Vulnerability index

Browse CVEs

800 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cleartext TransmissionCWE-319 × clear
Ksmbd HIGH 7.5
CVE-2021-45100

The ksmbd server through 3.4.2, as used in the Linux kernel through 5.15.8, sometimes communicates in cleartext even though encryption has been enabl…

Fix: after 3.4.2
Fix from $1,950 2021-12-16
Egeetouch Manager MEDIUM 6.8
CVE-2021-44518

An issue was discovered in the eGeeTouch 3rd Generation Travel Padlock application for Android. The lock sends a pairing code before each operation (…

No fix yet
Fix from $1,600 2021-12-02
Wokka Watch Q50 Firmware HIGH 8.1
CVE-2021-44480

Wokka Lokka Q50 devices through 2021-11-30 allow remote attackers (who know the SIM phone number and password) to listen to a device's surroundings v…

Mitigation only
Fix from $1,950 2021-12-01
Security Guardium Key Lifecycle Manager MEDIUM 5.9
CVE-2021-38978

IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information, caused by the failure to pro…

Fix: after 4.0.0.3
Fix from $1,600 2021-11-15
Halo\+ Camera Firmware MEDIUM 5.3
CVE-2021-3792

Some device communications in some Motorola-branded Binatone Hubble Cameras with backend Hubble services are not encrypted which could lead to the co…

Fix: 03.40.00 / 03.40.02+
Fix from $1,600 2021-11-12
Climatix Pol909 Firmware HIGH 7.4
CVE-2021-40366

A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.42), Climatix POL909 (AWM module) (All versions < V11.34). Th…

Fix: 11.34 / 11.42+
Fix from $1,950 2021-11-09
Qradar Network Security MEDIUM 5.9
CVE-2020-4152

IBM QRadar Network Security 5.4.0 and 5.5.0 transmits sensitive or security-critical data in cleartext in a communication channel that can be obtaine…

Fix: 5.4.0.14 / 5.5.0.9+
Fix from $1,600 2021-11-08
Mss550x Firmware MEDIUM 6.5
CVE-2021-3774

Meross Smart Wi-Fi 2 Way Wall Switch (MSS550X), on its 3.1.3 version and before, creates an open Wi-Fi Access Point without the required security mea…

Fix: after 3.1.3
Fix from $1,600 2021-11-05
Business Automation Workflow MEDIUM 5.9
CVE-2021-29753

IBM Business Automation Workflow 18. 19, 20, 21, and IBM Business Process Manager 8.5 and d8.6 transmits or stores authentication credentials, but it…

Mitigation only
Fix from $1,600 2021-11-05
Daqfactory MEDIUM 5.9
CVE-2021-42699

The affected product is vulnerable to cookie information being transmitted as cleartext over HTTP. An attacker can capture network traffic, obtain th…

Fix: after 18.1
Fix from $1,600 2021-11-05
Dialink MEDIUM 5.9
CVE-2021-38418

Delta Electronics DIALink versions 1.2.4.0 and prior runs by default on HTTP, which may allow an attacker to be positioned between the traffic and pe…

Fix: after 1.2.4.0
Fix from $1,600 2021-11-03
Seq.app.emailplus HIGH 7.5
CVE-2021-43270

Datalust Seq.App.EmailPlus (aka seq-app-htmlemail) 3.1.0-dev-00148, 3.1.0-dev-00170, and 3.1.0-dev-00176 can use cleartext SMTP on port 25 in some ca…

Patch available
Fix from $1,950 2021-11-02
Optinmonster HIGH 8.2
CVE-2021-39341EPSS 22%

The OptinMonster WordPress plugin is vulnerable to sensitive information disclosure and unauthorized setting updates due to insufficient authorizatio…

Fix: after 2.6.4
Fix from $1,950 2021-11-01
Ctpview HIGH 7.4
CVE-2021-0296

The Juniper Networks CTPView server is not enforcing HTTP Strict Transport Security (HSTS). HSTS is an optional response header which allows servers …

Mitigation only
Fix from $1,950 2021-10-19
R08sfcpu Firmware HIGH 7.5
CVE-2021-20599

Cleartext Transmission of Sensitive InformationCleartext transmission of sensitive information vulnerability in MELSEC iQ-R series Safety CPU R08/16/…

Mitigation only
Fix from $1,950 2021-10-14
GitLab MEDIUM 5.3
CVE-2021-39882

In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user.

