Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2025-40838
Ericsson Indoor Connect 8855 contains a vulnerability where server-side security can be bypassed in the client which if exploited can lead to unautho…
Indoor Connect 8855 Firmware
2025.q2+
MEDIUM 6.9
CVE-2025-10360
In Puppet Enterprise versions 2025.4.0 and 2025.5, the encryption key used for encrypting content in the Infra Assistant database was not excluded fr…
Mitigation only
MEDIUM 5.3
CVE-2025-54467
When a Java command with password parameters is executed and terminated by NeuVector for Process rule violation the password will appear in the NeuVe…
Mitigation only
CRITICAL 9.8
CVE-2025-23342
The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to gain access to a privileged account . A successful exploit of this vulner…
Nvdebug
1.7.0+
HIGH 8.8
CVE-2025-42933
When a user logs in via SAP Business One native client, the SLD backend service fails to enforce proper encryption of certain APIs. This leads to exp…
Mitigation only
HIGH 8.8
CVE-2025-41682
An authenticated, low-privileged attacker can obtain credentials stored on the charge controller including the manufacturer password.
Mitigation only
CRITICAL 9.4
CVE-2025-58366
Onyxia is a data science environment for kubernetes. In versions 4.6.0 through 4.8.0, Onyxia-API leaked the credentials of private helm repositories …
Patch available
MEDIUM 5.1
CVE-2025-55739
api is a module for FreePBX@, which is an open source GUI that controls and manages Asterisk© (PBX). In versions lower than 15.0.13, 16.0.2 through 1…
Patch available
MEDIUM 6.9
CVE-2025-57806
Local Deep Research is an AI-powered research assistant for deep, iterative research. Versions 0.2.0 through 0.6.7 stored confidential information, i…
Patch available
CRITICAL 9.8
CVE-2025-6519
E3 Site Supervisor (firmware version < 2.31F01) has a default admin user "ONEDAY" with a daily generated password. An attacker can predictably genera…
E3 Supervisory Controller Firmware
2.31f01+
CRITICAL 9.8
CVE-2025-52549
E3 Site Supervisor Control (firmware version < 2.31F01) generates the root linux password on each boot. An attacker can generate the root linux passw…
E3 Supervisory Controller Firmware
2.31f01+
HIGH 7.5
CVE-2025-52545
E3 Site Supervisor Control (firmware version < 2.31F01) RCI service contains an API call to read users info, which returns all usernames and password…
E3 Supervisory Controller Firmware
2.31f01+
CRITICAL 9.8
CVE-2025-52095
An issue in PDQ Smart Deploy V.3.0.2040 allows an attacker to escalate privileges via the Credential encryption routines in SDCommon.dll
Smart Deploy
3.0.2046+
CRITICAL 9.8
CVE-2025-55306
GenX_FX is an advance IA trading platform that will focus on forex trading. A vulnerability was identified in the GenX FX backend where API keys and …
Mitigation only
HIGH 7.5
CVE-2025-54156
The Sante PACS Server Web Portal sends credential information without encryption.
Sante Pacs Server
4.2.3+
HIGH 7.8
CVE-2025-40751
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.3). Affected SIMATIC RTLS Locating Manager Report Clients do …
Simatic Rtls Locating Manager
3.3+
HIGH 7.8
CVE-2025-48709
BMC Control-M/Server 9.0.21.300 displays cleartext database credentials in process lists and logs. An authenticated attacker with shell access could …
Control M\/server
Mitigation only
MEDIUM 5.3
CVE-2025-54394
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 has Insufficiently Protected Credentials for requests to remote Ex…
Directory Manager
11.1.25162.02+
HIGH 7.1
CVE-2025-54882
Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. In versions 0.8.0 through 0.9.21 and 1.0.0-beta through 1.1.0, Himme…
Himmelblau
0.9.22 / 1.2.0+
MEDIUM 6.9
CVE-2025-54876
The Janssen Project is an open-source identity and access management (IAM) platform. In versions 1.9.0 and below, Janssen stores passwords in plainte…
Patch available
MEDIUM 5.3
CVE-2025-38739
Dell Digital Delivery, versions prior to 5.6.1.0, contains an Insufficiently Protected Credentials vulnerability. A remote unauthenticated attacker c…
Digital Delivery
5.6.1.0+
MEDIUM 6.5
CVE-2025-53008
GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features,…
Glpi
10.0.19+
MEDIUM 5.5
CVE-2025-54422
Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. In versions 1.16.1 and below, a critical se…
Sandboxie
1.16.2+
CRITICAL 9.8
CVE-2025-54428
RevelaCode is an AI-powered faith-tech project that decodes biblical verses, prophecies and global events into accessible language. In versions below…
Patch available
MEDIUM 6.5
CVE-2025-54380
Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to version 17.6, Opencast would inco…
Opencast
17.6+
HIGH 8.7
CVE-2025-34139
A vulnerability exists in Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud that could allow an…
Mitigation only
HIGH 7.5
CVE-2025-7565
A vulnerability, which was classified as critical, was found in LB-LINK BL-AC3600 up to 1.0.22. This affects the function geteasycfg of the file /cgi…
Bl Ac3600 Firmware
after 1.0.22
MEDIUM 5.3
CVE-2025-53743
Jenkins Applitools Eyes Plugin 1.16.5 and earlier does not mask Applitools API keys displayed on the job configuration form, increasing the potential…
Applitools Eyes
1.16.6+
MEDIUM 5.3
CVE-2025-53667
Jenkins Dead Man's Snitch Plugin 0.1 does not mask Dead Man's Snitch tokens displayed on the job configuration form, increasing the potential for att…
Dead Man\'s Snitch
Mitigation only
MEDIUM 6.5
CVE-2025-53671
Jenkins Nouvola DiveCloud Plugin 1.08 and earlier does not mask DiveCloud API Keys and Credentials Encryption Keys displayed on the job configuration…
Nouvola Divecloud
after 1.08