Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2020-29054
An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B,…
72408a Firmware
No fix yet
MEDIUM 6.5
CVE-2020-28330
Barco wePresent WiPG-1600W devices have Unprotected Transport of Credentials. Affected Version(s): 2.5.1.8. An attacker armed with hardcoded API cred…
Wepresent Wipg 1600w Firmware
No fix yet
HIGH 7.5
CVE-2020-24227
Playground Sessions v2.5.582 (and earlier) for Windows, stores the user credentials in plain text allowing anyone with access to UserProfiles.sol to …
Playground Sessions
after 2.5.582
HIGH 7.5
CVE-2020-27554
Cleartext Transmission of Sensitive Information vulnerability in BASETech GE-131 BT-1837836 firmware 20180921 exists which could leak sensitive infor…
Ge 131 Bt 1837836 Firmware
No fix yet
MEDIUM 5.5
CVE-2020-27557
Unprotected Storage of Credentials vulnerability in BASETech GE-131 BT-1837836 firmware 20180921 allows local users to gain access to the video strea…
Ge 131 Bt 1837836 Firmware
No fix yet
CRITICAL 9.8
CVE-2020-26508
The WebTools component on Canon Oce ColorWave 3500 5.1.1.0 devices allows attackers to retrieve stored SMB credentials via the export feature, even t…
Oce Colorwave 3500 Firmware
Mitigation only
HIGH 8.1
CVE-2020-8259
Insufficient protection of the server-side encryption keys in Nextcloud Server 19.0.1 allowed an attacker to replace the encryption keys.
Nextcloud Server
20.0.0+
HIGH 7.8
CVE-2020-12333
Insufficiently protected credentials in the Intel(R) QAT for Linux before version 1.7.l.4.10.0 may allow an authenticated user to potentially enable …
Quickassist Technology
1.7.l.4.10.0+
MEDIUM 5.5
CVE-2020-12316
Insufficiently protected credentials in the Intel(R) EMA before version 1.3.3 may allow an authorized user to potentially enable information disclosu…
Endpoint Management Assistant
1.3.3+
MEDIUM 5.5
CVE-2020-4568
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, and 4.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID…
Security Key Lifecycle Manager
Patch available
HIGH 7.5
CVE-2020-27688
RVToolsPasswordEncryption.exe in RVTools 4.0.6 allows users to encrypt passwords to be used in the configuration files. This encryption used a static…
Rvtools
Mitigation only
MEDIUM 5.5
CVE-2020-2314
Jenkins AppSpider Plugin 1.0.12 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be …
Appspider
after 1.0.12
MEDIUM 6.5
CVE-2020-2318
Jenkins Mail Commander Plugin for Jenkins-ci Plugin 1.0.0 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller …
Mail Commander
after 1.0.0
MEDIUM 6.5
CVE-2020-2319
Jenkins VMware Lab Manager Slaves Plugin 0.2.8 and earlier stores a password unencrypted in the global config.xml file on the Jenkins controller wher…
Vmware Lab Manager Slaves
after 0.2.8
HIGH 7.5
CVE-2020-8183
A logic error in Nextcloud Server 19.0.0 caused a plaintext storage of the share password when it was given on the initial create API call.
Nextcloud Server
18.0.6 / 19.0.1+
HIGH 7.5
CVE-2020-27888
An issue was discovered on Ubiquiti UniFi Meshing Access Point UAP-AC-M 4.3.21.11325 and UniFi Controller 6.0.28 devices. Cached credentials are not …
Unifi Meshing Access Point Firmware
Mitigation only
MEDIUM 6.5
CVE-2020-7196
The HPE BlueData EPIC Software Platform version 4.0 and HPE Ezmeral Container Platform 5.0 use an insecure method of handling sensitive Kerberos pass…
Bluedata Epic
after 4.0
MEDIUM 6.5
CVE-2020-1688
On Juniper Networks SRX Series and NFX Series, a local authenticated user with access to the shell may obtain the Web API service private key that is…
Junos
Mitigation only
MEDIUM 6.3
CVE-2020-1669
The Juniper Device Manager (JDM) container, used by the disaggregated Junos OS architecture on Juniper Networks NFX350 Series devices, stores passwor…
Junos
Mitigation only
MEDIUM 6.1
CVE-2020-15157
In containerd (an industry-standard container runtime) before version 1.2.14 there is a credential leaking vulnerability. If a container image manife…
Ubuntu Linux
1.2.14+
MEDIUM 6.3
CVE-2020-3483
Duo has identified and fixed an issue with the Duo Network Gateway (DNG) product in which some customer-provided SSL certificates and private keys we…
Duo Network Gateway
after 1.5.7
HIGH 7.5
CVE-2018-20243
The implementation of POST with the username and password in the URL parameters exposed the credentials. More infomration is available in fineract ji…
Fineract
after 1.3.0
HIGH 7.5
CVE-2020-26149
NATS nats.js before 2.0.0-209, nats.ws before 1.0.0-111, and nats.deno before 1.0.0-9 allow credential disclosure from a client to a server.
Nats.deno
1.0.0-9 / 1.0.0-111+
CRITICAL 9.8
CVE-2019-16211
Brocade SANnav versions before v2.1.0, contain a Plaintext Password Storage vulnerability.
Brocade Sannav
2.1.0+
MEDIUM 5.5
CVE-2020-7945
Local registry credentials were included directly in the CD4PE deployment definition, which could expose these credentials to users who should not ha…
Continuous Delivery
Mitigation only
MEDIUM 6.1
CVE-2020-8339
A cross-site scripting inclusion (XSSI) vulnerability was reported in the legacy IBM BladeCenter Advanced Management Module (AMM) web interface prior…
Bladecenter Advanced Management Module Firmware
3.68n+
MEDIUM 6.5
CVE-2020-15791
A vulnerability has been identified in SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions), SIMATIC S7-400 CPU fa…
Simatic S7 300 Cpu 312 Firmware
Mitigation only
MEDIUM 6.5
CVE-2020-3547
A vulnerability in the web-based management interface of Cisco AsyncOS software for Cisco Email Security Appliance (ESA), Cisco Content Security Mana…
Asyncos
after 13.6.1-193
CRITICAL 9.1
CVE-2020-6874
A ZTE product is impacted by the cryptographic issues vulnerability. The encryption algorithm is not properly used, so remote attackers could use thi…
Zxiptv Firmware
Mitigation only
MEDIUM 6.5
CVE-2019-4697
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 stores user credentials in plain in clear text which can be read by an authenticated user. IBM X-…
Guardium Data Encryption
1.7.0+