Vulnerability index

Browse CVEs

800 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cleartext TransmissionCWE-319 × clear
Emui CRITICAL 9.1
CVE-2021-22380

There is a Cleartext Transmission of Sensitive Information Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affe…

Mitigation only
Fix from $2,300 2021-06-30
B426 Firmware MEDIUM 5.9
CVE-2021-23846

When using http protocol, the user password is transmitted as a clear text parameter for which it is possible to be obtained by an attacker through a…

Mitigation only
Fix from $1,600 2021-06-18
Fedora HIGH 7.5
CVE-2021-34825

Quassel through 0.13.1, when --require-ssl is enabled, launches without SSL or TLS support if a usable X.509 certificate is not found on the local sy…

Fix: after 0.13.1
Fix from $1,950 2021-06-17
Veryfitpro HIGH 8.1
CVE-2021-32612

The VeryFitPro (com.veryfit2hr.second) application 3.2.8 for Android does all communication with the backend API over cleartext HTTP. This includes l…

No fix yet
Fix from $1,950 2021-06-16
Emui MEDIUM 5.3
CVE-2021-22325

There is an Information Disclosure vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may result in video streams bein…

Mitigation only
Fix from $1,600 2021-06-03
Nginx Controller HIGH 7.4
CVE-2021-23018

Intra-cluster communication does not use TLS. The services within the NGINX Controller 3.x before 3.4.0 namespace are using cleartext protocols insid…

Fix: after 3.4.0
Fix from $1,950 2021-06-01
Control\>center MEDIUM 6.5
CVE-2021-33408

Local File Inclusion vulnerability in Ab Initio Control>Center before 4.0.2.6 allows remote attackers to retrieve arbitrary files. Fixed in v4.0.2.6 …

Fix: 4.0.2.6 / 4.0.3.1+
Fix from $1,600 2021-05-27
Couchbase Server MEDIUM 5.9
CVE-2021-27924

An issue was discovered in Couchbase Server 6.x through 6.6.1. The Couchbase Server UI is insecurely logging session cookies in the logs. This allows…

Fix: 6.6.2+
Fix from $1,600 2021-05-19
Remote Cap\/prx Firmware MEDIUM 6.5
CVE-2021-32456

SITEL CAP/PRX firmware version 5.2.01 allows an attacker with access to the local network of the device to obtain the authentication passwords by ana…

Mitigation only
Fix from $1,600 2021-05-17
Cloud Pak For Security MEDIUM 5.9
CVE-2021-20564

IBM Cloud Pak for Security (CP4S) 1.4.0.0, 1.5.0.0, 1.5.0.1, 1.6.0.0, and 1.6.0.1 could allow a remote attacker to obtain sensitive information, caus…

Mitigation only
Fix from $1,600 2021-05-14
Nport Ia5150a Firmware MEDIUM 5.9
CVE-2020-27184

The NPort IA5000A Series devices use Telnet as one of the network device management services. Telnet does not support the encryption of client-server…

Fix: after 1.7
Fix from $1,600 2021-05-14
Nport Ia5150a Firmware HIGH 7.5
CVE-2020-27185

Cleartext transmission of sensitive information via Moxa Service in NPort IA5000A series serial devices. Successfully exploiting the vulnerability co…

Fix: after 1.7
Fix from $1,950 2021-05-14
Webstorm HIGH 7.5
CVE-2021-31898

In JetBrains WebStorm before 2021.1, HTTP requests were used instead of HTTPS.

