Vulnerability index

Browse CVEs

800 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cleartext TransmissionCWE-319 × clear
Siveillance Video Client MEDIUM 5.3
CVE-2020-15785

A vulnerability has been identified in Siveillance Video Client (All versions). In environments where Windows NTLM authentication is enabled the affe…

Mitigation only
Fix from $1,600 2020-09-09
Linux Kernel HIGH 7.5
CVE-2020-1749

A flaw was found in the Linux kernel's implementation of some networking protocols in IPsec, such as VXLAN and GENEVE tunnels over IPv6. When an encr…

Patch available
Fix from $1,950 2020-09-09
Debian Linux MEDIUM 6.5
CVE-2020-3702

u'Specifically timed and handcrafted traffic can cause internal errors in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequ…

Mitigation only
Fix from $1,600 2020-09-08
Guardium Data Encryption HIGH 7.5
CVE-2019-4689

IBM Security Guardium Data Encryption (GDE) 3.0.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly …

Fix: 1.7.0 / 4.0.0.3+
Fix from $1,950 2020-08-26
M1000 Multipara Patient Monitor Firmware HIGH 7.8
CVE-2020-15482

An issue was discovered on Nescomed Multipara Monitor M1000 devices. The device enables an unencrypted TELNET service by default, with a blank passwo…

Mitigation only
Fix from $1,950 2020-08-26
Aptra Xfs HIGH 7.1
CVE-2020-10124

NCR SelfServ ATMs running APTRA XFS 05.01.00 do not encrypt, authenticate, or verify the integrity of messages between the BNA and the host computer,…

Mitigation only
Fix from $1,950 2020-08-21
Email Extension HIGH 7.5
CVE-2020-2232

Jenkins Email Extension Plugin 2.72 and 2.73 transmits and displays the SMTP password in plain text as part of the global Jenkins configuration form,…

Mitigation only
Fix from $1,950 2020-08-12
P2p MEDIUM 5.9
CVE-2020-9526

CS2 Network P2P through 3.x, as used in millions of Internet of Things devices, suffers from an information exposure flaw that exposes user session d…

Fix: after 3.0.3a
Fix from $1,600 2020-08-10
42633 Firmware HIGH 8.8
CVE-2020-15058

Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to elevate privileges because the administr…

Mitigation only
Fix from $1,950 2020-08-07
Da 70254 Firmware HIGH 8.8
CVE-2020-15062

DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to elevate privileges because the administr…

Mitigation only
Fix from $1,950 2020-08-07
Tl Ps310u Firmware HIGH 8.8
CVE-2020-15054

TP-Link USB Network Server TL-PS310U devices before 2.079.000.t0210 allow an attacker on the same network to elevate privileges because the administr…

Fix: 2.079.000.t0210+
Fix from $1,950 2020-08-07
Debian Linux MEDIUM 6.5
CVE-2020-15954

KDE KMail 19.12.3 (aka 5.13.3) engages in unencrypted POP3 communication during times when the UI indicates that encryption is in use.

Mitigation only
Fix from $1,600 2020-07-27
Esp Idf MEDIUM 6.8
CVE-2020-12638

An encryption-bypass issue was discovered on Espressif ESP-IDF devices through 4.2, ESP8266_NONOS_SDK devices through 3.0.3, and ESP8266_RTOS_SDK dev…

Fix: after 4.2
Fix from $1,600 2020-07-23
Verify Gateway MEDIUM 5.9
CVE-2020-4397

IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 transmits sensitive information in plain text which could be obtained by an attacker using man in the middle…

Patch available
Fix from $1,600 2020-07-22
Duoconnect MEDIUM 5.7
CVE-2020-3442

The DuoConnect client enables users to establish SSH connections to hosts protected by a DNG instance. When a user initiates an SSH connection to a D…

Fix: 1.1.1+
Fix from $1,600 2020-07-20
Simatic Hmi Basic Panels 1st Generation MEDIUM 6.5
CVE-2020-7592

A vulnerability has been identified in SIMATIC HMI Basic Panels 1st Generation (incl. SIPLUS variants) (All versions), SIMATIC HMI Basic Panels 2nd G…

