Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2023-31824
An issue found in DERICIA Co. Ltd, DELICIA v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token in …
Delicia
No fix yet
CRITICAL 9.8
CVE-2023-34128
Tomcat application credentials are hardcoded in SonicWall GMS and Analytics configuration file. This issue affects GMS: 9.3.2-SP1 and earlier version…
Analytics
9.3.2+
MEDIUM 6.5
CVE-2023-37951
Jenkins mabl Plugin 0.0.46 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission…
Mabl
after 0.0.46
MEDIUM 5.5
CVE-2023-36266
An issue was discovered in Keeper Password Manager for Desktop version 16.10.2 (fixed in 17.2), and the KeeperFill Browser Extensions version 16.5.4 …
Keeper
No fix yet
MEDIUM 6.5
CVE-2023-35348
Active Directory Federation Service Security Feature Bypass Vulnerability
Windows Server 2016
Patch available
MEDIUM 5.5
CVE-2023-36476
calamares-nixos-extensions provides Calamares branding and modules for NixOS, a distribution of GNU/Linux. Users of calamares-nixos-extensions versio…
Calamares Nixos Extensions
0.3.13+
HIGH 7.5
CVE-2020-18406
An issue was discovered in cmseasy v7.0.0 that allows user credentials to be sent in clear text due to no encryption of form data.
Cmseasy
No fix yet
HIGH 7.5
CVE-2023-28857
Apereo CAS is an open source multilingual single sign-on solution for the web. Apereo CAS can be configured to use authentication based on client X50…
Central Authentication Service
6.5.9.1 / 6.6.6+
MEDIUM 5.5
CVE-2023-35789
An issue was discovered in the C AMQP client library (aka rabbitmq-c) through 0.13.0 for RabbitMQ. Credentials can only be entered on the command lin…
Rabbitmq C
after 0.13.0
HIGH 7.3
CVE-2022-47376
The Alaris Infusion Central software, versions 1.1 to 1.3.2, may contain a recoverable password after the installation. No patient health data is sto…
Alaris Infusion Central
after 1.3.2
MEDIUM 5.9
CVE-2023-33620
GL.iNET GL-AR750S-Ext firmware v3.215 uses an insecure protocol in its communications which allows attackers to eavesdrop via a man-in-the-middle att…
Gl Ar750s Firmware
No fix yet
CRITICAL 9.8
CVE-2023-26204
A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 al…
Fortisiem
after 6.7.5
HIGH 7.5
CVE-2023-29168
The local Vuforia web application does not support HTTPS, and federated credentials are passed via basic authentication.
Vuforia Studio
9.9+
HIGH 7.5
CVE-2023-22862
IBM Aspera Connect 4.2.5 and IBM Aspera Cargo 4.2.5 transmits authentication credentials, but it uses an insecure method that is susceptible to unaut…
Aspera Cargo
4.2.6+
HIGH 8.8
CVE-2023-25740
After downloading a Windows <code>.scf</code> script from the local filesystem, an attacker could supply a remote path that would lead to unexpected …
Firefox
110.0+
MEDIUM 6.5
CVE-2023-31187
Avaya IX Workforce Engagement v15.2.7.1195 - CWE-522: Insufficiently Protected Credentials
Ix Workforce Engagement
No fix yet
MEDIUM 6.5
CVE-2023-32687
tgstation-server is a toolset to manage production BYOND servers. Starting in version 4.7.0 and prior to 5.12.1, instance users with the list chat bo…
Tgstation Server
5.12.1+
HIGH 7.5
CVE-2023-33263
In WFTPD 3.25, usernames and password hashes are stored in an openly viewable wftpd.ini configuration file within the WFTPD directory. NOTE: this is …
Wftpd
No fix yet
MEDIUM 6.5
CVE-2023-1763
Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS …
Ij Network Tool
after 4.7.5
HIGH 7.5
CVE-2023-33000
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.149 and earlier does not mask credentials displayed on the configuration form, increasin…
Ns Nd Integration Performance Publisher
after 4.8.0.149
MEDIUM 5.3
CVE-2022-47880
An Information disclosure vulnerability in /be/rpc.php in Jedox GmbH Jedox 2020.2.5 allow remote, authenticated users with permissions to modify data…
Jedox
No fix yet
MEDIUM 6.5
CVE-2022-40685
Insufficiently protected credentials in the Intel(R) DCM software before version 5.0.1 may allow an authenticated user to potentially enable informat…
Data Center Manager
5.0.1+
HIGH 8.8
CVE-2023-20046
A vulnerability in the key-based SSH authentication feature of Cisco StarOS Software could allow an authenticated, remote attacker to elevate privile…
Staros
21.22.14 / 21.23.31+
MEDIUM 5.9
CVE-2023-31136
PostgresNIO is a Swift client for PostgreSQL. Any user of PostgresNIO prior to version 1.14.2 connecting to servers with TLS enabled is vulnerable to…
Postgresnio
1.14.2+
MEDIUM 5.9
CVE-2023-28764
SAP BusinessObjects Platform - versions 420, 430, Information design tool transmits sensitive information as cleartext in the binaries over the netwo…
Businessobjects
Mitigation only
HIGH 7.5
CVE-2023-24506
Milesight NCR/camera version 71.8.0.6-r5 exposes credentials through an unspecified request.
Ncr\/camera Firmware
Mitigation only
HIGH 7.5
CVE-2023-2335
Plaintext Password in Registry
vulnerability in 42gears surelock windows surelockwinsetupv2.40.0.Exe on Windows (Registery modules) allows Retrieve…
Surelock
after 2.40.0
CRITICAL 9.8
CVE-2023-1778
This vulnerability exists in GajShield Data Security Firewall firmware versions prior to v4.28 (except v4.21) due to insecure default credentials whi…
Data Security Firewall Firmware
4.21 / 4.28+
HIGH 7.5
CVE-2023-30846
typed-rest-client is a library for Node Rest and Http Clients with typings for use with TypeScript. Users of the typed-rest-client library version 1.…
Typed Rest Client
1.8.0+
HIGH 8.1
CVE-2023-26567
Sangoma FreePBX 1805 through 2302 (when obtained as a ,.ISO file) places AMPDBUSER, AMPDBPASS, AMPMGRUSER, and AMPMGRPASS in the list of global varia…
Freepbx Linux 7
Mitigation only