Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.5
CVE-2026-27770
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
Mitigation only
HIGH 7.5
CVE-2026-30796
Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in rustdesk-client RustDesk Client rustdesk-clien…
Rustdesk Server
after 1.7.5
CRITICAL 10.0
CVE-2026-29128
IDC SFX2100 Satellite Receiver firmware ships with multiple daemon configuration files for routing components (e.g., zebra, bgpd, ospfd, and ripd) th…
Sfx2100 Firmware
Mitigation only
MEDIUM 5.9
CVE-2026-27167
Gradio is an open-source Python package designed for quick prototyping. Starting in version 4.16.0 and prior to version 6.6.0, Gradio applications ru…
Gradio
6.6.0+
CRITICAL 9.8
CVE-2026-21660
Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD vers…
Frick Controls Quantum Hd Firmware
after 10.22
MEDIUM 5.3
CVE-2026-25774
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
Ev.energy
Mitigation only
MEDIUM 5.3
CVE-2026-22878
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
Mobility46.se
Mitigation only
MEDIUM 5.3
CVE-2026-27773
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
Swtchenergy.com
No fix yet
HIGH 7.5
CVE-2026-20791
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
Chargemap.com
Mitigation only
MEDIUM 5.3
CVE-2026-22890
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
Ev2go.io
Mitigation only
MEDIUM 5.3
CVE-2026-20733
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
Cloudcharge.se
No fix yet
MEDIUM 5.7
CVE-2026-26049
The web management interface of the device renders the passwords in a
plaintext input field. The current password is directly visible to
anyone wit…
Mitigation only
MEDIUM 5.5
CVE-2026-27003
OpenClaw is a personal AI assistant. Telegram bot tokens can appear in error messages and stack traces (for example, when request URLs include `https…
Openclaw
2026.2.15+
MEDIUM 6.5
CVE-2026-25631
n8n is an open source workflow automation platform. Prior to 1.121.0, there is a vulnerability in the HTTP Request node's credential domain validatio…
N8n
1.121.0+
MEDIUM 6.8
CVE-2026-0715
Moxa Arm-based industrial computers running Moxa Industrial Linux Secure use a device-unique bootloader password provided on the device. An attacker …
Uc 1222a Firmware
after 1.4
HIGH 7.5
CVE-2020-37097
Edimax EW-7438RPn 1.13 contains an information disclosure vulnerability that exposes WiFi network configuration details through the wlencrypt_wiz.asp…
Ew 7438rpn Mini Firmware
No fix yet
MEDIUM 6.5
CVE-2025-52623
HCL AION is affected by an Autocomplete HTML Attribute Not Disabled for Password Field vulnerability. This can allow autocomplete on password fields…
Aion
Mitigation only
MEDIUM 6.5
CVE-2026-24845
malcontent discovers supply-chain compromises through. context, differential analysis, and YARA. Starting in version 0.10.0 and prior to version 1.20…
Malcontent
1.20.3+
MEDIUM 6.5
CVE-2020-36968
M/Monit 3.7.4 contains an authentication vulnerability that allows authenticated attackers to retrieve user password hashes through an administrative…
M\/monit
No fix yet
MEDIUM 6.5
CVE-2025-9521
Password Confirmation Bypass vulnerability in Omada Controllers, allowing an attacker with a valid session token to bypass secondary verification, an…
Omada Controller
6.0+
HIGH 7.4
CVE-2025-65098
Typebot is an open-source chatbot builder. In versions prior to 3.13.2, client-side script execution in Typebot allows stealing all stored credential…
Typebot
3.13.2+
CRITICAL 9.8
CVE-2026-23958
Dataease is an open source data visualization analysis tool. Prior to version 2.10.19, DataEase uses the MD5 hash of the user’s password as the JWT s…
Dataease
2.10.19+
HIGH 7.5
CVE-2026-21852EPSS 23%
Claude Code is an agentic coding tool. Prior to version 2.0.65, vulnerability in Claude Code's project-load flow allowed malicious repositories to ex…
Claude Code
2.0.65+
HIGH 7.5
CVE-2025-58741
Insufficiently Protected Credentials vulnerability in the Credential Field of Milner ImageDirector Capture allows retrieval of credential material an…
Imagedirector Capture
7.6.3.25808+
MEDIUM 5.9
CVE-2025-58742
Insufficiently Protected Credentials, Improper Restriction of Communication Channel to Intended Endpoints vulnerability in the Connection Settings di…
Imagedirector Capture
7.6.3.25808+
HIGH 8.8
CVE-2026-23742
Skipper is an HTTP router and reverse proxy for service composition. The default skipper configuration before 0.23.0 was -lua-sources=inline,file. Th…
Skipper
0.23.0+
MEDIUM 6.2
CVE-2021-47759
MTPutty 1.0.1.21 contains a sensitive information disclosure vulnerability that allows local attackers to view SSH connection passwords through Windo…
No fix yet
HIGH 7.5
CVE-2026-22911
Firmware update files may expose password hashes for system accounts, which could allow a remote attacker to recover credentials and gain unauthorize…
Tdc X401gl Firmware
Mitigation only
HIGH 7.5
CVE-2026-22240
The vulnerability exists in BLUVOYIX due to an improper password storage implementation and subsequent exposure via unauthenticated APIs. An unauthen…
Bluvoyix
Mitigation only
HIGH 7.5
CVE-2025-69271
Insufficiently Protected Credentials vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Sniffing Attacks.This issue affects DX Net…
Dx Netops Spectrum
25.4.1+