Vulnerability index

Browse CVEs

798 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cleartext TransmissionCWE-319 × clear
Rocket.chat MEDIUM 6.5
CVE-2022-32227

A cleartext transmission of sensitive information exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 relating to Oauth tokens by having the permission "v…

Fix: 4.7.5 / 4.8.2+
Fix from $1,600 2022-09-23
Espocrm MEDIUM 5.9
CVE-2022-38846

EspoCRM version 7.1.8 is vulnerable to Missing Secure Flag allowing the browser to send plain text cookies over an insecure channel (HTTP). An attack…

No fix yet
Fix from $1,600 2022-09-16
Trend Iq412 Firmware MEDIUM 6.5
CVE-2022-30312

The Trend Controls IC protocol through 2022-05-06 allows Cleartext Transmission of Sensitive Information. According to FSCT-2022-0050, there is a Tre…

Mitigation only
Fix from $1,600 2022-09-07
Simple Sign On HIGH 7.5
CVE-2022-2083

The Simple Single Sign On WordPress plugin through 4.1.0 leaks its OAuth client_secret, which could be used by attackers to gain unauthorized access …

Fix: after 4.1.0
Fix from $1,950 2022-09-05
D0 06dd1 Firmware CRITICAL 9.1
CVE-2022-2003

AutomationDirect DirectLOGIC is vulnerable to a specifically crafted serial message to the CPU serial port that will cause the PLC to respond with th…

Fix: 2.72+
Fix from $2,300 2022-08-31
C More Ea9 T6cl Firmware HIGH 7.5
CVE-2022-2005

AutomationDirect C-more EA9 HTTP webserver uses an insecure mechanism to transport credentials from client to web server, which may allow an attacker…

Fix: 6.73+
Fix from $1,950 2022-08-31
Sio Mb04rtds Firmware HIGH 7.5
CVE-2022-2485

Any attempt (good or bad) to log into AutomationDirect Stride Field I/O with a web browser may result in the device responding with its password in t…

Fix: 8.0.4.0 / 8.3.4.0+
Fix from $1,950 2022-08-31
Hg150 Ub Firmware HIGH 7.5
CVE-2022-36200

In FiberHome VDSL2 Modem HG150-Ub_V3.0, Credentials of Admin are submitted in URL, which can be logged/sniffed.

No fix yet
Fix from $1,950 2022-08-29
Satellite HIGH 8.8
CVE-2021-3590

A flaw was found in Foreman project. A credential leak was identified which will expose Azure Compute Profile password through JSON of the API output…

Mitigation only
Fix from $1,950 2022-08-22
Edgeaggregator MEDIUM 5.3
CVE-2022-2338

Softing Secure Integration Server V1.22 is vulnerable to authentication bypass via a machine-in-the-middle attack. The default the administration int…

Mitigation only
Fix from $1,600 2022-08-17
Businessobjects Business Intelligence HIGH 8.2
CVE-2022-32245

SAP BusinessObjects Business Intelligence Platform (Open Document) - versions 420, 430, allows an unauthenticated attacker to retrieve sensitive info…

Mitigation only
Fix from $1,950 2022-08-10
Note Station MEDIUM 5.9
CVE-2022-27619

Cleartext transmission of sensitive information vulnerability in authentication management in Synology Note Station Client before 2.2.2-609 allows ma…

Fix: 2.2.2-609+
Fix from $1,600 2022-08-03
Sysmac Cs1 Firmware HIGH 7.5
CVE-2022-31204

Omron CS series, CJ series, and CP series PLCs through 2022-05-18 use cleartext passwords. They feature a UM Protection setting that allows users or …

Fix: 1.5 / 1.10+
Fix from $1,950 2022-07-26
Citilog MEDIUM 5.9
CVE-2022-28861

The server in Citilog 8.0 allows an attacker (in a man in the middle position between the server and its smart camera Axis M1125) to see FTP credenti…

Mitigation only
Fix from $1,600 2022-07-21
Teleopti Workforce Management MEDIUM 6.5
CVE-2017-20109

