Vulnerability index

Browse CVEs

798 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cleartext TransmissionCWE-319 × clear
Journalpump HIGH 7.5
CVE-2023-51390

journalpump is a daemon that takes log messages from journald and pumps them to a given output. A logging vulnerability was found in journalpump whic…

Fix: 2.5.0+
Fix from $1,950 2023-12-21
Uc 500e Firmware MEDIUM 5.9
CVE-2023-50703

An attacker with network access could perform a man-in-the-middle (MitM) attack and capture sensitive information to gain unauthorized access to the …

No fix yet
Fix from $1,600 2023-12-20
Senec Storage Box Firmware CRITICAL 9.1
CVE-2023-39172

The affected devices transmit sensitive information unencrypted allowing a remote unauthenticated attacker to capture and modify network traffic.

Mitigation only
Fix from $2,300 2023-12-07
Mos MEDIUM 6.5
CVE-2023-24547

On affected platforms running Arista MOS, the configuration of a BGP password will cause the password to be logged in clear text that can be revealed…

Fix: after 0.39.4
Fix from $1,600 2023-12-06
Samsung Keyboard MEDIUM 5.3
CVE-2023-42579

Improper usage of insecure protocol (i.e. HTTP) in SogouSDK of Chinese Samsung Keyboard prior to versions 5.3.70.1 in Android 11, 5.4.60.49, 5.4.85.5…

Fix: 5.3.70.1 / 5.4.60.49+
Fix from $1,600 2023-12-05
L Inx Configurator HIGH 7.5
CVE-2023-46383

LOYTEC electronics GmbH LINX Configurator (all versions) uses HTTP Basic Authentication, which transmits usernames and passwords in base64-encoded cl…

No fix yet
Fix from $1,950 2023-11-30
L Inx Configurator HIGH 7.5
CVE-2023-46385

LOYTEC electronics GmbH LINX Configurator (all versions) is vulnerable to Insecure Permissions. An admin credential is passed as a value of URL param…

No fix yet
Fix from $1,950 2023-11-30
Syrus 4g Iot Telematics Gateway Firmware CRITICAL 9.8
CVE-2023-6248

The Syrus4 IoT gateway utilizes an unsecured MQTT server to download and execute arbitrary commands, allowing a remote unauthenticated attacker to ex…

Mitigation only
Fix from $2,300 2023-11-21
Comos HIGH 7.5
CVE-2023-43503

A vulnerability has been identified in COMOS (All versions < V10.4.4). Caching system in the affected application leaks sensitive information such as…

Fix: 10.4.4+
Fix from $1,950 2023-11-14
Linx 212 Firmware HIGH 7.5
CVE-2023-46382

LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) use cleartext HTTP for login.

No fix yet
Fix from $1,950 2023-11-04
Linx 212 Firmware HIGH 7.5
CVE-2023-46380

LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) send password-change requests vi…

No fix yet
Fix from $1,950 2023-11-04
Botan HIGH 7.5
CVE-2017-7252

bcrypt password hashing in Botan before 2.1.0 does not correctly handle passwords with a length between 57 and 72 characters, which makes it easier f…

Fix: 2.1.0+
Fix from $1,950 2023-11-03
Eds G503 Firmware MEDIUM 5.3
CVE-2023-5035

A vulnerability has been identified in PT-G503 Series firmware versions prior to v5.2, where the Secure attribute for sensitive cookies in HTTPS sess…

Fix: 5.2+
Fix from $1,600 2023-11-02
Ctrlx Hmi Web Panel Wr2107 Firmware HIGH 8.8
CVE-2023-45321

The Android Client application, when enrolled with the define method 1 (the user manually inserts the server ip address), use HTTP protocol to retri…

Mitigation only
Fix from $1,950 2023-10-25
Security Verify Governance HIGH 7.5
CVE-2023-33837

IBM Security Verify Governance 10.0 does not encrypt sensitive or critical information before storage or transmission. IBM X-Force ID: 256020.

