Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2018-7820
A Credentials Management CWE-255 vulnerability exists in the APC UPS Network Management Card 2 AOS v6.5.6, which could cause Remote Monitoring Creden…
Ap9630 Firmware
6.7.2+
MEDIUM 5.5
CVE-2019-10398
Jenkins Beaker Builder Plugin 1.9 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could …
Beaker Builder
after 1.9
HIGH 7.8
CVE-2019-11769
An issue was discovered in TeamViewer 14.2.2558. Updating the product as a non-administrative user requires entering administrative credentials into …
Teamviewer
Mitigation only
HIGH 8.8
CVE-2019-13348
In Knowage through 6.1.1, an authenticated user who accesses the datasources page will gain access to any data source credentials in cleartext, which…
Knowage
6.4+
HIGH 7.5
CVE-2019-10960
Zebra Industrial Printers All Versions, Zebra printers are shipped with unrestricted end-user access to front panel options. If the option to use a p…
Zt610 Firmware
Mitigation only
MEDIUM 6.5
CVE-2019-3753
Dell EMC PowerConnect 8024, 7000, M6348, M6220, M8024 and M8024-K running firmware versions prior to 5.1.15.2 contain a plain-text password storage v…
Emc Powerconnect 8024 Firmware
5.1.15.2+
CRITICAL 9.8
CVE-2019-15052
The HTTP client in Gradle before 5.6 sends authentication credentials originally destined for the configured host. If that host returns a 30x redirec…
Gradle
5.6+
MEDIUM 5.3
CVE-2019-10378
Jenkins TestLink Plugin 3.16 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be view…
Testlink
after 3.16
MEDIUM 6.5
CVE-2019-10379
Jenkins Google Cloud Messaging Notification Plugin 1.0 and earlier stores credentials unencrypted in its global configuration file on the Jenkins mas…
Cloud Messaging Notification
after 1.0
MEDIUM 6.5
CVE-2019-10385
Jenkins eggPlant Plugin 2.2 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by user…
Eggplant
after 2.2
CRITICAL 9.8
CVE-2019-14709
A cleartext password storage issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. The file in question is /usr/loc…
Mdc N4090 Firmware
after 6400.0.8.5
HIGH 7.8
CVE-2019-3800
CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --c…
Elasticsearch
1.16.0 / 2.1.2+
MEDIUM 6.5
CVE-2019-10366
Jenkins Skytap Cloud CI Plugin 2.06 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be view…
Skytap Cloud Ci
after 2.06
MEDIUM 5.5
CVE-2019-10345
Jenkins Configuration as Code Plugin 1.20 and earlier did not treat the proxy password as a secret to be masked when logging or encrypted for export.
Configuration As Code
1.20+
MEDIUM 5.5
CVE-2019-10361
Jenkins Maven Release Plugin 0.14.0 and earlier stored credentials unencrypted on the Jenkins master where they could be viewed by users with access …
M2release
after 0.14.0
HIGH 7.5
CVE-2019-1020009
Fleet before 2.1.2 allows exposure of SMTP credentials.
Fleet
after 2.1.1
MEDIUM 6.5
CVE-2019-1010241
Jenkins Credentials Binding Plugin Jenkins 1.17 is affected by: CWE-257: Storing Passwords in a Recoverable Format. The impact is: Authenticated user…
Credentials Binding
No fix yet
HIGH 7.5
CVE-2019-8932
Redbrick Shift through 3.4.3 allows an attacker to extract authentication tokens of services (such as Gmail, Outlook, etc.) used in the application.
Shift
after 3.4.3
CRITICAL 9.8
CVE-2019-1010308
Aquaverde GmbH Aquarius CMS prior to version 4.1.1 is affected by: Incorrect Access Control. The impact is: The access to the log file is not restric…
Aquarius Cms
4.1.1+
HIGH 7.8
CVE-2019-9657
Alarm.com ADC-V522IR 0100b9 devices have Incorrect Access Control, a different issue than CVE-2018-19588. This occurs because of incorrect protection…
Adc V522ir Firmware
No fix yet
HIGH 8.8
CVE-2019-10347
Jenkins Mashup Portlets Plugin stored credentials unencrypted on the Jenkins master where they can be viewed by users with access to the master file …
Mashup Portlets
after 1.0.9
HIGH 7.8
CVE-2019-12171
Dropbox.exe (and QtWebEngineProcess.exe in the Web Helper) in the Dropbox desktop application 71.4.108.0 store cleartext credentials in memory upon s…
Dropbox
No fix yet
CRITICAL 9.8
CVE-2019-13400
Dynacolor FCM-MB40 v1.2.0.0 use /etc/appWeb/appweb.pass to store administrative web-interface credentials in cleartext. These credentials can be retr…
Fcm Mb40 Firmware
No fix yet
CRITICAL 9.8
CVE-2019-9823
In several JetBrains IntelliJ IDEA versions, creating remote run configurations of JavaEE application servers leads to saving a cleartext record of t…
Intellij Idea
2018.1.8 / 2018.2.8+
HIGH 8.1
CVE-2019-9872
In several versions of JetBrains IntelliJ IDEA Ultimate, creating run configurations for cloud application servers leads to saving a cleartext unencr…
Intellij Idea
2018.1.8 / 2018.2.8+
CRITICAL 9.8
CVE-2019-9873
In several versions of JetBrains IntelliJ IDEA Ultimate, creating Task Servers configurations leads to saving a cleartext unencrypted record of the s…
Intellij Idea
2019.1+
HIGH 7.2
CVE-2019-12847
In JetBrains Hub versions earlier than 2018.4.11298, the audit events for SMTPSettings show a cleartext password to the admin user. It is only releva…
Hub
2018.4.11298+
HIGH 7.5
CVE-2019-13179
Calamares versions 3.1 through 3.2.10 copies a LUKS encryption keyfile from /crypto_keyfile.bin (mode 0600 owned by root) to /boot within a globally …
Calamares
after 3.2.10
CRITICAL 9.8
CVE-2019-7260EPSS 7%
Linear eMerge E3-Series devices have Cleartext Credentials in a Database.
Linear Emerge Essential Firmware
after 1.00-06
CRITICAL 9.8
CVE-2019-7271
Nortek Linear eMerge 50P/5000P devices have Default Credentials.
Linear Emerge 50p Firmware
after 4.6.07