Vulnerability index

Browse CVEs

800 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cleartext TransmissionCWE-319 × clear
Secvest Wireless Control Fube50001 Firmware HIGH 8.1
CVE-2020-14157

The wireless-communication feature of the ABUS Secvest FUBE50001 device does not encrypt sensitive data such as PIN codes or IDs of used proximity ch…

No fix yet
Fix from $1,950 2020-06-17
Ubuntu Linux MEDIUM 5.9
CVE-2020-14093

Mutt before 1.14.3 allows an IMAP fcc/postpone man-in-the-middle attack via a PREAUTH response.

Fix: 1.14.3+
Fix from $1,600 2020-06-15
Mids\' Reborn Hero Designer HIGH 8.1
CVE-2020-11614

Mids' Reborn Hero Designer 2.6.0.7 downloads the update manifest, as well as update files, over cleartext HTTP. Additionally, the application does no…

No fix yet
Fix from $1,950 2020-06-11
Visual Studio Live Share MEDIUM 5.9
CVE-2020-1343

An information disclosure vulnerability exists in Visual Studio Code Live Share Extension when it exposes tokens in plain text, aka 'Visual Studio Co…

Patch available
Fix from $1,600 2020-06-09
Dir 865l Firmware HIGH 7.5
CVE-2020-13787

D-Link DIR-865L Ax 1.20B01 Beta devices have Cleartext Transmission of Sensitive Information.

No fix yet
Fix from $1,950 2020-06-03
Pan Os HIGH 8.8
CVE-2020-2013

A cleartext transmission of sensitive information vulnerability in Palo Alto Networks PAN-OS Panorama that discloses an authenticated PAN-OS administ…

Fix: 8.1.13 / 9.0.6+
Fix from $1,950 2020-05-13
Urbancode Deploy MEDIUM 5.9
CVE-2019-4667

IBM UrbanCode Deploy (UCD) 7.0.5.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Stric…

Mitigation only
Fix from $1,600 2020-05-11
Hcl Nomad MEDIUM 5.3
CVE-2020-4092

"If port encryption is not enabled on the Domino Server, HCL Nomad on Android and iOS Platforms will communicate in clear text and does not currently…

Mitigation only
Fix from $1,600 2020-05-06
Big Ip Access Policy Manager CRITICAL 9.1
CVE-2020-5885

On versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, and 12.1.0-12.1.5.1, BIG-IP systems set up for connection mirroring in a high availabi…

Fix: after 15.1.0.1
Fix from $2,300 2020-04-30
Big Ip Access Policy Manager CRITICAL 9.1
CVE-2020-5886

On versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, and 12.1.0-12.1.5.1, BIG-IP systems setup for connection mirroring in a High Availabil…

Fix: after 15.1.0.1
Fix from $2,300 2020-04-30
Big Ip Access Policy Manager HIGH 8.1
CVE-2020-5876

On BIG-IP 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, a race condition exists where mcpd and other proce…

Fix: after 15.1.0.3
Fix from $1,950 2020-04-30
Big Ip Application Security Manager HIGH 7.5
CVE-2020-5879

On BIG-IP ASM 11.6.1-11.6.5.1, under certain configurations, the BIG-IP system sends data plane traffic to back-end servers unencrypted, even when a …

Fix: after 11.6.5.1
Fix from $1,950 2020-04-30
Nginx Controller HIGH 8.1
CVE-2020-5867

In versions prior to 3.3.0, the NGINX Controller Agent installer script 'install.sh' uses HTTP instead of HTTPS to check and install packages

Fix: 3.3.0+
Fix from $1,950 2020-04-23
Ecostruxure Machine Expert HIGH 7.5
CVE-2020-7488

A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists which could leak sensitive information transmitted between the softwa…

Mitigation only
Fix from $1,950 2020-04-22
Tg\/s3.2 Firmware MEDIUM 5.5
CVE-2019-19107

The Configuration pages in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway for user profiles and services transfer the passwo…

Mitigation only
Fix from $1,600 2020-04-22
Sf Rush Smart Band Firmware HIGH 8.1
CVE-2020-11539

An issue was discovered on Tata Sonata Smart SF Rush 1.12 devices. It has been identified that the smart band has no pairing (mode 0 Bluetooth LE sec…

No fix yet
Fix from $1,950 2020-04-22
Goland HIGH 7.5
CVE-2020-11685

In JetBrains GoLand before 2019.3.2, the plugin repository was accessed via HTTP instead of HTTPS.

