Vulnerability index

Browse CVEs

800 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cleartext TransmissionCWE-319 × clear
Powerlogic Ion7400 Firmware HIGH 7.5
CVE-2021-22702

A CWE-319: Cleartext transmission of sensitive information vulnerability exists in PowerLogic ION7400, ION7650, ION7700/73xx, ION83xx/84xx/85xx/8600,…

Fix: 3.0.0+
Fix from $1,950 2021-02-19
Powerlogic Ion7400 Firmware HIGH 7.5
CVE-2021-22703

A CWE-319: Cleartext transmission of sensitive information vulnerability exists in PowerLogic ION7400, ION7650, ION83xx/84xx/85xx/8600, ION8650, ION8…

Fix: 3.0.0+
Fix from $1,950 2021-02-19
Video Software Development Kit MEDIUM 5.9
CVE-2020-25605EPSS 6%

Cleartext transmission of sensitive information in Agora Video SDK prior to 3.1 allows a remote attacker to obtain access to audio and video of any o…

Fix: 3.1+
Fix from $1,600 2021-02-17
Archer C5v Firmware HIGH 7.1
CVE-2021-27209

In the management interface on TP-Link Archer C5v 1.7_181221 devices, credentials are sent in a base64 format over cleartext HTTP.

No fix yet
Fix from $1,950 2021-02-13
Security Verify Information Queue HIGH 7.5
CVE-2021-20409

IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a remote attacker to obtain sensitive information, caused by the failure to properl…

Patch available
Fix from $1,950 2021-02-12
Video Insight Vms CRITICAL 9.8
CVE-2021-20623

Video Insight VMS versions prior to 7.8 allows a remote attacker to execute arbitrary code with the system user privilege by sending a specially craf…

Fix: 7.8+
Fix from $2,300 2021-02-05
Harbor MEDIUM 5.3
CVE-2020-29662

In Harbor 2.0 before 2.0.5 and 2.1.x before 2.1.2 the catalog’s registry API is exposed on an unauthenticated path.

Fix: 2.0.5 / 2.1.2+
Fix from $1,600 2021-02-02
Mediawiki HIGH 7.5
CVE-2020-29005

The API in the Push extension for MediaWiki through 1.35 used cleartext for ApiPush credentials, allowing for potential information disclosure.

Fix: after 1.35
Fix from $1,950 2021-01-29
Rln8 410 Firmware HIGH 7.5
CVE-2020-25169

The affected Reolink P2P products do not sufficiently protect data transferred between the local device and Reolink servers. This can allow an attack…

Mitigation only
Fix from $1,950 2021-01-26
Octopusdsc MEDIUM 5.5
CVE-2021-21270

OctopusDSC is a PowerShell module with DSC resources that can be used to install and configure an Octopus Deploy Server and Tentacle agent. In Octopu…

Fix: 4.0.1002+
Fix from $1,600 2021-01-22
Security Identity Governance And Intelligence MEDIUM 5.9
CVE-2020-4969

IBM Security Identity Governance and Intelligence 5.2.6 could allow a remote attacker to obtain sensitive information, caused by the failure to prope…

Patch available
Fix from $1,600 2021-01-21
Emptoris Strategic Supply Management MEDIUM 5.9
CVE-2020-4893

IBM Emptoris Strategic Supply Management 10.1.0, 10.1.1, and 10.1.3 transmits sensitive information in HTTP GET request parameters. This may lead to …

Fix: 10.1.0.38 / 10.1.1.35+
Fix from $1,600 2021-01-07
Api Connect CRITICAL 9.1
CVE-2020-4899

IBM API Connect 5.0.0.0 through 5.0.8.10 could potentially leak sensitive information or allow for data corruption due to plain text transmission of …

Fix: after 5.0.8.10
Fix from $2,300 2021-01-05
Qts HIGH 7.5
CVE-2018-19944

A cleartext transmission of sensitive information vulnerability has been reported to affect certain QTS devices. If exploited, this vulnerability all…

Fix: 4.4.3.1354+
Fix from $1,950 2020-12-31
Bilanc HIGH 7.4
CVE-2020-11718

An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and below. Its software-update packages are downloaded via cleartext HTTP.

