Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2017-1378
IBM Spectrum Protect 7.1 and 8.1 (formerly Tivoli Storage Manager) disclosed unencrypted login credentials to Vmware vCenter in the application trace…
Tivoli Storage Manager
Patch available
HIGH 7.8
CVE-2017-1362
IBM Security Identity Manager Adapters 6.0 and 7.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: …
Security Identity Manager
Patch available
HIGH 8.1
CVE-2017-14418
The D-Link NPAPI extension, as used in conjunction with D-Link DIR-850L REV. B (with firmware through FW208WWb02) devices, sends the cleartext admin …
Dir 850l Firmware
No fix yet
CRITICAL 9.8
CVE-2017-13771
Lexmark Scan To Network (SNF) 3.2.9 and earlier stores network configuration credentials in plaintext and transmits them in requests, which allows re…
Scan To Network
after 3.2.9
MEDIUM 5.3
CVE-2017-8446
The Reporting feature in X-Pack in versions prior to 5.5.2 and standalone Reporting plugin versions versions prior to 2.4.6 had an impersonation vuln…
X Pack
after 5.5.1
HIGH 8.8
CVE-2017-7547EPSS 6%
PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attackers to re…
PostgreSQL
Mitigation only
CRITICAL 9.8
CVE-2017-4923
VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure vulnerability. This issue may allow plaintext credentials to be obtain…
Vcenter Server
Patch available
CRITICAL 9.8
CVE-2017-6532
Televes COAXDATA GATEWAY 1Gbps devices doc-wifi-hgw_v1.02.0014 4.20 have cleartext credentials in /mib.db.
Coaxdata Gateway 1gbps Firmware
Mitigation only
CRITICAL 9.8
CVE-2017-11349
dataTaker DT8x dEX 1.72.007 allows remote attackers to compose programs or schedules, for purposes such as sending e-mail messages or making outbound…
Dt8x Firmware
No fix yet
HIGH 8.1
CVE-2017-1337
IBM WebSphere MQ 9.0.1 and 9.0.2 Java/JMS application can incorrectly transmit user credentials in plain text. IBM X-Force ID: 126245.
Websphere Mq
Mitigation only
CRITICAL 9.8
CVE-2017-6709
A vulnerability in the AutoVNF tool for the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to access administrative c…
Ultra Services Framework
after 5.0.2
MEDIUM 5.5
CVE-2017-1207
IBM WebSphere Message Broker stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 123777.
Websphere Message Broker
Mitigation only
CRITICAL 9.8
CVE-2017-7315
An issue was discovered on Humax Digital HG100R 2.0.6 devices. To download the backup file it's not necessary to use credentials, and the router cred…
Hg100r Firmware
No fix yet
CRITICAL 9.8
CVE-2017-9248 KEVEPSS 75%
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web…
Sitefinity
10.0.6412.0+
CRITICAL 9.8
CVE-2017-6028
An Insufficiently Protected Credentials issue was discovered in Schneider Electric Modicon PLCs Modicon M241, all firmware versions, and Modicon M251…
Modicon M241 Firmware
after 4.0.3.20
HIGH 7.5
CVE-2017-6046
An Insufficiently Protected Credentials issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT,…
Airlink Raven Xe Firmware
Mitigation only
CRITICAL 9.8
CVE-2017-7905
A Weak Cryptography for Passwords issue was discovered in General Electric (GE) Multilin SR 750 Feeder Protection Relay, firmware versions prior to V…
Multilin Sr 750 Feeder Protection Relay Firmware
after 6.0
HIGH 7.5
CVE-2017-7524
tpm2-tools versions before 1.1.1 are vulnerable to a password leak due to transmitting password in plaintext from client to server when generating HM…
Tpm2.0 Tools
after 1.1.0
HIGH 7.5
CVE-2017-3214
The Milwaukee ONE-KEY Android mobile application stores the master token in plaintext in the apk binary.
One Key
Mitigation only
HIGH 7.8
CVE-2017-9552
A design flaw in authentication in Synology Photo Station 6.0-2528 through 6.7.1-3419 allows local users to obtain credentials via cmdline. Synology …
Photo Station
Mitigation only
MEDIUM 5.5
CVE-2017-6694
A vulnerability in the Virtual Network Function Manager's (VNFM) logging function of Cisco Ultra Services Platform could allow an authenticated, loca…
Ultra Services Platform
Mitigation only
HIGH 7.5
CVE-2017-9557
register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1 allows remote attackers to discover passwords by sending the username parameter in …
Easy Chat Server
after 3.1
CRITICAL 9.8
CVE-2017-8837
Cleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_…
B305hw2 Firmware
Patch available
CRITICAL 9.8
CVE-2017-7913
A Plaintext Storage of a Password issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3110-HSDPA…
Oncell G3110 Hspa Firmware
after 1.4
HIGH 7.5
CVE-2017-9136
An issue was discovered on Mimosa Client Radios before 2.2.3. In the device's web interface, there is a page that allows an attacker to use an unsani…
Backhaul Radios
after 2.2.1
HIGH 7.5
CVE-2017-7486EPSS 6%
PostgreSQL versions 8.4 - 9.6 are vulnerable to information leak in pg_user_mappings view which discloses foreign server passwords to any user having…
PostgreSQL
Mitigation only
CRITICAL 9.8
CVE-2017-7925EPSS 51%
A Password in Configuration File issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XX…
Dh Ipc Hdbw23a0rn Zs Firmware
Patch available
MEDIUM 6.8
CVE-2017-8371
Schneider Electric StruxureWare Data Center Expert before 7.4.0 uses cleartext RAM storage for passwords, which might allow remote attackers to obtai…
Struxureware Data Center Expert
after 7.3.1
HIGH 7.5
CVE-2017-8296
kedpm 0.5 and 1.0 creates a history file in ~/.kedpm/history that is written in cleartext. All of the commands performed in the password manager are …
Ked Password Manager
Patch available
HIGH 7.5
CVE-2017-8222
Wireless IP Camera (P2P) WIFICAM devices have an "Apple Production IOS Push Services" private RSA key and certificate stored in /system/www/pem/ck.pe…
Wireless Ip Camera \(p2p\) Firmware
No fix yet