of thi…
Dgx H100 Firmware
23.08.18+
MEDIUM 5.5
CVE-2023-41010
Insecure Permissions vulnerability in Sichuan Tianyi Kanghe Communication Co., Ltd China Telecom Tianyi Home Gateway v.TEWA-700G allows a local attac…
Tewa 700g Firmware
No fix yet
MEDIUM 5.5
CVE-2023-32338
IBM Sterling Secure Proxy and IBM Sterling External Authentication Server 6.0.3 and 6.1.0 stores user credentials in plain clear text which can be re…
Sterling External Authentication Server
Mitigation only
CRITICAL 9.8
CVE-2022-45611
An issue was discovered in Fresenius Kabi PharmaHelp 5.1.759.0 allows attackers to gain escalated privileges via via capture of user login informatio…
Pharmahelp Firmware
Mitigation only
HIGH 7.5
CVE-2023-40173
Social media skeleton is an uncompleted/framework social media project implemented using a php, css ,javascript and html. Prior to version 1.0.5 Soci…
Social Media Skeleton
1.0.5+
MEDIUM 6.5
CVE-2023-31492EPSS 8%
Zoho ManageEngine ADManager Plus version 7182 and prior disclosed the default passwords for the account restoration of unauthorized domains to the au…
Manageengine Admanager Plus
7.1+
MEDIUM 6.5
CVE-2023-40347
Jenkins Maven Artifact ChoiceListProvider (Nexus) Plugin 1.14 and earlier does not set the appropriate context for credentials lookup, allowing attac…
Maven Artifact Choicelistprovider \(nexus\)
after 1.14
MEDIUM 6.5
CVE-2023-40345
Jenkins Delphix Plugin 3.0.2 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Overall/Read permission…
Delphix
after 3.0.2
MEDIUM 5.5
CVE-2023-4327
Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user …
Raid Controller Web Interface
Mitigation only
MEDIUM 5.5
CVE-2023-4328
Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user…
Raid Controller Web Interface
Mitigation only
CRITICAL 9.8
CVE-2023-20965
In processMessageImpl of ClientModeImpl.java, there is a possible credential disclosure in the TOFU flow due to a logic error in the code. This could…
Android
Patch available
CRITICAL 9.8
CVE-2023-36082
An isssue in GatesAIr Flexiva FM Transmitter/Exiter Fax 150W allows a remote attacker to gain privileges via the LDAP and SMTP credentials.
Flexiva Fax 150w Firmware
Mitigation only
MEDIUM 6.5
CVE-2022-4926
Insufficient policy enforcement in Intents in Google Chrome on Android prior to 109.0.5414.119 allowed a remote attacker to bypass same origin policy…
Chrome
109.0.5414.119+
HIGH 7.5
CVE-2023-35067
Plaintext Storage of a Password vulnerability in Infodrom Software E-Invoice Approval System allows Read Sensitive Strings Within an Executable.
Thi…
E Invoice Approval System
20230701+
HIGH 8.8
CVE-2023-37362
Weintek Weincloud v0.13.6
could allow an attacker to abuse the registration functionality to login with testing credentials to the official websi…
Weincloud
Mitigation only
HIGH 7.5
CVE-2023-31824
An issue found in DERICIA Co. Ltd, DELICIA v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token in …
Delicia
No fix yet
CRITICAL 9.8
CVE-2023-34128
Tomcat application credentials are hardcoded in SonicWall GMS and Analytics configuration file. This issue affects GMS: 9.3.2-SP1 and earlier version…
Analytics
9.3.2+