Fix: after 014_31.01.2020
Fix from $1,950 2020-12-23
Solstice Pod Firmware MEDIUM 5.9
CVE-2020-35584

In Solstice Pod before 3.0.3, the web services allow users to connect to them over unencrypted channels via the Browser Look-in feature. An attacker …

Fix: 3.0.3+
Fix from $1,600 2020-12-23
Nport Iaw5000a I\/o Firmware CRITICAL 9.8
CVE-2020-25190

The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower stores and transmits the credentials of third-party services in cle…

Fix: after 2.1
Fix from $2,300 2020-12-23
Xport Edge Firmware MEDIUM 5.3
CVE-2020-13528

An information disclosure vulnerability exists in the Web Manager and telnet CLI functionality of Lantronix XPort EDGE 3.0.0.0R11, 3.1.0.0R9, 3.4.0.0…

Mitigation only
Fix from $1,600 2020-12-18
Bigfix Platform MEDIUM 5.3
CVE-2020-14248

BigFix Inventory up to v10.0.2 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http…

Fix: after 10.0.2
Fix from $1,600 2020-12-16
Total Security MEDIUM 5.9
CVE-2020-27586

Quick Heal Total Security before version 19.0 transmits quarantine and sysinfo files via clear text.

Fix: 19.00+
Fix from $1,600 2020-11-30
V1600d Firmware MEDIUM 5.9
CVE-2020-29380

An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4…

Mitigation only
Fix from $1,600 2020-11-29
72408a Firmware MEDIUM 5.9
CVE-2020-29055

An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B,…

No fix yet
Fix from $1,600 2020-11-24
Platinum 4410 Firmware MEDIUM 6.5
CVE-2020-25988

UPNP Service listening on port 5555 in Genexis Platinum 4410 Router V2.1 (P4410-V2–1.34H) has an action 'X_GetAccess' which leaks the credentials of …

No fix yet
Fix from $1,600 2020-11-17
Ge 131 Bt 1837836 Firmware HIGH 7.5
CVE-2020-27554

Cleartext Transmission of Sensitive Information vulnerability in BASETech GE-131 BT-1837836 firmware 20180921 exists which could leak sensitive infor…

No fix yet
Fix from $1,950 2020-11-17
Nio 50 Firmware HIGH 7.5
CVE-2020-25155

The affected product transmits unencrypted sensitive information, which may allow an attacker to access this information on the NIO 50 (all versions).

Mitigation only
Fix from $1,950 2020-11-13
Pivotal Scheduler CRITICAL 9.8
CVE-2020-5426

Scheduler for TAS prior to version 1.4.0 was permitting plaintext transmission of UAA client token by sending it over a non-TLS connection. This also…

Fix: 1.4.0+
Fix from $2,300 2020-11-11
Router Manager MEDIUM 5.9
CVE-2020-27657

Cleartext transmission of sensitive information vulnerability in DDNS in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle att…

Fix: 1.2.4-8081+
Fix from $1,600 2020-10-29
Linux Kernel HIGH 7.5
CVE-2020-25645

A flaw was found in the Linux kernel in versions before 5.9-rc7. Traffic between two Geneve endpoints may be unencrypted when IPsec is configured to …

Fix: 5.9.0+
Fix from $1,950 2020-10-13
Whatsapp HIGH 7.5
CVE-2020-1902

A user running a quick search on a highly forwarded message on WhatsApp for Android from v2.20.108 to v2.20.140 or WhatsApp Business for Android from…

Fix: after 2.20.140
Fix from $1,950 2020-10-06
Rv 3406 Firmware HIGH 8.1
CVE-2020-25748

A Cleartext Transmission issue was discovered on Rubetek RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339). Someone in the middle …

Mitigation only
Fix from $1,950 2020-09-25