Vulnerability index

Browse CVEs

798 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cleartext TransmissionCWE-319 × clear
Qms Automotive HIGH 7.4
CVE-2023-40729

A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application lacks security control to prevent unencrypted…

Fix: 12.39+
Fix from $1,950 2023-09-12
Oas Platform HIGH 8.1
CVE-2023-34998

An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A specially craft…

Mitigation only
Fix from $1,950 2023-09-05
Aspera Faspex MEDIUM 5.9
CVE-2023-22870

IBM Aspera Faspex 5.0.5 transmits sensitive information in cleartext which could be obtained by an attacker using man in the middle techniques. IBM …

Fix: after 5.0.5
Fix from $1,600 2023-09-05
Arcgis Server MEDIUM 5.3
CVE-2023-25848

ArcGIS Enterprise Server versions 11.0 and below have an information disclosure vulnerability where a remote, unauthorized attacker may submit a craf…

Fix: after 11.0
Fix from $1,600 2023-08-25
Qts MEDIUM 6.5
CVE-2023-34972

A cleartext transmission of sensitive information vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability p…

Fix: 5.0.1.2425 / 5.1.0.2444+
Fix from $1,600 2023-08-24
Vpn MEDIUM 6.3
CVE-2023-36671

An issue was discovered in the Clario VPN client through 5.9.1.1662 for macOS. The VPN client insecurely configures the operating system such that al…

Fix: after 5.9.1.1662
Fix from $1,600 2023-08-09
Vpn MEDIUM 5.7
CVE-2023-36672

An issue was discovered in the Clario VPN client through 5.9.1.1662 for macOS. The VPN client insecurely configures the operating system such that tr…

Fix: after 5.9.1.1662
Fix from $1,600 2023-08-09
Phantom Vpn HIGH 7.3
CVE-2023-36673

An issue was discovered in Avira Phantom VPN through 2.23.1 for macOS. The VPN client insecurely configures the operating system such that all IP tra…

Fix: after 2.23.1
Fix from $1,950 2023-08-09
Rt Ac66u B1 Firmware HIGH 7.5
CVE-2023-39086

ASUS RT-AC66U B1 3.0.0.4.286_51665 was discovered to transmit sensitive information in cleartext.

Mitigation only
Fix from $1,950 2023-08-08
Warp MEDIUM 6.8
CVE-2023-2754

The Cloudflare WARP client for Windows assigns loopback IPv4 addresses for the DNS Servers, since WARP acts as local DNS server that performs DNS que…

Fix: 2023.7.160.0+
Fix from $1,600 2023-08-03
Smartgard Silver With Matrix Keyboard HIGH 7.5
CVE-2023-3763

A vulnerability was found in Intergard SGS 8.7.0. It has been declared as problematic. This vulnerability affects unknown code of the component SQL Q…

No fix yet
Fix from $1,950 2023-07-19
Smartgard Silver With Matrix Keyboard HIGH 7.5
CVE-2023-3761

A vulnerability was found in Intergard SGS 8.7.0 and classified as problematic. Affected by this issue is some unknown functionality of the component…

Mitigation only
Fix from $1,950 2023-07-19
Device Manager HIGH 7.5
CVE-2023-34142

Cleartext Transmission of Sensitive Information vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Server, Device Manager Agen…

Fix: 8.8.5-02+
Fix from $1,950 2023-07-18
Safeq Server MEDIUM 6.5
CVE-2023-35833

An issue was discovered in YSoft SAFEQ 6 Server before 6.0.82. When modifying the URL of the LDAP server configuration from LDAPS to LDAP, the system…

Fix: 6.0.82+
Fix from $1,600 2023-07-13
Marui HIGH 7.5
CVE-2023-31823

An issue found in Marui Co Marui Official app v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token …

No fix yet
Fix from $1,950 2023-07-13
Icr890 4 Firmware HIGH 7.5
CVE-2023-3272

Cleartext Transmission of Sensitive Information in the SICK ICR890-4 could allow a remote attacker to gather sensitive information by intercepting ne…