Mitigation only
Fix from $1,600 2020-07-14
Bitbucket MEDIUM 6.5
CVE-2020-14171

Atlassian Bitbucket Server from version 4.9.0 before version 7.2.4 allows remote attackers to intercept unencrypted repository import requests via a …

Fix: 7.2.4+
Fix from $1,600 2020-07-09
Ubuntu Linux HIGH 7.5
CVE-2020-12398

If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH response, then Thunderbird will continue with an unen…

Fix: 68.9.0+
Fix from $1,950 2020-07-09
Android Ble Library MEDIUM 6.5
CVE-2020-15509

Nordic Semiconductor Android BLE Library through 2.2.1 and DFU Library through 1.10.4 for Android (as used by nRF Connect and other applications) can…

Fix: after 2.2.1
Fix from $1,600 2020-07-07
Micro Air Vehicle Link HIGH 7.5
CVE-2020-10281

This vulnerability applies to the Micro Air Vehicle Link (MAVLink) protocol and allows a remote attacker to gain access to sensitive information prov…

Mitigation only
Fix from $1,950 2020-07-03
Nginx Controller HIGH 7.8
CVE-2020-5899

In NGINX Controller 3.0.0-3.4.0, recovery code required to change a user's password is transmitted and stored in the database in plain text, which al…

Fix: after 3.4.0
Fix from $1,950 2020-07-01
Prismaflex Firmware HIGH 7.5
CVE-2020-12036

Baxter PrismaFlex all versions, PrisMax all versions prior to 3.x, The affected devices do not implement data-in-transit encryption (e.g., TLS/SSL) w…

Fix: 3.0+
Fix from $1,950 2020-06-29
Prismaflex Firmware HIGH 7.5
CVE-2020-12037

Baxter PrismaFlex all versions, PrisMax all versions prior to 3.x, The affected devices do not implement data-in-transit encryption (e.g., TLS/SSL) w…

Fix: 3.0+
Fix from $1,950 2020-06-29
Sigma Spectrum Infusion System Firmware CRITICAL 9.8
CVE-2020-12040

Sigma Spectrum Infusion System v's6.x (model 35700BAX) and Baxter Spectrum Infusion System Version(s) 8.x (model 35700BAX2) at the application layer …

Fix: after 6.05
Fix from $2,300 2020-06-29
Phoenix X36 Firmware HIGH 7.5
CVE-2020-12048

Phoenix Hemodialysis Delivery System SW 3.36 and 3.40, The Phoenix Hemodialysis device does not support data-in-transit encryption (e.g., TLS/SSL) wh…

Mitigation only
Fix from $1,950 2020-06-29
Em2400 Firmware HIGH 7.5
CVE-2020-12008

Baxter ExactaMix EM 2400 Versions 1.10, 1.11 and ExactaMix EM1200 Versions 1.1, 1.2 systems use cleartext messages to communicate order information w…

Mitigation only
Fix from $1,950 2020-06-29
Controledge Plc Firmware HIGH 7.5
CVE-2020-10628

ControlEdge PLC (R130.2, R140, R150, and R151) and RTU (R101, R110, R140, R150, and R151) exposes unencrypted passwords on the network.

Mitigation only
Fix from $1,950 2020-06-26
Controledge Plc Firmware HIGH 7.5
CVE-2020-10624

ControlEdge PLC (R130.2, R140, R150, and R151) and RTU (R101, R110, R140, R150, and R151) exposes a session token on the network.

Mitigation only
Fix from $1,950 2020-06-26
Melsec Iq R Firmware CRITICAL 9.8
CVE-2020-5594

Mitsubishi Electric MELSEC iQ-R, iQ-F, Q, L, and FX series CPU modules all versions contain a vulnerability that allows cleartext transmission of sen…

Mitigation only
Fix from $2,300 2020-06-23
Bt Ctroms Terminal HIGH 8.1
CVE-2020-14930

An issue was discovered in BT CTROMS Terminal OS Port Portal CT-464. Account takeover can occur because the password-reset feature discloses the veri…

No fix yet
Fix from $1,950 2020-06-19