Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2022-0738
An issue has been discovered in GitLab affecting all versions starting from 14.6 before 14.6.5, all versions starting from 14.7 before 14.7.4, all ve…
GitLab
14.6.5 / 14.7.4+
MEDIUM 6.7
CVE-2022-0859
McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a local attacker to point an ePO server to an arbitrary SQL server during…
Epolicy Orchestrator
5.10.0+
MEDIUM 5.3
CVE-2022-0862
A lack of password change protection vulnerability in a depreciated API of McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allow…
Epolicy Orchestrator
5.10.0+
MEDIUM 5.5
CVE-2020-25184
Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x stores the password in plaintext in a file that is in the same directory as the executable f…
Epas Gtw Firmware
1.1.0+
MEDIUM 6.5
CVE-2022-27216
Jenkins dbCharts Plugin 0.5.2 and earlier stores JDBC connection passwords unencrypted in its global configuration file on the Jenkins controller whe…
Dbcharts
after 0.5.2
MEDIUM 6.5
CVE-2022-27217
Jenkins Vmware vRealize CodeStream Plugin 1.2 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they c…
Vmware Vrealize Codestream
after 1.2
MEDIUM 6.5
CVE-2022-27206
Jenkins GitLab Authentication Plugin 1.13 and earlier stores the GitLab client secret unencrypted in the global config.xml file on the Jenkins contro…
Gitlab Authentication
after 1.13
MEDIUM 5.9
CVE-2021-23222
A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryp…
PostgreSQL
9.6.24 / 10.19+
MEDIUM 5.5
CVE-2022-22908
SangforCSClient.exe in Sangfor VDI Client 5.4.2.1006 allows attackers, when they are able to read process memory, to discover the contents of the Use…
Vdi Client
No fix yet
HIGH 8.6
CVE-2022-24610
Settings/network settings/wireless settings on the Alecto DVC-215IP camera version 63.1.1.173 and below shows the Wi-Fi passphrase hidden, but by edi…
Dvc 215ip Firmware
63.1.1.173+
MEDIUM 6.5
CVE-2022-24982
Forms generated by JQueryForm.com before 2022-02-05 allows a remote authenticated attacker to access the cleartext credentials of all other form user…
Jqueryform
2022-02-05+
MEDIUM 6.5
CVE-2022-25184
Jenkins Pipeline: Build Step Plugin 2.15 and earlier reveals password parameter default values when generating a pipeline script using the Pipeline S…
Pipeline\
after 2.15
HIGH 7.5
CVE-2021-22798
A CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause Sensitive data such as login credentials being exposed when a N…
Conext Combox Firmware
Mitigation only
MEDIUM 5.5
CVE-2022-0019
An insufficiently protected credentials vulnerability exists in the Palo Alto Networks GlobalProtect app on Linux that exposes the hashed credentials…
Globalprotect
5.1.10 / 5.3.2+
HIGH 8.8
CVE-2021-40360
A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions), SIMATIC PCS 7 V9.1 (All versions < V9.1 …
Simatic Pcs 7
7.4+
MEDIUM 6.5
CVE-2021-44451EPSS 8%
Apache Superset up to and including 1.3.2 allowed for registered database connections password leak for authenticated users. This information could b…
Superset
after 1.3.2
HIGH 7.5
CVE-2022-23223
On Apache ShenYu versions 2.4.0 and 2.4.1, and endpoint existed that disclosed the passwords of all users. Users are recommended to upgrade to versio…
Shenyu
Patch available
MEDIUM 5.5
CVE-2022-22554
Dell EMC System Update, version 1.9.2 and prior, contain an Unprotected Storage of Credentials vulnerability. A local attacker with user privleges co…
Emc System Update
after 1.9.2.0
CRITICAL 9.8
CVE-2021-23196
The web application on Agilia Link+ version 3.0 implements authentication and session management mechanisms exclusively on the client-side and does n…
Agilia Connect Firmware
3.0+
MEDIUM 5.5
CVE-2021-23207
An attacker with physical access to the host can extract the secrets from the registry and create valid JWT tokens for the Fresenius Kabi Vigilant Ma…
Agilia Connect
3.0+
MEDIUM 5.5
CVE-2021-32039
Users with appropriate file access may be able to access unencrypted user credentials saved by MongoDB Extension for VS Code in a binary file. These …
MongoDB
after 0.7.0
MEDIUM 5.5
CVE-2022-20621
Jenkins Metrics Plugin 4.0.2.8 and earlier stores an access key unencrypted in its global configuration file on the Jenkins controller where it can b…
Metrics
after 4.0.2.8
MEDIUM 6.5
CVE-2022-23109
Jenkins HashiCorp Vault Plugin 3.7.0 and earlier does not mask Vault credentials in Pipeline build logs or in Pipeline step descriptions when Pipelin…
Hashicorp Vault
after 3.7.0
HIGH 7.5
CVE-2022-23117
Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent processes to retrieve all userna…
Conjur Secrets
after 1.0.9
CRITICAL 9.8
CVE-2021-37400
An attacker may obtain the user credentials from the communication between the PLC and the software. As a result, the PLC user program may be uploade…
Data File Manager
after 8.19.1
CRITICAL 9.8
CVE-2021-37401
An attacker may obtain the user credentials from file servers, backup repositories, or ZLD files saved in SD cards. As a result, the PLC user program…
Data File Manager
after 8.19.1
HIGH 7.6
CVE-2021-20826
Unprotected transport of credentials vulnerability in IDEC PLCs (FC6A Series MICROSmart All-in-One CPU module v2.32 and earlier, FC6A Series MICROSma…
Microsmart Fc6a Firmware
after 8.19.1
MEDIUM 6.7
CVE-2021-36317
Dell EMC Avamar Server version 19.4 contains a plain-text password storage vulnerability in AvInstaller. A local attacker could potentially exploit t…
Emc Avamar Server
Patch available
MEDIUM 6.7
CVE-2021-36318
Dell EMC Avamar versions 18.2,19.1,19.2,19.3,19.4 contain a plain-text password storage vulnerability. A high privileged user could potentially explo…
Emc Avamar Server
Patch available
HIGH 7.5
CVE-2021-42913
The SyncThru Web Service on Samsung SCX-6x55X printers allows an attacker to gain access to a list of SMB users and cleartext passwords by reading th…
Syncthru Web Service
Mitigation only