Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2019-13054
The Logitech R500 presentation clicker allows attackers to determine the AES key, leading to keystroke injection. On Windows, any text may be injecte…
R500 Firmware
No fix yet
HIGH 7.3
CVE-2019-11272
Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPasswordEncoder. If an appli…
Spring Security
4.2.13+
MEDIUM 6.5
CVE-2019-4385
IBM Spectrum Protect Plus 10.1.2 may display the vSnap CIFS password in the IBM Spectrum Protect Plus Joblog. This can result in an attacker gaining …
Spectrum Protect Plus
after 10.1.2.303
HIGH 7.8
CVE-2019-11271
Cloud Foundry BOSH 270.x versions prior to v270.1.1, contain a BOSH Director that does not properly redact credentials when configured to use a MySQL…
Bosh
270.1.1+
MEDIUM 5.5
CVE-2019-4239
IBM MQ Advanced Cloud Pak (IBM Cloud Private 1.0.0 through 3.0.1) stores user credentials in plain in clear text which can be read by a local user. I…
Cloud Private
after 3.0.1
CRITICAL 9.8
CVE-2019-3947
Fuji Electric V-Server before 6.0.33.0 stores database credentials in project files as plaintext. An attacker that can gain access to the project fil…
V Server
6.0.33.0+
MEDIUM 5.5
CVE-2019-6567
A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All Versions < V5.2.4), SCALANCE X-200IRT switch fam…
Scalance X 200 Firmware
5.2.4+
CRITICAL 9.8
CVE-2019-10160EPSS 5%
A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.…
Python
2.7.17 / 3.5.8+
HIGH 8.8
CVE-2019-6452
Kyocera Command Center RX TASKalfa4501i and TASKalfa5052ci allows remote attackers to abuse the Test button in the machine address book to obtain a c…
Command Center Rx
No fix yet
CRITICAL 9.8
CVE-2019-11367
An issue was discovered in AUO Solar Data Recorder before 1.3.0. The web portal uses HTTP Basic Authentication and provides the account and password …
Solar Data Recorder
1.3.0+
HIGH 8.8
CVE-2019-11369EPSS 8%
An issue was discovered in Carel pCOWeb prior to B1.2.4. In /config/pw_changeusers.html the device stores cleartext passwords, which may allow sensit…
Pcoweb Card Firmware
No fix yet
HIGH 7.8
CVE-2019-10981
In Vijeo Citect 7.30 and 7.40, and CitectSCADA 7.30 and 7.40, a vulnerability has been identified that may allow an authenticated local user access t…
Citectscada
Patch available
HIGH 8.8
CVE-2019-10329
Jenkins InfluxDB Plugin 1.21 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they can be view…
Influxdb
after 1.21
HIGH 7.5
CVE-2019-12452
types/types.go in Containous Traefik 1.7.x through 1.7.11, when the --api flag is used and the API is publicly reachable and exposed without sufficie…
Traefik
after 1.7.11
MEDIUM 5.9
CVE-2019-4138
IBM Tivoli Storage Productivity Center 5.2.13 through 5.3.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to…
Spectrum Control
after 5.3.2.0
HIGH 7.1
CVE-2019-5625
The Android mobile application Halo Home before 1.11.0 stores OAuth authentication and refresh access tokens in a clear text file. This file persists…
Halo Home
No fix yet
HIGH 7.8
CVE-2019-5626
The Android mobile application BlueCats Reveal before 3.0.19 stores the username and password in a clear text file. This file persists until the user…
Bluecats Reveal
3.0.19+
HIGH 7.8
CVE-2019-5627
The iOS mobile application BlueCats Reveal before 5.14 stores the username and password in the app cache as base64 encoded strings, i.e. clear text. …
Bc Reveal
5.14+
CRITICAL 9.8
CVE-2019-12046
LemonLDAP::NG -2.0.3 has Incorrect Access Control.
Debian Linux
No fix yet
HIGH 7.8
CVE-2019-10139
During HE deployment via cockpit-ovirt, cockpit-ovirt generates an ansible variable file `/var/lib/ovirt-hosted-engine-setup/cockpit/ansibleVarFileXX…
Cockpit Ovirt
Mitigation only
HIGH 7.8
CVE-2019-0881
An elevation of privilege vulnerability exists when the Windows Kernel improperly handles key enumeration, aka 'Windows Kernel Elevation of Privilege…
Windows 10
Patch available
HIGH 7.5
CVE-2019-10921
A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Unencrypted storage of passwords in the project coul…
Logo\!8 Bm Firmware
8.3+
MEDIUM 6.8
CVE-2019-8350
The Simple - Better Banking application 2.45.0 through 2.45.3 (fixed in 2.46.0) for Android was affected by an information disclosure vulnerability t…
Better Banking
after 2.45.3
MEDIUM 6.8
CVE-2019-11885
eyeDisk implements the unlock feature by sending a cleartext password. The password can be discovered by sniffing USB traffic or by sending a 06 05 5…
Eyedisk
No fix yet
MEDIUM 5.5
CVE-2019-11820
Information exposure through process environment vulnerability in Synology Calendar before 2.3.3-0620 allows local users to obtain credentials via cm…
Calendar
2.3.3-0620+
HIGH 7.8
CVE-2019-3938
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 stores usernames, passwords, and other configuration options in the file gener…
Am 100 Firmware
No fix yet
HIGH 8.8
CVE-2019-10313
Jenkins Twitter Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with a…
Twitter
after 0.7
HIGH 8.8
CVE-2019-10316
Jenkins Aqua MicroScanner Plugin 1.0.5 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they c…
Aqua Microscanner
after 1.0.5
HIGH 8.8
CVE-2019-10318
Jenkins Azure AD Plugin 0.3.3 and earlier stored the client secret unencrypted in the global config.xml configuration file on the Jenkins master wher…
Azure Ad
after 0.3.3
HIGH 7.8
CVE-2019-10239
Robotronic RunAsSpc 3.7.0.0 protects stored credentials insufficiently, which allows locally authenticated attackers (under the same user context) to…
Runasspc
No fix yet