Fix: 14.1.7 / 14.2.5+
Fix from $1,600 2021-10-05
Laracms HIGH 7.5
CVE-2020-20128

LaraCMS v1.0.1 transmits sensitive information in cleartext which can be intercepted by attackers.

No fix yet
Fix from $1,950 2021-09-29
Curl HIGH 7.5
CVE-2021-22946

A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the…

Fix: 7.79.0+
Fix from $1,950 2021-09-29
Financial HIGH 7.5
CVE-2021-39342

The Credova_Financial WordPress plugin discloses a site's associated Credova API account username and password in plaintext via an AJAX action whenev…

Fix: 1.4.9+
Fix from $1,950 2021-09-29
S9922l Firmware MEDIUM 5.3
CVE-2021-36165

RICON Industrial Cellular Router S9922L 16.10.3(3794) is affected by cleartext storage of sensitive information and sends username and password as ba…

No fix yet
Fix from $1,600 2021-09-28
R6400v2 Firmware HIGH 8.1
CVE-2021-40847EPSS 10%

The update process of the Circle Parental Control Service on various NETGEAR routers allows remote attackers to achieve remote code execution as root…

No fix yet
Fix from $1,950 2021-09-21
Mirrorop Windows Sender HIGH 8.8
CVE-2021-38142

Barco MirrorOp Windows Sender before 2.5.3.65 uses cleartext HTTP and thus allows rogue software upgrades. An attacker on the local network can achie…

Fix: 2.5.3.65+
Fix from $1,950 2021-09-07
Fedora MEDIUM 5.9
CVE-2021-39272

Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances, such as a certain situation with IMAP and PREAUTH.

Fix: 6.4.22+
Fix from $1,600 2021-08-30
Spacecom2 HIGH 7.5
CVE-2021-33883

A Cleartext Transmission of Sensitive Information vulnerability in B. Braun SpaceCom2 prior to 012U000062 allows a remote attacker to obtain sensitiv…

Fix: 012u000062+
Fix from $1,950 2021-08-25
Kmail MEDIUM 5.3
CVE-2021-38373

In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Server requires authentication" …

Mitigation only
Fix from $1,600 2021-08-10
Curl MEDIUM 5.3
CVE-2021-22923

When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink XML file, those sam…

Fix: 1.0.1.1 / 7.78.0+
Fix from $1,600 2021-08-05
Directory Studio HIGH 7.5
CVE-2021-33900

While investigating DIRSTUDIO-1219 it was noticed that configured StartTLS encryption was not applied when any SASL authentication mechanism (DIGEST-…

Fix: after 1.5.3
Fix from $1,950 2021-07-26
Debian Linux HIGH 7.5
CVE-2020-36423

An issue was discovered in Arm Mbed TLS before 2.23.0. A remote attacker can recover plaintext because a certain Lucky 13 countermeasure doesn't prop…

Fix: 2.16.7 / 2.23.0+
Fix from $1,950 2021-07-19
Qradar Security Information And Event Manager MEDIUM 6.5
CVE-2020-4980

IBM QRadar SIEM 7.3 and 7.4 uses less secure methods for protecting data in transit between hosts when encrypt host connections is not enabled as wel…

Fix: 7.3.3 / 7.4.3+
Fix from $1,600 2021-07-16
Flamingo 2 Firmware MEDIUM 5.3
CVE-2020-12730

MagicMotion Flamingo 2 lacks BLE encryption, enabling data sniffing and packet forgery.

Mitigation only
Fix from $1,600 2021-07-15