Vulnerability index

Browse CVEs

798 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cleartext TransmissionCWE-319 × clear
Robotic Process Automation MEDIUM 5.9
CVE-2023-22863

IBM Robotic Process Automation 20.12.0 through 21.0.2 defaults to HTTP in some RPA commands when the prefix is not explicitly specified in the URL. …

Fix: 21.0.3+
Fix from $1,600 2023-01-18
Inrouter302 Firmware MEDIUM 5.9
CVE-2023-22597

InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CW…

Fix: 2.3.0.r5542 / 3.5.56+
Fix from $1,600 2023-01-12
Weave Gitops MEDIUM 6.0
CVE-2022-23509

Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. GitOps r…

Fix: 0.12.0+
Fix from $1,600 2023-01-09
Foxman Un CRITICAL 9.8
CVE-2022-3929

Communication between the client and the server application of the affected products is partially done using CORBA (Common Object Request Broker Arch…

Mitigation only
Fix from $2,300 2023-01-05
Pyload MEDIUM 5.3
CVE-2023-0055

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository pyload/pyload prior to 0.5.0b3.dev32.

Patch available
Fix from $1,600 2023-01-04
Curl HIGH 7.5
CVE-2022-43551EPSS 17%

A vulnerability exists in curl <7.87.0 HSTS check that could be bypassed to trick it to keep using HTTP. Using its HSTS support, curl can be instruct…

Fix: 7.87.0 / 8.2.12+
Fix from $1,950 2022-12-23
Firefox HIGH 8.8
CVE-2022-22758

When clicking on a tel: link, USSD codes, specified after a <code>\*</code> character, would be included in the phone number. On certain phones, or o…

Fix: 97.0+
Fix from $1,950 2022-12-22
Intellij Idea HIGH 7.5
CVE-2022-47895

In JetBrains IntelliJ IDEA before 2022.3.1 the "Validate JSP File" action used the HTTP protocol to download required JAR files.

Fix: 2022.3.1+
Fix from $1,950 2022-12-22
Bigfix Insights For Vulnerability Remediation MEDIUM 5.3
CVE-2022-42454

Insights for Vulnerability Remediation (IVR) is vulnerable to man-in-the-middle attacks that may lead to information disclosure.  This requires privi…

Fix: after 2.0
Fix from $1,600 2022-12-21
Whohas HIGH 7.5
CVE-2021-4258

A vulnerability was found in whohas. It has been rated as problematic. This issue affects some unknown processing of the component Package Informatio…

Fix: 2021-11-01+
Fix from $1,950 2022-12-19
Spectrum Protect Plus MEDIUM 5.9
CVE-2020-4497

IBM Spectrum Protect Plus 10.1.0 through 10.1.12 discloses sensitive information due to unencrypted data being used in the communication flow between…

Fix: 10.1.13+
Fix from $1,600 2022-12-14
Vrv9506jac23 Firmware MEDIUM 6.5
CVE-2020-9420

The login password of the web administrative dashboard in Arcadyan Wifi routers VRV9506JAC23 is sent in cleartext, allowing an attacker to sniff and …

No fix yet
Fix from $1,600 2022-12-14
Sicam Pas\/pqs CRITICAL 9.8
CVE-2022-43724

A vulnerability has been identified in SICAM PAS/PQS (All versions < V7.0). Affected software transmits the database credentials for the inbuilt SQL …

Fix: 7.0+
Fix from $2,300 2022-12-13
Openharmony MEDIUM 5.3
CVE-2022-45877

OpenHarmony-v3.1.4 and prior versions had an vulnerability. PIN code is transmitted to the peer device in plain text during cross-device authenticati…

Fix: after 3.1.4
Fix from $1,600 2022-12-08
Telepad MEDIUM 5.9
CVE-2022-45478

Telepad allows an attacker (in a man-in-the-middle position between the server and a connected device) to see all data (including keypresses) in clea…

Fix: after 1.0.7
Fix from $1,600 2022-12-05
Pc Keyboard Wifi \& Bluetooth MEDIUM 5.9
CVE-2022-45480

