Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.3
CVE-2025-53650
Jenkins Credentials Binding Plugin 687.v619cb_15e923f and earlier does not properly mask (i.e., replace with asterisks) credentials present in except…
Credentials Binding
after 687.689.v1a_f775332fc
MEDIUM 6.5
CVE-2025-53654
Jenkins Statistics Gatherer Plugin 2.0.3 and earlier stores the AWS Secret Key unencrypted in its global configuration file on the Jenkins controller…
Statistics Gatherer
after 2.0.3
MEDIUM 6.4
CVE-2025-24508
Extraction of Account Connectivity Credentials (ACCs) from the IT Management Agent secure storage
Mitigation only
HIGH 7.8
CVE-2025-34078
A local privilege escalation vulnerability exists in NSClient++ 0.5.2.35 when both the web interface and ExternalScripts features are enabled. The co…
Nsclient\+\+
No fix yet
MEDIUM 5.7
CVE-2025-34062
An information disclosure vulnerability exists in OneLogin AD Connector versions prior to 6.1.5 via the /api/adc/v4/configuration endpoint. An attack…
Mitigation only
MEDIUM 6.8
CVE-2025-6081
Insufficiently Protected Credentials in LDAP in Konica Minolta bizhub 227 Multifunction printers version GCQ-Y3 or earlier allows an attacker can rec…
Mitigation only
HIGH 8.1
CVE-2024-49364
tiny-secp256k1 is a tiny secp256k1 native/JS wrapper. Prior to version 1.1.7, a private key can be extracted on signing a malicious JSON-stringifiabl…
Patch available
MEDIUM 6.8
CVE-2024-51984
An authenticated attacker can reconfigure the target device to use an external service (such as LDAP or FTP) controlled by the attacker. If an existi…
Mitigation only
MEDIUM 5.3
CVE-2025-6526
A vulnerability, which was classified as problematic, has been found in 70mai M300 up to 20250611. This issue affects some unknown processing of the …
M300 Firmware
after 2025-06-11
MEDIUM 5.5
CVE-2025-35941
A password is exposed locally.
No fix yet
HIGH 7.5
CVE-2025-30183
CyberData 011209 Intercom
does not properly store or protect web server admin credentials.
011209 Sip Emergency Intercom Firmware
22.0.1+
MEDIUM 5.3
CVE-2024-47081
Requests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific m…
Patch available
MEDIUM 6.5
CVE-2025-33079
IBM Controller 11.0.0, 11.0.1, and 11.1.0 application could allow an authenticated user to obtain sensitive credentials that may be inadvertently inc…
Cognos Controller
Mitigation only
MEDIUM 6.5
CVE-2025-3480
MedDream WEB DICOM Viewer Cleartext Transmission of Credentials Information Disclosure Vulnerability. This vulnerability allows network-adjacent atta…
Pacs Server
Mitigation only
HIGH 8.7
CVE-2025-3079
A passback vulnerability which relates to office/small office multifunction printers and laser printers.
No fix yet
HIGH 8.7
CVE-2025-3078
A passback vulnerability which relates to production printers and office multifunction printers.
Mitigation only
MEDIUM 6.5
CVE-2025-4679
A vulnerability in Synology Active Backup for Microsoft 365 allows remote authenticated attackers to obtain sensitive information via unspecified vec…
Active Backup For Microsoft 365
Mitigation only
HIGH 7.5
CVE-2025-33093
IBM Sterling Partner Engagement Manager 6.1.0, 6.2.0, 6.2.2 JWT secret is stored in public Helm Charts and is not stored as a Kubernetes secret.
Sterling Partner Engagement Manager
Mitigation only
HIGH 7.1
CVE-2025-46820
phpgt/Dom provides access to modern DOM APIs. Versions of phpgt/Dom prior to 4.1.8 expose the GITHUB_TOKEN in the Dom workflow run artifact. The ci.y…
Patch available
MEDIUM 6.5
CVE-2025-2772
BEC Technologies Multiple Routers Insufficiently Protected Credentials Information Disclosure Vulnerability. This vulnerability allows network-adjace…
Router Firmware
Mitigation only
MEDIUM 6.9
CVE-2025-32963
MinIO Operator STS is a native IAM Authentication for Kubernetes. Prior to version 7.1.0, if no audiences are provided for the `spec.audiences` field…
Patch available
HIGH 7.5
CVE-2025-28228
A credential exposure vulnerability in Electrolink 500W, 1kW, 2kW Medium DAB Transmitter Web v01.09, v01.08, v01.07, and Display v1.4, v1.2 allows un…
Fm\/dab\/tv Transmitter Web Management System
No fix yet
CRITICAL 9.3
CVE-2025-22372
Insufficiently Protected Credentials vulnerability in SicommNet BASEC on SaaS allows Password Recovery.
Passwords are either stored in plain text usi…
Mitigation only
MEDIUM 5.5
CVE-2025-26628
Insufficiently protected credentials in Azure Local Cluster allows an authorized attacker to disclose information locally.
Azure Local Cluster
2411.2+
HIGH 8.5
CVE-2025-2908
The exposure of credentials in the call forwarding configuration module in MeetMe products in versions prior to 2024-09 allows an attacker to gain ac…
Mitigation only
CRITICAL 9.0
CVE-2025-2311
Incorrect Use of Privileged APIs, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in Sechard Info…
Mitigation only
CRITICAL 9.1
CVE-2025-25650
An issue in the storage of NFC card data in Dorset DG 201 Digital Lock H5_433WBSK_v2.2_220605 allows attackers to produce cloned NFC cards to bypass …
Mitigation only
HIGH 7.5
CVE-2025-2277
Exposure of password in web-based SSH authentication component in Devolutions Server 2024.3.13 and earlier allows a user to unadvertently leak his SS…
Devolutions Server
2025.1.3.0+
MEDIUM 5.3
CVE-2025-27926
In Nintex Automation 5.6 and 5.7 before 5.8, the K2 SmartForms Designer folder has configuration files (web.config) containing passwords that are rea…
Automation
5.8+
MEDIUM 5.3
CVE-2024-47109
IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 UI could disclosure the installation path of the server which could aid…
Sterling File Gateway
6.1.2.7 / 6.2.0.4+