Vulnerability index

Browse CVEs

800 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cleartext TransmissionCWE-319 × clear
Petalk Ai Firmware HIGH 8.1
CVE-2019-16732

Unencrypted HTTP communications for firmware upgrades in Petalk AI and PF-103 allow man-in-the-middle attackers to run arbitrary code as the root use…

No fix yet
Fix from $1,950 2019-12-13
Sppa T3000 Application Server MEDIUM 5.9
CVE-2019-18285

A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The RMI communication between the client…

No fix yet
Fix from $1,600 2019-12-12
Last.fm Desktop MEDIUM 5.3
CVE-2019-19251

The Last.fm desktop app (Last.fm Scrobbler) through 2.1.39 on macOS makes HTTP requests that include an API key without the use of SSL/TLS. Although …

Fix: after 2.1.39
Fix from $1,600 2019-12-10
Ie Sw Pl09m 5gc 4gt Firmware CRITICAL 9.8
CVE-2019-16672

An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 dev…

Fix: after 3.4.4
Fix from $2,300 2019-12-06
Debian Linux MEDIUM 5.3
CVE-2015-7542

A vulnerability exists in libgwenhywfar through 4.12.0 due to the usage of outdated bundled CA certificates.

Fix: after 4.12.0
Fix from $1,600 2019-12-03
Terraform HIGH 7.5
CVE-2019-19316

When using the Azure backend with a shared access signature (SAS), Terraform versions prior to 0.12.17 may transmit the token and state snapshot usin…

Fix: 0.12.17+
Fix from $1,950 2019-12-02
Satellite HIGH 8.6
CVE-2012-5562

A flaw was found in rhn-proxy. This vulnerability may allow the rhn-proxy to transmit user credentials in clear-text when it accesses RHN Satellite. …

Fix: 5.6+
Fix from $1,950 2019-12-02
Bcst 60 Firmware CRITICAL 9.8
CVE-2019-12503

Due to unencrypted and unauthenticated data communication, the wireless barcode scanner Inateck BCST-60 is prone to keystroke injection attacks. Thus…

No fix yet
Fix from $2,300 2019-12-02
Anviz Firmware HIGH 7.5
CVE-2019-12388

Anviz access control devices perform cleartext transmission of sensitive information (passwords/pins and names) when replying to query on port tcp/50…

Mitigation only
Fix from $1,950 2019-12-02
Mi Fit MEDIUM 5.3
CVE-2019-19463

The Anhui Huami Mi Fit application before 4.0.11 for Android has an Unencrypted Update Check.

Fix: 4.0.11+
Fix from $1,600 2019-11-30
Jenkins Qmetry For Jira MEDIUM 6.5
CVE-2019-16545

Jenkins QMetry for JIRA - Test Management Plugin transmits credentials in its configuration in plain text as part of job configuration forms, potenti…

Fix: after 1.12
Fix from $1,600 2019-11-21
Pidgin MEDIUM 5.5
CVE-2012-1257

Pidgin 2.10.0 uses DBUS for certain cleartext communication, which allows local users to obtain sensitive information via a dbus session monitor.

Mitigation only
Fix from $1,600 2019-11-20
Data Loss Prevention MEDIUM 6.5
CVE-2019-3640

Unprotected Transport of Credentials in ePO extension in McAfee Data Loss Prevention 11.x prior to 11.4.0 allows remote attackers with access to the …

Fix: after 11.4.0
Fix from $1,600 2019-11-14
Fedora MEDIUM 5.5
CVE-2010-4177

mysql-gui-tools (mysql-query-browser and mysql-admin) before 5.0r14+openSUSE-2.3 exposes the password of a user connected to the MySQL server in clea…

Fix: 5.0r14+
Fix from $1,600 2019-11-12
Dir 600 B1 Firmware CRITICAL 9.8
CVE-2019-18852

Certain D-Link devices have a hardcoded Alphanetworks user account with TELNET access because of /etc/config/image_sign or /etc/alpha_config/image_si…