Fix: 2021.1+
Fix from $1,950 2021-05-11
Desktop Telematico MEDIUM 5.3
CVE-2021-3003

Agenzia delle Entrate Desktop Telematico 1.0.0 contacts the jws.agenziaentrate.it server over cleartext HTTP, which allows man-in-the-middle attacker…

No fix yet
Fix from $1,600 2021-05-10
Emote Remote Mouse MEDIUM 5.3
CVE-2021-27569

An issue was discovered in Emote Remote Mouse through 4.0.0.0. Attackers can maximize or minimize the window of a running process by sending the proc…

Fix: after 4.0.0.0
Fix from $1,600 2021-05-07
Emote Remote Mouse HIGH 8.1
CVE-2021-27574

An issue was discovered in Emote Remote Mouse through 4.0.0.0. It uses cleartext HTTP to check, and request, updates. Thus, attackers can machine-in-…

Fix: after 4.0.0.0
Fix from $1,950 2021-05-07
Pgsync HIGH 7.5
CVE-2021-31671

pgsync before 0.6.7 is affected by Information Disclosure of sensitive information. Syncing the schema with the --schema-first and --schema-only opti…

Fix: 0.6.7+
Fix from $1,950 2021-04-27
Foreman MEDIUM 5.9
CVE-2021-3494

A smart proxy that provides a restful API to various sub-systems of the Foreman is affected by the flaw which can cause a Man-in-the-Middle attack. T…

Fix: 2.5.0+
Fix from $1,600 2021-04-26
Emc Powerscale Onefs CRITICAL 9.1
CVE-2020-26197

Dell PowerScale OneFS 8.1.0 - 9.1.0 contains an LDAP Provider inability to connect over TLSv1.2 vulnerability. It may make it easier to eavesdrop and…

Mitigation only
Fix from $2,300 2021-04-20
Home Center 2 Firmware HIGH 7.5
CVE-2021-20992

In Fibaro Home Center 2 and Lite devices in all versions provide a web based management interface over unencrypted HTTP protocol. Communication betwe…

No fix yet
Fix from $1,950 2021-04-19
Endpoint Security MEDIUM 6.5
CVE-2020-7308

Cleartext Transmission of Sensitive Information between McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update and McAfee Gl…

Fix: after 10.6.1
Fix from $1,600 2021-04-15
Br200 Firmware HIGH 8.8
CVE-2021-27251

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR Nighthawk R7800. Authentication i…

Fix: 1.0.0.134 / 1.0.1.60+
Fix from $1,950 2021-04-14
Vision Pro HIGH 8.8
CVE-2021-27194

Cleartext transmission of sensitive information in Netop Vision Pro up to and including 9.7.1 allows a remote unauthenticated attacker to gather cred…

Fix: after 9.7.1
Fix from $1,950 2021-03-25
Wrongthink HIGH 7.5
CVE-2021-21387

Wrongthink peer-to-peer, end-to-end encrypted messenger with PeerJS and Axolotl ratchet. In wrongthink from version 2.0.0 and before 2.3.0 there was …

Fix: 2.3.0+
Fix from $1,950 2021-03-19
Spectre Rt Ert351 Firmware HIGH 7.5
CVE-2019-18231

Advantech Spectre RT ERT351 Versions 5.1.3 and prior logins and passwords are transmitted in clear text form, which may allow an attacker to intercep…

Fix: after 5.1.3
Fix from $1,950 2021-03-17
Diibear MEDIUM 5.5
CVE-2020-35456

The Taidii Diibear Android application 2.4.0 and all its derivatives allow attackers to view private chat messages and media files via logcat because…

Mitigation only
Fix from $1,600 2021-03-17
Api Connect HIGH 7.5
CVE-2020-4695

IBM API Connect V10 is impacted by insecure communications during database replication. As the data replication happens over insecure communication c…

Fix: after 10.0.1.0
Fix from $1,950 2021-03-08
Diskstation Manager HIGH 8.7
CVE-2021-26564

Cleartext transmission of sensitive information vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-…

Fix: 6.2.3-25426-3+
Fix from $1,950 2021-02-26
Diskstation Manager MEDIUM 5.9
CVE-2021-26565

Cleartext transmission of sensitive information vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-…

Fix: 6.2.3-25426-3+
Fix from $1,600 2021-02-26
Diskstation Manager HIGH 7.4
CVE-2021-26560

Cleartext transmission of sensitive information vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows…

Fix: 6.2.3-25426-3+
Fix from $1,950 2021-02-26