Vulnerability index

Browse CVEs

798 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cleartext TransmissionCWE-319 × clear
Cyber Protect HIGH 7.5
CVE-2022-30994

Cleartext transmission of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 29240

Fix: 15+
Fix from $1,950 2022-05-18
Mavic 3 Firmware HIGH 7.5
CVE-2022-29945

DJI drone devices sold in 2017 through 2022 broadcast unencrypted information about the drone operator's physical location via the AeroScope protocol.

Mitigation only
Fix from $1,950 2022-04-29
Mxview HIGH 7.5
CVE-2021-40392

An information disclosure vulnerability exists in the Web Application functionality of Moxa MXView Series 3.2.4. Network sniffing can lead to a discl…

No fix yet
Fix from $1,950 2022-04-14
Htcondor HIGH 7.4
CVE-2021-45104

An issue was discovered in HTCondor 9.0.x before 9.0.10 and 9.1.x before 9.5.1. An attacker who can capture HTCondor network data can interfere with …

Fix: 9.0.10 / 9.6.0+
Fix from $1,950 2022-04-06
Manageengine Adaudit Plus HIGH 8.8
CVE-2022-24978

Zoho ManageEngine ADAudit Plus before 7055 allows authenticated Privilege Escalation on Integrated products. This occurs because a password field is …

Fix: after 6.0
Fix from $1,950 2022-04-05
Arc MEDIUM 5.9
CVE-2021-45894

An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4. There is Cleartext Transmission of Sensitive Information.

No fix yet
Fix from $1,600 2022-04-05
C0 10dd1e D Firmware HIGH 7.5
CVE-2021-32982

Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 passwords are sent as plaintext during unlocking and project transfe…

Fix: 3.00+
Fix from $1,950 2022-04-04
Myvue HIGH 7.5
CVE-2021-33022

Philips Vue PACS versions 12.2.x.x and prior transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffe…

Fix: 12.2.1.5 / 12.2.8.0+
Fix from $1,950 2022-04-01
Iss Blackice Pc Protection MEDIUM 5.3
CVE-2003-5002

A vulnerability was found in ISS BlackICE PC Protection. It has been declared as problematic. Affected by this vulnerability is the component Update …

Mitigation only
Fix from $1,600 2022-03-28
Diaenergie HIGH 7.5
CVE-2022-0988

Delta Electronics DIAEnergie (Version 1.7.5 and prior) is vulnerable to cleartext transmission as the web application runs by default on HTTP. This c…

Fix: after 1.7.5
Fix from $1,950 2022-03-25
Multilin B30 Firmware HIGH 7.5
CVE-2021-27422

GE UR firmware versions prior to version 8.1x web server interface is supported on UR over HTTP protocol. It allows sensitive information exposure wi…

Fix: 8.10+
Fix from $1,950 2022-03-23
Epas Gtw Firmware HIGH 8.8
CVE-2020-25178

ISaGRAF Workbench communicates with Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x using TCP/IP. This communication protocol provides vario…

Fix: 1.1.0+
Fix from $1,950 2022-03-18
G90 Firmware MEDIUM 5.5
CVE-2021-41849

An issue was discovered in Luna Simo PPR1.180610.011/202001031830. It sends the following Personally Identifiable Information (PII) in plaintext usin…

No fix yet
Fix from $1,600 2022-03-11
Trading Paints HIGH 7.5
CVE-2021-40846

An issue was discovered in Rhinode Trading Paints through 2.0.36. TP Updater.exe uses cleartext HTTP to check, and request, updates. Thus, attackers …

Fix: after 2.0.36
Fix from $1,950 2022-03-04
Cimplicity CRITICAL 9.8
CVE-2022-21798

The affected product is vulnerable due to cleartext transmission of credentials seen in the CIMPLICITY network, which can be easily spoofed and used …

Mitigation only
Fix from $2,300 2022-02-25
Cobbler MEDIUM 5.9
CVE-2021-45081

An issue was discovered in Cobbler through 3.3.1. Routines in several files use the HTTP protocol instead of the more secure HTTPS.

