Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.3
CVE-2018-21239
An issue was discovered in Foxit Reader and PhantomPDF before 9.2. It allows NTLM credential theft via a GoToE or GoToR action.
Phantompdf
9.2+
MEDIUM 5.5
CVE-2020-7030
A sensitive information disclosure vulnerability was discovered in the web interface component of IP Office that may potentially allow a local user t…
Ip Office
after 11.0.4.2
MEDIUM 6.5
CVE-2020-2198
Jenkins Project Inheritance Plugin 19.08.02 and earlier does not redact encrypted secrets in the 'getConfigAsXML' API URL when transmitting job confi…
Project Inheritance
after 19.08.02
HIGH 7.8
CVE-2014-8938
Lexiglot through 2014-11-20 allows local users to obtain sensitive information by listing a process because the username and password are on the comm…
Lexiglot
after 2014-11-20
HIGH 7.5
CVE-2014-9702
system/classes/DbPDO.php in Cmfive through 2015-03-15, when database connectivity malfunctions, allows remote attackers to obtain sensitive informati…
Cmfive
after 2015-03-15
MEDIUM 6.5
CVE-2019-13023
An issue was discovered in all versions of Bond JetSelect. Within the JetSelect Application, the web interface hides RADIUS secrets, WPA passwords, a…
Jetselect
Mitigation only
MEDIUM 5.5
CVE-2014-1423
signond before 8.57+15.04.20141127.1-0ubuntu1, as used in Ubuntu Touch, did not properly restrict applications from querying oath tokens due to incor…
Signond
8.57+
HIGH 7.5
CVE-2020-10972
An issue was discovered where a page is exposed that has the current administrator password in cleartext in the source code of the page. No authentic…
Wn530hg4 Firmware
Mitigation only
CRITICAL 9.8
CVE-2019-18868
Blaauw Remote Kiln Control through v3.00r4 allows an unauthenticated attacker to access MySQL credentials in cleartext in /engine/db.inc, /lang/nl.ba…
Remote Kiln Control
after 3.0.0
MEDIUM 6.5
CVE-2020-2181
Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets in the build log when the build contains no …
Credentials Binding
after 1.22
HIGH 7.5
CVE-2019-19218
BMC Control-M/Agent 7.0.00.000 has Insecure Password Storage.
Control M\/agent
Mitigation only
MEDIUM 5.3
CVE-2020-11821
In Rukovoditel 2.5.2, users' passwords and usernames are stored in a cookie with URL encoding, base64 encoding, and hashing. Thus, an attacker can ea…
Rukovoditel
No fix yet
HIGH 7.5
CVE-2020-12273
In TestLink 1.9.20, a crafted login.php viewer parameter exposes cleartext credentials.
Testlink
Patch available
MEDIUM 5.5
CVE-2019-4668
IBM UrbanCode Deploy (UCD) 7.0.4.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 171250.
Urbancode Deploy
7.0.4.0+
MEDIUM 5.5
CVE-2019-19105
The backup function in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway saves the current settings and configuration of the ap…
Tg\/s3.2 Firmware
Mitigation only
HIGH 7.8
CVE-2017-18777
Certain NETGEAR devices are affected by administrative password disclosure. This affects D6220 before V1.0.0.28, D6400 before V1.0.0.60, D8500 before…
D6220 Firmware
1.0.0.28 / 1.0.0.60+
HIGH 7.5
CVE-2020-11008
Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. This b…
Git
2.17.5 / 2.18.4+
HIGH 7.8
CVE-2017-18843
Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects R6700v2 before 1.1.0.38, R6800 before 1.1.0.38, and D7…
R6700 Firmware
1.0.1.50 / 1.1.0.38+
HIGH 7.8
CVE-2017-18844
Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects R6700v2 before 1.1.0.38, R6800 before 1.1.0.38, and D7…
R6700 Firmware
1.0.1.50 / 1.1.0.38+
HIGH 7.8
CVE-2017-18845
Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects R6700v2 before 1.1.0.38 and R6800 before 1.1.0.38.
R6700 Firmware
1.1.0.38+
HIGH 8.8
CVE-2020-9523
Insufficiently protected credentials vulnerability on Micro Focus enterprise developer and enterprise server, affecting all version prior to 4.0 Patc…
Enterprise Developer
after 3.0
MEDIUM 5.5
CVE-2020-5721
MikroTik WinBox 3.22 and below stores the user's cleartext password in the settings.cfg.viw configuration file when the Keep Password field is set an…
Winbox
after 3.22
HIGH 7.5
CVE-2020-5260EPSS 10%
Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. Git us…
Git
2.17.4 / 2.18.3+
CRITICAL 9.8
CVE-2020-6195
SAP Business Objects Business Intelligence Platform (CMC), version 4.1, 4.2, shows cleartext password in the response, leading to Information Disclos…
Businessobjects Business Intelligence Platform
Mitigation only
HIGH 7.5
CVE-2020-11694
In JetBrains PyCharm 2019.2.5 and 2019.3 on Windows, Apple Notarization Service credentials were included. This is fixed in 2019.2.6 and 2019.3.3.
Pycharm
No fix yet
MEDIUM 6.5
CVE-2020-5406
VMware Tanzu Application Service for VMs, 2.6.x versions prior to 2.6.18, 2.7.x versions prior to 2.7.11, and 2.8.x versions prior to 2.8.5, includes…
Tanzu Application Service For Vms
2.6.18 / 2.7.11+
HIGH 7.5
CVE-2020-11555
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It allows remote attackers to obtain sensitive credential information…
Snmpc Online
2020-01-28+
HIGH 7.5
CVE-2020-11557
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It includes the username and password values in cleartext within each…
Snmpc Online
2020-01-28+
HIGH 7.2
CVE-2020-11629
An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. The External Command Certificate Validator, which allows administrators to u…
Ejbca
6.15.2.6 / 7.3.1.2+
HIGH 7.8
CVE-2020-11560
NCH Express Invoice 7.25 allows local users to discover the cleartext password by reading the configuration file.
Express Invoice
No fix yet