Patch available
Fix from $1,950 2023-10-23
Cognos Dashboards On Cloud Pak For Data HIGH 7.5
CVE-2023-38276

IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in environment variables which could aid in further attacks against t…

Patch available
Fix from $1,950 2023-10-22
Cognos Dashboards On Cloud Pak For Data HIGH 7.5
CVE-2023-38275

IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in container images which could lead to further attacks against the s…

Patch available
Fix from $1,950 2023-10-22
Dexgate MEDIUM 6.5
CVE-2023-41088

The affected product is vulnerable to a cleartext transmission of sensitive information vulnerability, which may allow an attacker with access to the…

Mitigation only
Fix from $1,600 2023-10-19
Bentley Nevada 3500 System Firmware HIGH 8.2
CVE-2023-34441

Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05 contains a cleartext transmission vulnerability which could allow an attacker to…

Mitigation only
Fix from $1,950 2023-10-19
Security Verify Privilege On Premises HIGH 7.5
CVE-2022-22385

IBM Security Verify Privilege On-Premises 11.5 could disclose sensitive information to an attacked due to the transmission of data in clear text. IB…

Fix: 11.5+
Fix from $1,950 2023-10-17
Wplsoft MEDIUM 5.9
CVE-2023-5461

A vulnerability was found in Delta Electronics WPLSoft 2.51. It has been classified as problematic. Affected is an unknown function of the component …

Mitigation only
Fix from $1,600 2023-10-09
Apu0200 Firmware MEDIUM 6.5
CVE-2023-5100

Cleartext Transmission of Sensitive Information in RDT400 in SICK APU allows an unprivileged remote attacker to retrieve potentially sensitive inform…

Fix: 4.0.0.6+
Fix from $1,600 2023-10-09
Openshift Data Science HIGH 7.5
CVE-2023-3361

A flaw was found in Red Hat OpenShift Data Science. When exporting a pipeline from the Elyra notebook pipeline editor as Python DSL or YAML, it reads…

Fix: 1.28.1+
Fix from $1,950 2023-10-04
Netman 204 Firmware HIGH 7.5
CVE-2022-47892

All versions of NetMan 204 could allow an unauthenticated remote attacker to read a file (config.cgi) containing sensitive information, like credenti…

Mitigation only
Fix from $1,950 2023-10-03
Big Ip Access Policy Manager HIGH 8.2
CVE-2023-43125

BIG-IP APM clients may send IP traffic outside of the VPN tunnel.  Note: Software versions which have reached End of Technical Support (EoTS) are not…

Fix: after 16.1.4
Fix from $1,950 2023-09-27
Big Ip Access Policy Manager HIGH 7.1
CVE-2023-43124

BIG-IP APM clients may send IP traffic outside of the VPN tunnel.  Note: Software versions which have reached End of Technical Support (EoTS) are not…

Fix: after 16.1.4
Fix from $1,950 2023-09-27
Cloudexplorer Lite HIGH 7.5
CVE-2023-42147

An issue in CloudExplorer Lite 1.3.1 allows an attacker to obtain sensitive information via the login key component.

No fix yet
Fix from $1,950 2023-09-20
Ekorrci Firmware MEDIUM 6.5
CVE-2022-47560

The lack of web request control on ekorCCP and ekorRCI devices allows a potential attacker to create custom requests to execute malicious actions whe…

Mitigation only
Fix from $1,600 2023-09-20
Openstack Platform HIGH 7.5
CVE-2022-3261

A flaw was found in OpenStack. Multiple components show plain-text passwords in /var/log/messages during the OpenStack overcloud update run, leading …

Mitigation only
Fix from $1,950 2023-09-15
Keycloak HIGH 8.8
CVE-2023-4918

A flaw was found in the Keycloak package, more specifically org.keycloak.userprofile. When a user registers itself through registration flow, the "pa…

Mitigation only
Fix from $1,950 2023-09-12