Fix: after 3.3.1
Fix from $1,600 2022-02-20
Guardium Data Encryption MEDIUM 5.9
CVE-2021-39026

IBM Guardium Data Encryption (GDE) 5.0.0.2 and 5.0.0.3 could allow a remote attacker to obtain sensitive information, caused by the failure to proper…

Patch available
Fix from $1,600 2022-02-18
Tl Wr841n Firmware CRITICAL 9.8
CVE-2022-0162

The vulnerability exists in TP-Link TL-WR841N V11 3.16.9 Build 160325 Rel.62500n wireless router due to transmission of authentication information in…

Mitigation only
Fix from $2,300 2022-02-09
Northstar Club Management HIGH 7.5
CVE-2021-29397

Cleartext Transmission of Sensitive Information in /northstar/Admin/login.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remo…

Mitigation only
Fix from $1,950 2022-02-04
X5000r Firmware HIGH 7.5
CVE-2021-45735

TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to use the HTTP protocol for authentication into the admin interface, allowing attackers to int…

No fix yet
Fix from $1,950 2022-02-04
Agilia Partner Maintenance Software HIGH 7.5
CVE-2021-41835

Fresenius Kabi Agilia Link + version 3.0 does not enforce transport layer encryption. Therefore, transmitted data may be sent in cleartext. Transport…

Fix: 3.0+
Fix from $1,950 2022-01-21
Active Directory MEDIUM 6.5
CVE-2022-23105

Jenkins Active Directory Plugin 2.25 and earlier does not encrypt the transmission of data between the Jenkins controller and Active Directory server…

Fix: after 2.25
Fix from $1,600 2022-01-12
L9 HIGH 7.5
CVE-2021-40148

In Modem EMM, there is a possible information disclosure due to a missing data encryption. This could lead to remote information disclosure with no a…

Mitigation only
Fix from $1,950 2022-01-04
Rax43 Firmware MEDIUM 6.8
CVE-2021-20169

Netgear RAX43 version 1.0.3.96 does not utilize secure communications to the web interface. By default, all communication to/from the device is sent …

Mitigation only
Fix from $1,600 2021-12-30
R6700 Firmware HIGH 7.5
CVE-2021-20174

Netgear Nighthawk R6700 version 1.0.4.120 does not utilize secure communication methods to the web interface. By default, all communication to/from t…

Mitigation only
Fix from $1,950 2021-12-30
R6700 Firmware HIGH 7.5
CVE-2021-20175

Netgear Nighthawk R6700 version 1.0.4.120 does not utilize secure communication methods to the SOAP interface. By default, all communication to/from …

Mitigation only
Fix from $1,950 2021-12-30
Tew 827dru Firmware HIGH 7.5
CVE-2021-20154

Trendnet AC2600 TEW-827DRU version 2.08B01 contains an security flaw in the web interface. HTTPS is not enabled on the device by default. This result…

Mitigation only
Fix from $1,950 2021-12-30
Mgate Mb3180 Firmware HIGH 7.5
CVE-2021-4161

The affected products contain vulnerable firmware, which could allow an attacker to sniff the traffic and decrypt login credential details. This coul…

Fix: after 4.1
Fix from $1,950 2021-12-27
Ksmbd HIGH 7.5
CVE-2021-45100

The ksmbd server through 3.4.2, as used in the Linux kernel through 5.15.8, sometimes communicates in cleartext even though encryption has been enabl…

Fix: after 3.4.2
Fix from $1,950 2021-12-16
Egeetouch Manager MEDIUM 6.8
CVE-2021-44518

An issue was discovered in the eGeeTouch 3rd Generation Travel Padlock application for Android. The lock sends a pairing code before each operation (…

No fix yet
Fix from $1,600 2021-12-02