Vulnerability index

Browse CVEs

798 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cleartext TransmissionCWE-319 × clear
Keepass HIGH 7.5
CVE-2023-32784

In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a workspace is locked or no longer …

Fix: 2.54+
Fix from $1,950 2023-05-15
Cp3 Firmware CRITICAL 9.8
CVE-2023-30354

Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 does not defend against physical access to U-Boot via the UART: the Wi-Fi password is sho…

Mitigation only
Fix from $2,300 2023-05-10
Skybridge Mb A110 Firmware MEDIUM 6.5
CVE-2023-25070

Cleartext transmission of sensitive information exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier. If the telnet connection is enabled,…

Fix: after 4.2.0
Fix from $1,600 2023-05-10
Mymail HIGH 7.5
CVE-2023-32290

The myMail app through 14.30 for iOS sends cleartext credentials in a situation where STARTTLS is expected by a server.

Fix: after 14.30
Fix from $1,950 2023-05-07
N301 Firmware MEDIUM 5.7
CVE-2023-29680

Cleartext Transmission in set-cookie:ecos_pw: Tenda N301 v6.0, Firmware v12.02.01.61_multi allows an authenticated attacker on the LAN or WLAN to int…

No fix yet
Fix from $1,600 2023-05-01
N301 Firmware MEDIUM 5.7
CVE-2023-29681

Cleartext Transmission in cookie:ecos_pw: in Tenda N301 v6.0, firmware v12.03.01.06_pt allows an authenticated attacker on the LAN or WLAN to interce…

No fix yet
Fix from $1,600 2023-05-01
Vcs754a Firmware HIGH 8.8
CVE-2023-25437EPSS 14%

An issue was discovered in vTech VCS754 version 1.1.1.A before 1.1.1.H, allows attackers to gain escalated privileges and gain sensitive information …

Fix: 1.1.1.h+
Fix from $1,950 2023-04-27
Baremetal Operator MEDIUM 5.5
CVE-2023-30841

Baremetal Operator (BMO) is a bare metal host provisioning integration for Kubernetes. Prior to version 0.3.0, ironic and ironic-inspector deployed w…

Fix: 0.3.0+
Fix from $1,600 2023-04-26
Mattermost Server HIGH 7.5
CVE-2023-1831

Mattermost fails to redact from audit logs the user password during user creation and the user password hash in other operations if the experimental …

Fix: 7.7.3 / 7.8.2+
Fix from $1,950 2023-04-17
GitLab MEDIUM 5.9
CVE-2019-14942

An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.1.6. Cookies for GitLab Pages…

Fix: 11.11.8 / 12.0.6+
Fix from $1,600 2023-04-16
Azure Key Vault HIGH 7.5
CVE-2023-30514

Jenkins Azure Key Vault Plugin 187.va_cd5fecd198a_ and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log whe…

Fix: after 187.va_cd5fecd198a
Fix from $1,950 2023-04-12
Thycotic Devops Secrets Vault HIGH 7.5
CVE-2023-30515

Jenkins Thycotic DevOps Secrets Vault Plugin 1.0.0 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log whe…

Fix: after 1.0.0
Fix from $1,950 2023-04-12
Kubernetes HIGH 7.5
CVE-2023-30513

Jenkins Kubernetes Plugin 3909.v1f2c633e8590 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push…

Fix: after 3909.v1f2c633e8590
Fix from $1,950 2023-04-12
Desktop HIGH 7.5
CVE-2023-1802

In Docker Desktop 4.17.x the Artifactory Integration falls back to sending registry credentials over plain HTTP if the HTTPS health check has failed.…

No fix yet
Fix from $1,950 2023-04-06
Samba MEDIUM 5.9
CVE-2023-0922

The Samba AD DC administration tool, when operating against a remote LDAP server, will by default send new or reset passwords over a signed-only conn…

Fix: 4.16.10 / 4.17.7+
Fix from $1,600 2023-04-03
Ldap Connector HIGH 7.5
CVE-2023-1656

Cleartext Transmission of Sensitive Information vulnerability in ForgeRock Inc. OpenIDM and Java Remote Connector Server (RCS) LDAP Connector on Wind…

Fix: 1.5.20.14+
Fix from $1,950 2023-03-29
Ey As525f001 Firmware MEDIUM 6.5
CVE-2023-27927

An authenticated malicious user could acquire the simple mail transfer protocol (SMTP) Password in cleartext format, despite it being protected and h…

Mitigation only
Fix from $1,600 2023-03-27
Rbs750 Firmware MEDIUM 5.9
CVE-2022-38458

A cleartext transmission vulnerability exists in the Remote Management functionality of Netgear Orbi Router RBR750 4.6.8.5. A specially-crafted man-i…

No fix yet
Fix from $1,600 2023-03-21
Nova 220 Eyk220f001 Firmware HIGH 7.5
CVE-2023-0053

SAUTER Controls Nova 200–220 Series with firmware version 3.3-006 and prior and BACnetstac version 4.2.1 and prior have only FTP and Telnet availab…

Fix: after 4.2.1
Fix from $1,950 2023-03-02
Music MEDIUM 5.3
CVE-2022-32906

This issue was addressed with using HTTPS when sending information over the network. This issue is fixed in Apple Music 3.9.10 for Android. A user in…

Fix: 3.9.10+
Fix from $1,600 2023-02-27
Curl CRITICAL 9.1
CVE-2023-23914

A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs a…

Fix: 7.88.0 / 8.2.12+
Fix from $2,300 2023-02-23
Curl MEDIUM 6.5
CVE-2023-23915

A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrectly whe…

Fix: 7.88.0 / 8.2.12+
Fix from $1,600 2023-02-23
Badgemaker HIGH 7.5
CVE-2022-45546

Information Disclosure in Authentication Component of ScreenCheck BadgeMaker 2.6.2.0 application allows internal attacker to obtain credentials for a…

No fix yet
Fix from $1,950 2023-02-15
Xbc Dn32u Firmware HIGH 7.5
CVE-2023-22806

LS ELECTRIC XBC-DN32U with operating system version 01.80 transmits sensitive information in cleartext when communicating over its XGT protocol. This…

Mitigation only
Fix from $1,950 2023-02-15
Cortex Xdr Agent MEDIUM 6.7
CVE-2023-0001

An information exposure vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local system administrator to disclose t…

Fix: 7.5.101+
Fix from $1,600 2023-02-08
Sds 3008 Firmware HIGH 7.5
CVE-2022-40693

A cleartext transmission vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A speciall…

Fix: after 2.1
Fix from $1,950 2023-02-07
Couchbase Server HIGH 7.5
CVE-2023-25016

Couchbase Server before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2 exposes Sensitive Information to an Unauthorized Actor.

Fix: 6.6.6 / 7.0.5+
Fix from $1,950 2023-02-06
Automate MEDIUM 5.9
CVE-2023-23130

Connectwise Automate 2022.11 is vulnerable to Cleartext authentication. Authentication is being done via HTTP (cleartext) with SSL disabled. OTE: the…

Mitigation only
Fix from $1,600 2023-02-01
Last Yard CRITICAL 9.8
CVE-2022-47714

Last Yard 22.09.8-1 does not enforce HSTS headers

No fix yet
Fix from $2,300 2023-02-01
Jira Pipeline Steps MEDIUM 5.5
CVE-2023-24440

Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier transmits the private key in plain text as part of the global Jenkins configurat…

Fix: after 2.0.165.v8846cf59f3db
Fix from $1,600 2023-01-26