Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.1
CVE-2025-1886
Pass-Back vulnerability in versions prior to 2025.35.000 of Sage 200 Spain. This vulnerability allows an authenticated attacker with administrator pr…
Mitigation only
CRITICAL 10.0
CVE-2024-12799
Insufficiently Protected Credentials
vulnerability in OpenText Identity Manager Advanced Edition on Windows, Linux,
64 bit allows Privilege Abuse. Th…
Mitigation only
CRITICAL 9.8
CVE-2025-27648
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.913 Application 20.0.2253 allows Cross Tenant Password Exposure V-2024-003.
Vasion Print
20.0.2253 / 22.0.913+
CRITICAL 9.8
CVE-2025-27650
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Private Keys in Docker Overlay V-2023-013.
Vasion Print
20.0.2014 / 22.0.862+
HIGH 7.5
CVE-2024-41771
IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a remote attacker to download temporary files which could expose…
Engineering Requirements Management Doors Next
Mitigation only
HIGH 7.5
CVE-2024-41770
IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a remote attacker to download temporary files which could expose…
Engineering Requirements Management Doors Next
Mitigation only
MEDIUM 6.8
CVE-2024-44754
Cryptographic key extraction from internal flash in Minut M2 with firmware version #15142 allows physically proximate attackers to inject modified fi…
Mitigation only
HIGH 8.8
CVE-2024-38291
In XIQ-SE before 24.2.11, a low-privileged user may be able to access admin passwords, which could lead to privilege escalation.
Xiq Se
24.2.11+
CRITICAL 9.8
CVE-2025-25570
Vue Vben Admin 2.10.1 allows unauthorized login to the backend due to an issue with hardcoded credentials.
Mitigation only
MEDIUM 6.3
CVE-2024-37362
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or re…
Mitigation only
CRITICAL 9.9
CVE-2025-0867
The standard user uses the run as function to start the MEAC applications with administrative privileges. To ensure that the system can startup on it…
Mitigation only
CRITICAL 9.1
CVE-2025-26492
In JetBrains TeamCity before 2024.12.2 improper Kubernetes connection settings could expose sensitive resources
Teamcity
2024.12.2+
MEDIUM 6.5
CVE-2024-43779
An information disclosure vulnerability exists in the Vault API functionality of ClearML Enterprise Server 3.22.5-1533. A specially crafted HTTP requ…
Clearml Enterprise Server
No fix yet
CRITICAL 9.8
CVE-2025-0890EPSS 14%
**UNSUPPORTED WHEN ASSIGNED**
Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAF…
Vmg4325 B10a Firmware
Mitigation only
HIGH 7.6
CVE-2024-12511
With address book access, SMB/FTP settings could be modified, redirecting scans and possibly capturing credentials. This requires enabled scan functi…
Mitigation only
CRITICAL 9.8
CVE-2025-0498
A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists du…
Factorytalk Assetcentre
15.00.01+
CRITICAL 9.8
CVE-2025-0497
A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists du…
Factorytalk Assetcentre
15.00.01+
CRITICAL 9.8
CVE-2025-0477
An encryption vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due …
Factorytalk Assetcentre
15.00.01+
CRITICAL 9.8
CVE-2024-57395
Password Vulnerability in Safety production process management system v1.0 allows a remote attacker to escalate privileges, execute arbitrary code an…
Mitigation only
HIGH 7.5
CVE-2024-23733
The /WmAdmin/,/invoke/vm.server/login login page in the Integration Server in Software AG webMethods 10.15.0 before Core_Fix7 allows remote attackers…
Mitigation only
MEDIUM 5.5
CVE-2023-50945
IBM Common Licensing 9.0 stores user credentials in plain clear text which can be read by a local user.
Common Licensing
Mitigation only
MEDIUM 5.7
CVE-2024-42012
GRAU DATA Blocky before 3.1 stores passwords encrypted rather than hashed. At the login screen, the user's password is compared to the user's decrypt…
Mitigation only
MEDIUM 6.6
CVE-2025-23040
GitHub Desktop is an open-source Electron-based GitHub app designed for git development. An attacker convincing a user to clone a repository directly…
Mitigation only
HIGH 7.2
CVE-2024-46480
An NTLM hash leak in Venki Supravizio BPM up to 18.0.1 allows authenticated attackers with Application Administrator access to escalate privileges on…
Supravizio Bpm
after 18.0.1
CRITICAL 9.8
CVE-2024-42172
HCL MyXalytics is affected by broken authentication. It allows attackers to compromise keys, passwords, and session tokens, potentially leading to i…
Dryice Myxalytics
Mitigation only
MEDIUM 5.5
CVE-2024-54471
This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A …
macOS
13.7.1 / 14.7.1+
MEDIUM 6.7
CVE-2024-53292
Dell VxVerify, versions prior to x.40.405, contain a Plain-text Password Storage Vulnerability in the shell wrapper. A local high privileged attacker…
Vxrail Hyperconverged Infrastructure
Mitigation only
HIGH 8.0
CVE-2024-46341
TP-Link TL-WR845N(UN)_V4_190219 was discovered to transmit credentials in base64 encoded form, which can be easily decoded by an attacker executing a…
Tl Wr845n Firmware
Mitigation only
HIGH 8.0
CVE-2024-50699
TP-Link TL-WR845N(UN)_V4_201214, TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 were discovered to contain weak default credentials for the Admi…
Tl Wr845n Firmware
No fix yet
CRITICAL 9.1
CVE-2024-40583
Pentaminds CuroVMS v2.0.1 was discovered to contain exposed credentials.
Curovms
No fix yet