A vulnerability classified as problematic was found in Teleopti WFM up to 7.1.0. Affected by this vulnerability is an unknown functionality of the fi…

Fix: after 7.1.0
Fix from $1,600 2022-06-29
Stardom Fcj Firmware HIGH 7.5
CVE-2022-29519

Cleartext transmission of sensitive information vulnerability exists in STARDOM FCN Controller and FCJ Controller R1.01 to R4.31, which may allow an …

Mitigation only
Fix from $1,950 2022-06-28
Concrete Cms CRITICAL 9.8
CVE-2022-21829

Concrete CMS Versions 9.0.0 through 9.0.2 and 8.5.7 and below can download zip files over HTTP and execute code from those zip files which could lead…

Fix: 8.5.8 / 9.1.0+
Fix from $2,300 2022-06-24
Local Run Manager MEDIUM 5.9
CVE-2022-1524

LRM version 2.4 and lower does not implement TLS encryption. A malicious actor can MITM attack sensitive data in-transit, including credentials.

Fix: after 3.1
Fix from $1,600 2022-06-24
Atvise MEDIUM 5.9
CVE-2022-21184

An information disclosure vulnerability exists in the License registration functionality of Bachmann Visutec GmbH Atvise 3.5.4, 3.6 and 3.7. A plaint…

Mitigation only
Fix from $1,600 2022-06-17
Universal Management Suite MEDIUM 6.5
CVE-2022-25805

An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. The transmission of cleartext LDAP bind credentials by the cmd_mgt_loa…

No fix yet
Fix from $1,600 2022-06-09
Entelitouch Firmware MEDIUM 5.9
CVE-2022-29733

Delta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 was discovered to transmit and store sensitive information in cleartext. This vulnerab…

No fix yet
Fix from $1,600 2022-06-02
Terminattr MEDIUM 6.1
CVE-2021-28508

This advisory documents the impact of an internally found vulnerability in Arista EOS state streaming telemetry agent TerminAttr and OpenConfig trans…

Fix: 1.10.11 / 1.16.8+
Fix from $1,600 2022-05-26
Terminattr MEDIUM 6.1
CVE-2021-28509

This advisory documents the impact of an internally found vulnerability in Arista EOS state streaming telemetry agent TerminAttr and OpenConfig trans…

Fix: 1.10.11 / 1.16.8+
Fix from $1,600 2022-05-26
Oas Platform HIGH 7.5
CVE-2022-26077

A cleartext transmission of sensitive information vulnerability exists in the OAS Engine configuration communications functionality of Open Automatio…

No fix yet
Fix from $1,950 2022-05-25
Interoperability Solution Xds HIGH 7.5
CVE-2021-32966

Philips Interoperability Solution XDS versions 2.5 through 3.11 and 2018-1 through 2021-1 are vulnerable to clear text transmission of sensitive info…

Fix: after 2021-1
Fix from $1,950 2022-05-25
Rancher MEDIUM 6.8
CVE-2022-21951

A Cleartext Transmission of Sensitive Information vulnerability in SUSE Rancher, Rancher allows attackers on the network to read and change network d…

Fix: 2.5.14 / 2.6.5+
Fix from $1,600 2022-05-25
7kg8500 0aa00 0aa0 Firmware HIGH 8.8
CVE-2022-29874

A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not encrypt web traffic with clients but communicate in cle…

Fix: 3.00+
Fix from $1,950 2022-05-20
Kalay P2p Software Development Kit HIGH 7.5
CVE-2021-32934

The affected ThroughTek P2P products (SDKs using versions before 3.1.5, any versions with nossl tag, device firmware not using AuthKey for IOTC conne…

Fix: after 3.1.5
Fix from $1,950 2022-05-19
Security Identity Manager MEDIUM 5.9
CVE-2020-4970

IBM Security Identity Governance and Intelligence 5.2.4, 5.2.5, and 5.2.6 could allow a remote attacker to obtain sensitive information, caused by th…

Mitigation only
Fix from $1,600 2022-05-19
Cyber Protect HIGH 7.5
CVE-2022-30993

Cleartext transmission of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 29240

Fix: 15+
Fix from $1,950 2022-05-18