PC Keyboard WiFi & Bluetooth allows an attacker (in a man-in-the-middle position between the server and a connected device) to see all data (includin…

Fix: after 30
Fix from $1,600 2022-12-02
Lazy Mouse MEDIUM 5.9
CVE-2022-45483

Lazy Mouse allows an attacker (in a man in the middle position between the server and a connected device) to see all data (including keypresses) in c…

Fix: after 2.0.1
Fix from $1,600 2022-12-02
Web Based Quiz System HIGH 7.5
CVE-2022-44411

Web Based Quiz System v1.0 transmits user passwords in plaintext during the authentication process, allowing attackers to obtain users' passwords via…

No fix yet
Fix from $1,950 2022-11-25
Engineer\'s Toolset MEDIUM 5.3
CVE-2021-35246

The application fails to prevent users from connecting to it over unencrypted connections. An attacker able to modify a legitimate user's network tra…

Patch available
Fix from $1,600 2022-11-23
Concrete Cms MEDIUM 5.3
CVE-2022-43691

Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 inadvertently disclose server-side sensitive information (secrets in envir…

Fix: 8.5.10+
Fix from $1,600 2022-11-14
Xm Jpr2 Lx Firmware MEDIUM 5.3
CVE-2021-38828

Xiongmai Camera XM-JPR2-LX V4.02.R12.A6420987.10002.147502.00000 is vulnerable to plain-text traffic sniffing.

Fix: after 4.02.r12.a6420987.10002.147502.00000
Fix from $1,600 2022-11-14
Upsmon Pro HIGH 7.5
CVE-2022-38122

UPSMON PRO transmits sensitive data in cleartext over HTTP protocol. An unauthenticated remote attacker can exploit this vulnerability to access sens…

Mitigation only
Fix from $1,950 2022-11-10
Mac 557if E Firmware CRITICAL 9.8
CVE-2022-33321

Cleartext Transmission of Sensitive Information vulnerability due to the use of Basic Authentication for HTTP connections in Mitsubishi Electric cons…

Mitigation only
Fix from $2,300 2022-11-08
Vantara Pentaho HIGH 7.5
CVE-2021-45447

Hitachi Vantara Pentaho Business Analytics Server versions before 9.3.0.0, 9.2.0.2 and 8.3.0.25 with the Data Lineage feature enabled transmits data…

Fix: 8.3.0.25 / 9.2.0.2+
Fix from $1,950 2022-11-02
Curl HIGH 7.5
CVE-2022-42916

In curl before 7.86.0, the HSTS check could be bypassed to trick it into staying with HTTP. Using its HSTS support, curl can be instructed to use HTT…

Fix: 7.86.0 / 8.2.12+
Fix from $1,950 2022-10-29
Haas Controller HIGH 7.5
CVE-2022-41636

Communication traffic involving "Ethernet Q Commands" service of Haas Controller version 100.20.000.1110 is transmitted in cleartext. This allows an …

Mitigation only
Fix from $1,950 2022-10-28
Kardiamobile Firmware HIGH 7.6
CVE-2022-41627

The physical IoT device of the AliveCor's KardiaMobile, a smartphone-based personal electrocardiogram (EKG) has no encryption for its data-over-sound…

Mitigation only
Fix from $1,950 2022-10-27
Passster MEDIUM 5.9
CVE-2022-3206

The Passster WordPress plugin before 3.5.5.5.2 stores the password inside a cookie named "passster" using base64 encoding method which is easy to dec…

Fix: 3.5.5.5.2+
Fix from $1,600 2022-10-17
Tiny Csrf MEDIUM 6.5
CVE-2022-39287

tiny-csrf is a Node.js cross site request forgery (CSRF) protection middleware. In versions prior to 1.1.0 cookies were not encrypted and thus CSRF t…

Fix: 1.1.0+
Fix from $1,600 2022-10-07
Pjsip CRITICAL 9.1
CVE-2022-39269

PJSIP is a free and open source multimedia communication library written in C. When processing certain packets, PJSIP may incorrectly switch from usi…

Fix: 2.13+
Fix from $2,300 2022-10-06