Fix: 2019.3.2+
Fix from $1,950 2020-04-22
Tristation 1131 HIGH 7.5
CVE-2020-7483

**VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability could cause certain data to be visible on the network when the 'password' feature is enabled.…

Fix: after 4.12.0
Fix from $1,950 2020-04-16
Qradar Security Information And Event Manager MEDIUM 5.9
CVE-2019-4594

IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict…

Fix: 7.3.3+
Fix from $1,600 2020-04-15
Businessobjects Business Intelligence Platform CRITICAL 9.8
CVE-2020-6195

SAP Business Objects Business Intelligence Platform (CMC), version 4.1, 4.2, shows cleartext password in the response, leading to Information Disclos…

Mitigation only
Fix from $2,300 2020-04-14
Snmpc Online HIGH 7.5
CVE-2020-11557

An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It includes the username and password values in cleartext within each…

Fix: 2020-01-28+
Fix from $1,950 2020-04-09
Infinias Eidc32 Firmware CRITICAL 9.8
CVE-2020-11542

3xLOGIC Infinias eIDC32 2.213 devices with Web 1.107 allow Authentication Bypass via CMD.HTM?CMD= because authentication depends on the client side's…

No fix yet
Fix from $2,300 2020-04-04
Big Iq Centralized Management HIGH 8.1
CVE-2020-5860

On BIG-IP 15.0.0-15.1.0.2, 14.1.0-14.1.2.3, 13.1.0-13.1.3.2, 12.1.0-12.1.5.1, and 11.5.2-11.6.5.1 and BIG-IQ 7.0.0, 6.0.0-6.1.0, and 5.2.0-5.4.0, in …

Fix: after 15.1.0
Fix from $1,950 2020-03-27
Sits\ HIGH 8.1
CVE-2019-19127

An authentication bypass vulnerability is present in the standalone SITS:Vision 9.7.0 component of Tribal SITS in its default configuration, related …

No fix yet
Fix from $1,950 2020-03-25
Eds G516e Firmware HIGH 7.5
CVE-2020-6997

In Moxa EDS-G516E Series firmware, Version 5.2 or lower, sensitive information is transmitted over some web applications in cleartext.

Fix: after 5.2
Fix from $1,950 2020-03-24
Iologik 2512 Firmware HIGH 7.5
CVE-2020-7003

In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, sensitive information is tran…

Fix: after 3.0
Fix from $1,950 2020-03-24
Enigma Network Management Solution HIGH 7.5
CVE-2019-16063

NETSAS Enigma NMS 65.0.0 and prior does not encrypt sensitive data rendered within web pages. It is possible for an attacker to expose unencrypted se…

Fix: after 65.0.0
Fix from $1,950 2020-03-19
Enigma Network Management Solution HIGH 7.5
CVE-2019-16067

NETSAS Enigma NMS 65.0.0 and prior utilises basic authentication over HTTP for enforcing access control to the web application. The use of weak authe…

Fix: after 65.0.0
Fix from $1,950 2020-03-19
Open Network Automation Platform MEDIUM 6.5
CVE-2019-12122

An issue was discovered in ONAP Portal through Dublin. By executing a call to ONAPPORTAL/portalApi/loggedinUser, an attacker who possesses a user's c…

Fix: 4.0.0+
Fix from $1,600 2020-03-18
Cg3700b Firmware CRITICAL 9.8
CVE-2019-13394

The Voo branded NETGEAR CG3700b custom firmware V2.02.03 uses HTTP Basic Authentication over cleartext HTTP.

No fix yet
Fix from $2,300 2020-03-13