Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2016-9593
foreman-debug before version 1.15.0 is vulnerable to a flaw in foreman-debug's logging. An attacker with access to the foreman log file would be able…
Satellite
1.15.0+
CRITICAL 9.8
CVE-2018-10024
ubiQuoss Switch VP5208A creates a bcm_password file at /cgi-bin/ with the user credentials in cleartext when a failed login attempt occurs. The file …
Vp5208a Firmware
Mitigation only
HIGH 7.8
CVE-2018-4170
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "Admin Framework" component. It allows lo…
Mac Os X
10.13.4+
CRITICAL 9.8
CVE-2018-9160EPSS 76%
SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.
Sickrage
after 9.2.101
HIGH 8.0
CVE-2018-5708EPSS 6%
An issue was discovered on D-Link DIR-601 B1 2.02NA devices. Being on the same local network as, but being unauthenticated to, the administrator's pa…
Dir 601 Firmware
No fix yet
CRITICAL 9.8
CVE-2018-9031
The login interface on TNLSoftSolutions Sentry Vision 3.x devices provides password disclosure by reading an "if(pwd ==" line in the HTML source code…
Sentry Vision
No fix yet
CRITICAL 9.8
CVE-2017-11510
An information leak exists in Wanscam's HW0021 network camera that allows an unauthenticated remote attacker to recover the administrator username an…
Hw0021 Firmware
No fix yet
HIGH 7.2
CVE-2017-0925
Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration API endpoin…
GitLab
after 10.3.3
HIGH 7.8
CVE-2018-1000104
A plaintext storage of a password vulnerability exists in Jenkins Coverity Plugin 1.10.0 and earlier in CIMInstance.java that allows an attacker with…
Coverity
after 1.10.0
HIGH 8.1
CVE-2018-7698
An issue was discovered in D-Link mydlink+ 3.8.5 build 259 for DCS-933L 1.05.04 and DCS-934L 1.05.04 devices. The mydlink+ app sends the username and…
Mydlink\+
Mitigation only
HIGH 7.5
CVE-2017-5189
NetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel, allowing attackers to extrac…
Imanager
Mitigation only
HIGH 7.8
CVE-2018-1377
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Forc…
Security Guardium Big Data Intelligence
Mitigation only
HIGH 8.1
CVE-2018-3609EPSS 21%
A vulnerability in the Trend Micro InterScan Messaging Security Virtual Appliance 9.0 and 9.1 management portal could allow an unauthenticated user t…
Interscan Messaging Security Virtual Appliance
No fix yet
HIGH 7.8
CVE-2018-0828
Windows 10 version 1607 and Windows Server 2016 allow an elevation of privilege vulnerability due to how the MultiPoint management account password i…
Windows 10
Patch available
MEDIUM 6.7
CVE-2017-9969
An information disclosure vulnerability exists in Schneider Electric's IGSS Mobile application version 3.01 and prior. Passwords are stored in clear …
Igss Mobile
after 3.01
HIGH 8.8
CVE-2017-15656
Password are stored in plaintext in nvram in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt.
Asuswrt
after 3.0.0.4.380.7743
HIGH 7.8
CVE-2017-1779
IBM Cognos Analytics 11.0 could store cached credentials locally that could be obtained by a local user. IBM X-Force ID: 136824.
Cognos Analytics
Patch available
HIGH 7.8
CVE-2017-1000387
Jenkins Build-Publisher plugin version 1.21 and earlier stores credentials to other Jenkins instances in the file hudson.plugins.build_publisher.Buil…
Build Publisher
after 1.21
HIGH 8.8
CVE-2017-16731
An Unprotected Transport of Credentials issue was discovered in ABB Ellipse 8.3 through Ellipse 8.9 released prior to December 2017 (including Ellips…
Ellipse
after 8.9.0
CRITICAL 9.8
CVE-2017-17106EPSS 15%
Credentials for Zivif PR115-204-P-RS V2.3.4.2103 Webcams can be obtained by an unauthenticated remote attacker using a standard web /cgi-bin/hi3510/p…
Pr115 204 P Rs Firmware
No fix yet
CRITICAL 9.8
CVE-2017-3192EPSS 39%
D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 do not sufficiently protect administrator credentials. The tools_admin.asp pag…
Dir 130 Firmware
Mitigation only
HIGH 7.2
CVE-2017-14111
The workstation logging function in Philips IntelliSpace Cardiovascular (ISCV) 2.3.0 and earlier and Xcelera R4.1L1 and earlier records domain authen…
Intellispace Cardiovascular
after 2.3.0
MEDIUM 5.3
CVE-2017-15272
The PSFTPd 10.0.4 Build 729 server stores its configuration inside PSFTPd.dat. This file is a Microsoft Access Database and can be extracted. The app…
Psftpd
No fix yet
HIGH 8.1
CVE-2017-14711
The Kickbase GmbH "Kickbase Bundesliga Manager" app before 2.2.1 -- aka kickbase-bundesliga-manager/id678241305 -- for iOS is vulnerable to a credent…
Bundesliga Manager
2.2.1+
HIGH 7.8
CVE-2017-15918
Sera 1.2 stores the user's login password in plain text in their home directory. This makes privilege escalation trivial and also exposes the user an…
Sera
No fix yet
CRITICAL 9.8
CVE-2017-1000245
The SSH Plugin stores credentials which allow jobs to access remote servers via the SSH protocol. User passwords and passphrases for encrypted SSH ke…
Ssh
after 2.4
HIGH 8.1
CVE-2017-3760
The Lenovo Service Framework Android application uses a set of nonsecure credentials when performing integrity verification of downloaded application…
Service Framework
Patch available
HIGH 8.4
CVE-2017-5700
Insufficient protection of password storage in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and be…
Nuc7i7bnh Firmware
Patch available
HIGH 7.5
CVE-2017-13998
An Insufficiently Protected Credentials issue was discovered in LOYTEC LVIS-3ME versions prior to 6.2.0. The application does not sufficiently protec…
Lvis 3me Firmware
after 6.1.1
HIGH 7.8
CVE-2017-1201
IBM BigFix Compliance Analytics 1.9.79 (TEMA SUAv1 SCA SCM) stores user credentials in clear text which can be read by a local user. IBM X-Force ID: …
Bigfix Security Compliance Analytics
Mitigation only