Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.5
CVE-2022-29959
Emerson OpenBSI through 2022-04-29 mishandles credential storage. It is an engineering environment for the ControlWave and Bristol Babcock line of RT…
Openbsi
5.9+
MEDIUM 6.8
CVE-2022-36307
The AirVelocity 1500 prints SNMP credentials on its physically accessible serial port during boot. This was fixed in AirVelocity 1500 software versio…
Airvelocity 1500 Firmware
after 15.18.00.2511
CRITICAL 9.1
CVE-2022-36308
Airspan AirVelocity 1500 web management UI displays SNMP credentials in plaintext on software versions older than 15.18.00.2511, and stores SNMPv3 cr…
Airvelocity 1500 Firmware
after 15.18.00.2511
MEDIUM 5.9
CVE-2022-22983
VMware Workstation (16.x prior to 16.2.4) contains an unprotected storage of credentials vulnerability. A malicious actor with local user privileges …
Workstation
16.2.4+
MEDIUM 6.5
CVE-2022-33169
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to insufficiently protected credentials for users created via a bulk upload. …
Robotic Process Automation
after 21.0.3
MEDIUM 5.0
CVE-2021-27785
HCL Commerce's Remote Store server could allow a local attacker to obtain sensitive personal information. The vulnerability requires the victim to fi…
Hcl Commerce
after 9.1.10
CRITICAL 9.8
CVE-2021-22640
An attacker can decrypt the Ovarro TBox login password by communication capture and brute force attacks.
Twinsoft
1.46 / 12.4+
MEDIUM 6.5
CVE-2022-36901
Jenkins HTTP Request Plugin 1.15 and earlier stores HTTP Request passwords unencrypted in its global configuration file on the Jenkins controller whe…
Http Request
after 1.15
HIGH 7.5
CVE-2022-1766
Anchore Enterprise anchorectl version 0.1.4 improperly stored credentials when generating a Software Bill of Materials. anchorectl will add the crede…
Anchore
0.1.5 / 4.0.1+
MEDIUM 6.5
CVE-2022-27544
BigFix Web Reports authorized users may see SMTP credentials in clear text.
Bigfix Platform
after 10.0.6
HIGH 7.5
CVE-2022-22998
Implemented protections on AWS credentials that were not properly protected.
My Cloud Home Duo Firmware
8.5.1-102+
MEDIUM 5.5
CVE-2022-1794
The CODESYS OPC DA Server prior V3.5.18.20 stores PLC passwords as plain text in its configuration file so that it is visible to all authorized Micro…
Opc Da Server
3.5.18.20+
CRITICAL 9.8
CVE-2022-35411EPSS 46%
rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header is sent. In other words, altho…
Rpc.py
after 0.6.0
MEDIUM 5.5
CVE-2022-27548
HCL Launch stores user credentials in plain clear text which can be read by a local user.
Hcl Launch
Mitigation only
MEDIUM 5.5
CVE-2022-23725
PingID Windows Login prior to 2.8 does not properly set permissions on the Windows Registry entries used to store sensitive API keys under some circu…
Pingid Integration For Windows Login
2.8+
MEDIUM 6.5
CVE-2022-34816
Jenkins HPE Network Virtualization Plugin 1.0 stores passwords unencrypted in its global configuration file on the Jenkins controller where they can …
Hpe Network Virtualization
Mitigation only
MEDIUM 6.5
CVE-2022-34805
Jenkins Skype notifier Plugin 1.1.0 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can…
Skype Notifier
after 1.1.0
MEDIUM 6.5
CVE-2022-34806
Jenkins Jigomerge Plugin 0.9 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by u…
Jigomerge
after 0.9
MEDIUM 6.5
CVE-2022-34807
Jenkins Elasticsearch Query Plugin 1.2 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it …
Elasticsearch Query
after 1.2
MEDIUM 6.5
CVE-2022-34809
Jenkins RQM Plugin 2.8 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by…
Rqm
after 2.8
CRITICAL 9.8
CVE-2022-31887
Marval MSM v14.19.0.12476 has a 0-Click Account Takeover vulnerability which allows an attacker to change any user's password in the organization, th…
Marval Msm
No fix yet
MEDIUM 6.1
CVE-2022-31085
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior t…
Debian Linux
8.0+
MEDIUM 6.5
CVE-2022-2221
Information Exposure vulnerability in My Account Settings of Devolutions Remote Desktop Manager before 2022.1.8 allows authenticated users to access …
Remote Desktop Manager
2022.1.8+
MEDIUM 6.5
CVE-2022-28167
Brocade SANnav before Brocade SANvav v. 2.2.0.2 and Brocade SANanv v.2.1.1.8 logs the Brocade Fabric OS switch password in plain text in asyncjobsche…
Sannav
2.1.1.8 / 2.2.0.2+
CRITICAL 9.1
CVE-2022-2103
An attacker with weak credentials could access the TCP port via an open FTP port, allowing an attacker to read sensitive files and write to remotely …
Sepcos Control And Protection Relay Firmware
1.23.21 / 1.24.8+
MEDIUM 6.5
CVE-2022-1666
The default password for the web application’s root user (the vendor’s private account) was weak and the MD5 hash was used to crack the password usin…
Sepcos Control And Protection Relay Firmware
1.23.21 / 1.24.8+
MEDIUM 6.5
CVE-2022-34213
Jenkins Squash TM Publisher (Squash4Jenkins) Plugin 1.0.0 and earlier stores passwords unencrypted in its global configuration file on the Jenkins co…
Squash Tm Publisher
after 1.0.0
MEDIUM 6.5
CVE-2022-34199
Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they c…
Convertigo Mobile Platform
after 1.1
MEDIUM 6.5
CVE-2022-34202
Jenkins EasyQA Plugin 1.0 and earlier stores user passwords unencrypted in its global configuration file on the Jenkins controller where they can be …
Easyqa
after 1.0
MEDIUM 5.9
CVE-2022-21184
An information disclosure vulnerability exists in the License registration functionality of Bachmann Visutec GmbH Atvise 3.5.4, 3.6 and 3.7. A plaint…
Atvise
Mitigation only