Fix: 2.5.0+
Fix from $1,950 2023-07-10
Android HIGH 7.5
CVE-2023-21219

there is a possible use of unencrypted transport over cellular networks due to an insecure default value. This could lead to remote information discl…

Mitigation only
Fix from $1,950 2023-06-28
Android HIGH 7.5
CVE-2023-21220

there is a possible use of unencrypted transport over cellular networks due to an insecure default value. This could lead to remote information discl…

Mitigation only
Fix from $1,950 2023-06-28
Sick Eventcam App HIGH 7.4
CVE-2023-31410

A remote unprivileged attacker can intercept the communication via e.g. Man-In-The-Middle, due to the absence of Transport Layer Security (TLS) in th…

Mitigation only
Fix from $1,950 2023-06-19
Serv U HIGH 7.5
CVE-2023-23841

SolarWinds Serv-U is submitting an HTTP request when changing or updating the attributes for File Share or File request.  Part of the URL of the requ…

Fix: 15.4+
Fix from $1,950 2023-06-15
Rt Ax3000 Firmware MEDIUM 5.3
CVE-2023-31195

ASUS Router RT-AX3000 Firmware versions prior to 3.0.0.4.388.23403 uses sensitive cookies without 'Secure' attribute. When an attacker is in a positi…

Fix: 3.0.0.4.388.23403+
Fix from $1,600 2023-06-13
Maximo Application Suite MEDIUM 5.9
CVE-2023-27861

IBM Maximo Application Suite - Manage Component 8.8.0 and 8.9.0 transmits sensitive information in cleartext that could be intercepted by an attacker…

Mitigation only
Fix from $1,600 2023-06-05
Coda 5310 Firmware HIGH 7.5
CVE-2023-30602

Hitron Technologies CODA-5310’s Telnet function transfers sensitive data in plaintext. An unauthenticated remote attacker can exploit this vulnerabil…

Mitigation only
Fix from $1,950 2023-06-02
Openproject HIGH 7.5
CVE-2023-33960

OpenProject is web-based project management software. For any OpenProject installation, a `robots.txt` file is generated through the server to denote…

Fix: 12.5.6+
Fix from $1,950 2023-06-01
Hqt401 Firmware CRITICAL 9.8
CVE-2023-3028

Insufficient authentication in the MQTT backend (broker) allows an attacker to access and even manipulate the telemetry data of the entire fleet of v…

Mitigation only
Fix from $2,300 2023-06-01
Escan Management Console CRITICAL 9.8
CVE-2023-33730

Privilege Escalation in the "GetUserCurrentPwd" function in Microworld Technologies eScan Management Console 14.0.1400.2281 allows any remote attacke…

No fix yet
Fix from $2,300 2023-05-31
Insight HIGH 7.4
CVE-2023-28348

An issue was discovered in Faronics Insight 10.0.19045 on Windows. A suitably positioned attacker could perform a man-in-the-middle attack on either …

No fix yet
Fix from $1,950 2023-05-31
Highlight MEDIUM 6.5
CVE-2023-33187

Highlight is an open source, full-stack monitoring platform. Highlight may record passwords on customer deployments when a password html input is swi…

Fix: 6.0.0+
Fix from $1,600 2023-05-26
Orvc HIGH 7.5
CVE-2023-31193

Snap One OvrC Pro versions prior to 7.3 use HTTP connections when downloading a program from their servers. Because they do not use HTTPS, OvrC Pro d…

Fix: 7.3.0+
Fix from $1,950 2023-05-22
Powerlogic Ion9000 Firmware CRITICAL 9.8
CVE-2022-46680

A CWE-319: Cleartext transmission of sensitive information vulnerability exists that could cause disclosure of sensitive information, denial of servi…

Fix: 4.0.0+
Fix from $2,300 2023-05-22