Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2020-2133
Jenkins Applatix Plugin 1.1 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users w…
Applatix
after 1.1
MEDIUM 5.3
CVE-2020-2119
Jenkins Azure AD Plugin 1.1.2 and earlier transmits configured credentials in plain text as part of the global Jenkins configuration form, potentiall…
Azure Ad
after 1.1.2
HIGH 7.5
CVE-2020-2114
Jenkins S3 publisher Plugin 0.11.4 and earlier transmits configured credentials in plain text as part of the global Jenkins configuration form, poten…
S3 Publisher
after 0.11.4
CRITICAL 9.8
CVE-2020-6969
It is possible to unmask credentials and other sensitive information on “unprotected” project files, which may allow an attacker to remotely access t…
C More Ea9 Rhi Firmware
6.53+
CRITICAL 9.8
CVE-2013-7055EPSS 7%
D-Link DIR-100 4.03B07 has PPTP and poe information disclosure
Dir 100 Firmware
No fix yet
CRITICAL 9.8
CVE-2013-7052EPSS 25%
D-Link DIR-100 4.03B07: security bypass via an error in the cliget.cgi script
Dir 100 Firmware
No fix yet
HIGH 7.5
CVE-2013-2672
Brother MFC-9970CDW devices with firmware 0D allow cleartext submission of passwords.
Mfc 9970cdw Firmware
No fix yet
MEDIUM 5.5
CVE-2019-19119
An issue was discovered in PRTG 7.x through 19.4.53. Due to insufficient access control on local registry keys for the Core Server Service, a non-adm…
Prtg Network Monitor
after 19.4.53.
MEDIUM 6.8
CVE-2013-5113
LastPass prior to 2.5.1 has an insecure PIN implementation.
Lastpass
2.5.1+
HIGH 7.5
CVE-2020-7909
In JetBrains TeamCity before 2019.1.5, some server-stored passwords could be shown via the web UI.
Teamcity
2019.1.5+
HIGH 7.5
CVE-2014-2581
Smb4K before 1.1.1 allows remote attackers to obtain credentials via vectors related to the cuid option in the "Additional options" line edit.
Fedora
1.1.1+
CRITICAL 9.8
CVE-2014-3445EPSS 5%
backup.php in HandsomeWeb SOS Webpages before 1.1.12 does not require knowledge of the cleartext password, which allows remote attackers to bypass au…
Sos Webpages
1.1.12+
MEDIUM 5.5
CVE-2019-19539
An issue was discovered in Idelji Web ViewPoint H01ABO-H01BY and L01ABP-L01ABZ, Web ViewPoint Plus H01AAG-H01AAQ and L01AAH-L01AAR, and Web ViewPoint…
Web Viewpoint T0320
Mitigation only
HIGH 7.5
CVE-2019-19823EPSS 6%
A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords in flash …
A3002ru Firmware
after 2019-12-12
CRITICAL 10.0
CVE-2020-6961
In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X,…
Apexpro Telemetry Server Firmware
after 4.2
HIGH 7.5
CVE-2012-6663EPSS 9%
General Electric D20ME devices are not properly configured and reveal plaintext passwords.
D20me Firmware
No fix yet
HIGH 7.5
CVE-2019-19898
In IXP EasyInstall 6.2.13723, there are cleartext credentials in network communication on TCP port 20050 when using the Administrator console remotel…
Easyinstall
No fix yet
CRITICAL 9.8
CVE-2019-19843
Incorrect access control in the web interface in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote credential fetch via an unauthentica…
Unleashed
9.10.2.0.84 / 9.12.3.0.136+
CRITICAL 9.8
CVE-2020-7233
KMS Controls BAC-A1616BC BACnet devices have a cleartext password of snowman in the BACKDOOR_NAME variable in the BC_Logon.swf file.
Bac A1616bc Firmware
No fix yet
MEDIUM 5.5
CVE-2019-19696
A RootCA vulnerability found in Trend Micro Password Manager for Windows and macOS exists where the localhost.key of RootCA.crt might be improperly a…
Password Manager
after 5.0.1047
HIGH 7.5
CVE-2019-12423EPSS 6%
Apache CXF ships with a OpenId Connect JWK Keys service, which allows a client to obtain the public keys in JWK format, which can then be used to ver…
Cxf
3.2.12 / 3.3.5+
CRITICAL 9.8
CVE-2014-5381EPSS 7%
Grand MA 300 allows a brute-force attack on the PIN.
Grand Ma300 Firmware
No fix yet
HIGH 7.5
CVE-2014-6039EPSS 69%
ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability. Fixed version 10 Build 10000.
Manageengine Eventlog Analyzer
after 9.9
HIGH 7.5
CVE-2012-3823
Arial Campaign Enterprise before 11.0.551 stores passwords in clear text and these may be retrieved.
Campaign Enterprise
11.0.551+
HIGH 7.8
CVE-2019-4508
IBM QRadar SIEM 7.3.0 through 7.3.3 uses weak credential storage in some instances which could be decrypted by a local attacker. IBM X-Force ID: 1644…
Qradar Security Information And Event Manager
after 7.3.3
CRITICAL 9.8
CVE-2014-5093
Status2k does not remove the install directory allowing credential reset.
Status2k
No fix yet
MEDIUM 6.5
CVE-2019-6700
An information exposure vulnerability in the external authentication profile form of FortiSIEM 5.2.2 and earlier may allow an authenticated attacker …
Fortisiem
5.2.5+
HIGH 7.5
CVE-2019-5990
Access analysis CGI An-Analyzer released in 2019 June 24 and earlier allow remote attackers to obtain a login password via HTTP referer.
Cgi An Anlyzer
after 2019-06-24
HIGH 7.5
CVE-2013-3620
Hardcoded WSMan credentials in Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before 3.15 (…
Netscaler Sdx Firmware
3.12 / 3.15+
MEDIUM 6.3
CVE-2019-10205
A flaw was found in the way Red Hat Quay stores robot account tokens in plain text. An attacker able to perform database queries in the Red Hat Quay …
Quay
Mitigation only