No fix yet
Fix from $2,300 2019-11-11
Viber HIGH 8.8
CVE-2019-18800

Viber through 11.7.0.5 allows a remote attacker who can capture a victim's internet traffic to steal their Viber account, because not all Viber proto…

Fix: after 11.7.0.5
Fix from $1,950 2019-11-06
Modicon M580 Firmware HIGH 7.5
CVE-2019-6845

A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists in Modicon M580, Modicon M340, Modicon Premium , Modicon Quantum (all…

Mitigation only
Fix from $1,950 2019-10-29
Modicon M580 Firmware MEDIUM 6.5
CVE-2019-6846

A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modules (all…

Mitigation only
Fix from $1,600 2019-10-29
Lx390 Firmware HIGH 7.5
CVE-2019-18201

An issue was discovered on Fujitsu Wireless Keyboard Set LX390 GK381 devices. Because of the lack of proper encryption of 2.4 GHz communication, an a…

No fix yet
Fix from $1,950 2019-10-24
Lx390 Firmware MEDIUM 6.6
CVE-2019-18199

An issue was discovered on Fujitsu Wireless Keyboard Set LX390 GK381 devices. Because of the lack of proper encryption of 2.4 GHz communication, and …

No fix yet
Fix from $1,600 2019-10-24
Moolticute MEDIUM 6.5
CVE-2019-12967

Stephan Mooltipass Moolticute through 0.42.1 (and possibly earlier versions) has Incorrect Access Control.

Fix: after 0.42.1
Fix from $1,600 2019-10-22
Server CRITICAL 9.8
CVE-2019-17393

The Customer's Tomedo Server in Version 1.7.3 communicates to the Vendor Tomedo Server via HTTP (in cleartext) that can be sniffed by unauthorized ac…

No fix yet
Fix from $2,300 2019-10-18
Deep Security HIGH 7.5
CVE-2019-15626

The Deep Security Manager application (Versions 10.0, 11.0 and 12.0), when configured in a certain way, may transmit initial LDAP communication in cl…

Patch available
Fix from $1,950 2019-10-17
Infinite Design MEDIUM 6.5
CVE-2019-17356

The Infinite Design application 3.4.12 for Android sends a username and password via TCP without any encryption during login, as demonstrated by snif…

No fix yet
Fix from $1,600 2019-10-15
Explorer 710 Firmware HIGH 7.8
CVE-2019-9532

The web application portal of the Cobham EXPLORER 710, firmware version 1.07, sends the login password in cleartext. This could allow an unauthentica…

Mitigation only
Fix from $1,950 2019-10-10
Junos MEDIUM 5.5
CVE-2019-0069

On EX4600, QFX5100 Series, NFX Series, QFX10K Series, QFX5110, QFX5200 Series, QFX5110, QFX5200, QFX10K Series, vSRX, SRX1500, SRX4000 Series, vSRX, …

Mitigation only
Fix from $1,600 2019-10-09
Renpho MEDIUM 6.8
CVE-2019-14808

An issue was discovered in the RENPHO application 3.0.0 for iOS. It transmits JSON data unencrypted to a server without an integrity check, if a user…

No fix yet
Fix from $1,600 2019-10-09
Combi Stream Mslq Firmware CRITICAL 9.1
CVE-2019-17218

An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. By default, the communication to the web service i…

Mitigation only
Fix from $2,300 2019-10-06
Toolbox MEDIUM 5.9
CVE-2019-14959

JetBrains Toolbox before 1.15.5605 was resolving an internal URL via a cleartext http connection.

Fix: 1.15.5605+
Fix from $1,600 2019-10-02
Mina HIGH 7.5
CVE-2019-0231

Handling of the close_notify SSL/TLS message does not lead to a connection closure, leading the server to retain the socket opened and to have the cl…

Mitigation only
Fix from $1,950 2019-10-01