Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2018-8851
Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The dev…
Smartserver 1 Firmware
4.11.007+
MEDIUM 6.7
CVE-2017-5704
Platform sample code firmware included with 4th Gen Intel Core Processor, 5th Gen Intel Core Processor, 6th Gen Intel Core Processor, and 7th Gen Int…
Core I3
Mitigation only
HIGH 7.8
CVE-2018-1000401
Jenkins project Jenkins AWS CodePipeline Plugin version 0.36 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSCodePipe…
Aws Codepipeline
after 0.36
HIGH 7.8
CVE-2018-1000403
Jenkins project Jenkins AWS CodeDeploy Plugin version 1.19 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSCodeDeploy…
Aws Codedeploy
after 1.19
HIGH 7.8
CVE-2018-1000404
Jenkins project Jenkins AWS CodeBuild Plugin version 0.26 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSClientFacto…
Aws Codebuild
after 0.26
HIGH 7.0
CVE-2017-2665
The skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /etc/skyring/skyring.conf file…
MongoDB
Mitigation only
HIGH 7.8
CVE-2018-11634
Plaintext Storage of Passwords in the administrative console in Dialogic PowerMedia XMS before 3.5 SU2 allows local users to access the web applicati…
Powermedia Xms
after 3.5
HIGH 8.1
CVE-2018-11639
Plaintext Storage of Passwords within Cookies in /var/www/xms/application/controllers/verifyLogin.php in the administrative console in Dialogic Power…
Powermedia Xms
after 3.5
HIGH 8.8
CVE-2018-7782
In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, authenticated users can view passwords…
Imps110 1 Firmware
3.29.69+
CRITICAL 9.8
CVE-2018-11746
In Puppet Discovery prior to 1.2.0, when running Discovery against Windows hosts, WinRM connections can fall back to using basic auth over insecure c…
Discovery
1.2.0+
HIGH 7.8
CVE-2018-13014
Storing password in recoverable format in safensec.com (SysWatch service) in SAFE'N'SEC SoftControl/SafenSoft SysWatch, SoftControl/SafenSoft TPSecur…
Enterprise Suite
4.4.2+
MEDIUM 5.9
CVE-2017-16718
Beckhoff TwinCAT 3 supports communication over ADS. ADS is a protocol for industrial automation in protected environments. This protocol uses user co…
Twincat
No fix yet
HIGH 7.2
CVE-2018-1000608
A exposure of sensitive information vulnerability exists in Jenkins z/OS Connector Plugin 1.2.6.1 and earlier in SCLMSCM.java that allows an attacker…
Z\/os Connector
after 1.2.6.1
HIGH 8.8
CVE-2018-1000610
A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in DataBoundConfigurator.java,…
Configuration As Code
Mitigation only
MEDIUM 6.7
CVE-2018-12260
An issue was discovered on Momentum Axel 720P 5.1.8 devices. The root password can be obtained in cleartext by issuing the command 'showKey' from the…
Momentum Axel 720p Firmware
No fix yet
HIGH 7.8
CVE-2018-1075
ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one choo…
Ovirt
4.2.3+
HIGH 8.8
CVE-2018-4190
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is aff…
Safari
7.5 / 11.1.1+
HIGH 7.8
CVE-2018-0335
A vulnerability in the web portal authentication process of Cisco Prime Collaboration Provisioning could allow an unauthenticated, local attacker to …
Prime Collaboration
Mitigation only
CRITICAL 9.8
CVE-2017-7933
In ABB IP GATEWAY 3.39 and prior, some configuration files contain passwords stored in plain-text, which may allow an attacker to gain unauthorized a…
Ip Gateway Firmware
after 3.39
CRITICAL 9.8
CVE-2018-7510
In the web application in BeaconMedaes TotalAlert Scroll Medical Air Systems running software versions prior to 4107600010.23, passwords are presente…
Scroll Medical Air Systems Firmware
4107600010.23+
CRITICAL 9.8
CVE-2018-11544
The Olive Tree Ftp Server application 1.32 for Android has Insecure Data Storage because a username and password are stored in the /data/data/com.the…
Ftp Server
No fix yet
CRITICAL 9.8
CVE-2018-7518
In TotalAlert Web Application in BeaconMedaes Scroll Medical Air Systems prior to v4107600010.23, an attacker with network access to the integrated w…
Scroll Medical Air Systems Firmware
4107600010.23+
HIGH 7.0
CVE-2018-10355
An authentication weakness vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to recover user passwords on vulnerable …
Email Encryption Gateway
after 5.5
HIGH 7.0
CVE-2018-10327
PrinterOn Enterprise 4.1.3 stores the Active Directory bind credentials using base64 encoding, which allows local users to obtain credentials for a d…
Printeron
No fix yet
HIGH 8.8
CVE-2017-12123
An exploitable clear text transmission of password vulnerability exists in the web server and telnet functionality of Moxa EDR-810 V4.1 build 1703031…
Edr 810 Firmware
No fix yet
HIGH 7.8
CVE-2018-6618
Easy Hosting Control Panel (EHCP) v0.37.12.b allows attackers to obtain sensitive information by leveraging cleartext password storage.
Easy Hosting Control Panel
No fix yet
HIGH 7.2
CVE-2018-1074
ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentials, includ…
Enterprise Virtualization
after 4.1.11.1
HIGH 8.8
CVE-2017-9654
The Philips DoseWise Portal web-based application versions 1.1.7.333 and 2.1.1.3069 stores login credentials in clear text within backend system file…
Dosewise
Mitigation only
HIGH 7.0
CVE-2017-1764
IBM Cognos Business Intelligence 10.2, 10.2.1, 10.2.1.1, and 10.2.2, under specialized circumstances, could expose plain text credentials to a local …
Cognos Business Intelligence
No fix yet
HIGH 8.8
CVE-2018-10286EPSS 7%
The Ericsson-LG iPECS NMS A.1Ac web application discloses sensitive information such as the NMS admin credentials and the PostgreSQL database credent…
Ipecs Nms
No fix yet