Vulnerability index

Browse CVEs

800 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cleartext TransmissionCWE-319 × clear
E\!cockpit HIGH 7.5
CVE-2019-5107

A cleartext transmission vulnerability exists in the network communication functionality of WAGO e!Cockpit version 1.5.1.1. An attacker with access t…

Mitigation only
Fix from $1,950 2020-03-11
Mb3170 Firmware HIGH 7.5
CVE-2019-9101

An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB31…

Fix: after 4.0
Fix from $1,950 2020-03-11
Tc7337net Firmware CRITICAL 9.8
CVE-2020-10376

Technicolor TC7337NET 08.89.17.23.03 devices allow remote attackers to discover passwords by sniffing the network for an "Authorization: Basic" HTTP …

Mitigation only
Fix from $2,300 2020-03-11
Solution Manager CRITICAL 9.8
CVE-2020-6198

SAP Solution Manager (Diagnostics Agent), version 720, allows unencrypted connections from unauthenticated sources. This allows an attacker to contro…

Mitigation only
Fix from $2,300 2020-03-10
Repository Connector MEDIUM 5.3
CVE-2020-2149

Jenkins Repository Connector Plugin 1.2.6 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form…

Fix: after 1.2.6
Fix from $1,600 2020-03-09
Sonar Quality Gates MEDIUM 5.3
CVE-2020-2150

Jenkins Sonar Quality Gates Plugin 1.3.1 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form,…

Fix: after 1.3.1
Fix from $1,600 2020-03-09
Quality Gates MEDIUM 5.3
CVE-2020-2151

Jenkins Quality Gates Plugin 2.5 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potenti…

Fix: after 2.5
Fix from $1,600 2020-03-09
Openshift Deployer MEDIUM 5.3
CVE-2020-2155

Jenkins OpenShift Deployer Plugin 1.2.0 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, …

Fix: after 1.2.0
Fix from $1,600 2020-03-09
Logstash MEDIUM 5.3
CVE-2020-2143

Jenkins Logstash Plugin 2.3.1 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentiall…

Fix: after 2.3.1
Fix from $1,600 2020-03-09
Hga12r 02 Firmware CRITICAL 9.8
CVE-2020-9477

An issue was discovered on HUMAX HGA12R-02 BRGCAA 1.1.53 devices. A vulnerability in the authentication functionality in the web-based interface coul…

Mitigation only
Fix from $2,300 2020-03-04
Smarthome Firmware CRITICAL 9.8
CVE-2020-9550

Rubetek SmartHome 2020 devices use unencrypted 433 MHz communication between controllers and beacons, allowing an attacker to sniff and spoof beacon …

Mitigation only
Fix from $2,300 2020-03-04
Safari MEDIUM 6.5
CVE-2020-3841

The issue was addressed with improved UI handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, Safari 13.0.5. A local user may unknowingly s…

Fix: 13.0.5 / 13.3.1+
Fix from $1,600 2020-02-27
Scala HIGH 7.5
CVE-2020-7907

In the JetBrains Scala plugin before 2019.2.1, some artefact dependencies were resolved over unencrypted connections.

Fix: 2019.2.1+
Fix from $1,950 2020-02-21
Credhub HIGH 7.4
CVE-2020-5399

Cloud Foundry CredHub, versions prior to 2.5.10, connects to a MySQL database without TLS even when configured to use TLS. A malicious user with acce…

Fix: 2.5.10 / 12.29.0+
Fix from $1,950 2020-02-12
Yetishare HIGH 7.5
CVE-2019-20061

The user-introduction email in MFScripts YetiShare v3.5.2 through v4.5.4 may leak the (system-picked) password if this email is sent in cleartext. In…

Fix: after 4.5.4
Fix from $1,950 2020-02-10
Global Tv MEDIUM 5.3
CVE-2020-8506

The Global TV application 2.3.2 for Android and 4.7.5 for iOS sends Unencrypted Analytics.

Fix: after 4.7.5
Fix from $1,600 2020-02-05
Citytv Video HIGH 7.5
CVE-2020-8507

The Citytv Video application 4.08.0 for Android and 3.35 for iOS sends Unencrypted Analytics.

Fix: after 4.08.0
Fix from $1,950 2020-02-05
N Central HIGH 7.5
CVE-2020-7984

SolarWinds N-central before 12.1 SP1 HF5 and 12.2 before SP1 HF2 allows remote attackers to retrieve cleartext domain admin credentials from the Agen…

Fix: 12.1.1.404 / 12.2.1.280+
Fix from $1,950 2020-01-26
Easyinstall HIGH 7.5
CVE-2019-19898

In IXP EasyInstall 6.2.13723, there are cleartext credentials in network communication on TCP port 20050 when using the Administrator console remotel…

No fix yet
Fix from $1,950 2020-01-23
Kafka HIGH 7.5
CVE-2019-12399

When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a conne…

Fix: after 14.4.0
Fix from $1,950 2020-01-14
Grand Ma300 Firmware HIGH 7.5
CVE-2014-5380

Grand MA 300 allows retrieval of the access PIN from sniffed data.

No fix yet
Fix from $1,950 2020-01-13
D5 Firmware HIGH 7.5
CVE-2019-16274

DTEN D5 before 1.3 and D7 before 1.3 devices transfer customer data files via unencrypted HTTP.

Fix: 1.3+
Fix from $1,950 2020-01-06
Connect Box Eurodocsis Firmware HIGH 7.5
CVE-2019-19967

The Administration page on Connect Box EuroDOCSIS 3.0 Voice Gateway CH7465LG-NCIP-6.12.18.25-2p6-NOSH devices accepts a cleartext password in a POST …

No fix yet
Fix from $1,950 2019-12-25
Hg100 Firmware CRITICAL 9.8
CVE-2019-15911

An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Because of insecure key transport in Z…

No fix yet
Fix from $2,300 2019-12-20
Hgb10r 02 Firmware HIGH 7.5
CVE-2019-19889

An issue was discovered on Humax Wireless Voice Gateway HGB10R-2 20160817_1855 devices. The attacker can discover admin credentials in the backup fil…

No fix yet
Fix from $1,950 2019-12-18
Hgb10r 02 Firmware HIGH 7.5
CVE-2019-19890

An issue was discovered on Humax Wireless Voice Gateway HGB10R-2 20160817_1855 devices. Admin credentials are sent over cleartext HTTP.

No fix yet
Fix from $1,950 2019-12-18
Texture MEDIUM 6.5
CVE-2019-8632

Some analytics data was sent using HTTP rather than HTTPS. This was addressed by no longer sending this analytics data. This issue is fixed in Textur…

Fix: 4.22.0.4 / 5.11.10+
Fix from $1,600 2019-12-18
Fedora HIGH 7.5
CVE-2019-3992

ELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. A remote unauthenticated attacker can access the server's config…

Fix: after 3.1.4-57bea22
Fix from $1,950 2019-12-17
Fedora HIGH 7.5
CVE-2019-3993EPSS 46%

ELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. A remote unauthenticated attacker can recover a user's password …

Fix: after 3.1.4-57bea22
Fix from $1,950 2019-12-17
Sctmexecutor MEDIUM 5.3
CVE-2019-16568

Jenkins SCTMExecutor Plugin 2.2 and earlier transmits previously configured service credentials in plain text as part of the global configuration, as…

Fix: after 2.2
Fix from $1,600 2019-12-17