Vulnerability index

Browse CVEs

800 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cleartext TransmissionCWE-319 × clear
Intellij Idea MEDIUM 5.9
CVE-2019-14954

JetBrains IntelliJ IDEA before 2019.2 was resolving the markdown plantuml artifact download link via a cleartext http connection.

Fix: 2019.2+
Fix from $1,600 2019-10-01
Sourcegear Vault HIGH 7.5
CVE-2019-10435

Jenkins SourceGear Vault Plugin transmits configured credentials in plain text as part of job configuration forms, potentially resulting in their exp…

Fix: after 1.1.1
Fix from $1,950 2019-10-01
Ldap Email HIGH 7.5
CVE-2019-10434

Jenkins LDAP Email Plugin transmits configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in t…

Fix: after 0.8
Fix from $1,950 2019-10-01
Sterling File Gateway MEDIUM 5.3
CVE-2019-4280

IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 displays sensitive information in HTTP requests which could be used in further attacks against the …

Fix: after 6.0.1.0
Fix from $1,600 2019-09-30
Nulock HIGH 8.8
CVE-2019-16924

The Nulock application 1.5.0 for mobile devices sends a cleartext password over Bluetooth, which allows remote attackers (after sniffing the network)…

No fix yet
Fix from $1,950 2019-09-27
Thunderbird MEDIUM 6.5
CVE-2019-11739

Encrypted S/MIME parts in a crafted multipart/alternative message can leak plaintext when included in a a HTML reply/forward. This vulnerability affe…

Fix: 60.9.0 / 68.1.0+
Fix from $1,600 2019-09-27
Big Iq Centralized Management MEDIUM 6.5
CVE-2019-6652

In BIG-IQ 6.0.0-6.1.0, services for stats do not require authentication nor do they implement any form of Transport Layer Security (TLS).

Fix: after 6.1.0
Fix from $1,600 2019-09-25
Aqua Microscanner MEDIUM 5.3
CVE-2019-10427

Jenkins Aqua MicroScanner Plugin 1.0.7 and earlier transmitted configured credentials in plain text as part of the global Jenkins configuration form,…

Fix: after 1.0.7
Fix from $1,600 2019-09-25
Aqua Security Scanner HIGH 7.5
CVE-2019-10428

Jenkins Aqua Security Scanner Plugin 3.0.17 and earlier transmitted configured credentials in plain text as part of the global Jenkins configuration …

Fix: after 3.0.17
Fix from $1,950 2019-09-25
Inedo Buildmaster HIGH 7.5
CVE-2019-10411

Jenkins Inedo BuildMaster Plugin 2.4.0 and earlier transmitted configured credentials in plain text as part of the global Jenkins configuration form,…

Fix: after 2.4.0
Fix from $1,950 2019-09-25
Inedo Proget HIGH 7.5
CVE-2019-10412

Jenkins Inedo ProGet Plugin 1.2 and earlier transmitted configured credentials in plain text as part of the global Jenkins configuration form, potent…

Fix: after 1.2
Fix from $1,950 2019-09-25
Ontap Select Deploy Administration Utility CRITICAL 9.8
CVE-2019-5505

ONTAP Select Deploy administration utility versions 2.2 through 2.12.1 transmit credentials in plaintext.

Fix: after 2.12.1
Fix from $2,300 2019-09-24
Oncommand Workflow Automation MEDIUM 5.3
CVE-2019-5503

OnCommand Workflow Automation versions prior to 5.0 shipped without certain HTTP Security headers configured which could allow an attacker to obtain …

Mitigation only
Fix from $1,600 2019-09-10
Tiktok MEDIUM 6.5
CVE-2019-14319

The TikTok (formerly Musical.ly) application 12.2.0 for Android and iOS performs unencrypted transmission of images, videos, and likes. This allows a…

Mitigation only
Fix from $1,600 2019-09-04
Ibm Application Security On Cloud MEDIUM 6.5
CVE-2019-10391

Jenkins IBM Application Security on Cloud Plugin 1.2.4 and earlier transmitted configured passwords in plain text as part of job configuration forms,…

Fix: after 1.2.4
Fix from $1,600 2019-08-28
Hickory Smart Ethernet Bridge Firmware HIGH 7.5
CVE-2019-5635

A cleartext transmission of sensitive information vulnerability is present in Hickory Smart Ethernet Bridge from Belwith Products, LLC. Captured data…

Mitigation only
Fix from $1,950 2019-08-22
Application Service MEDIUM 5.4
CVE-2019-11276

Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.16, 2.4.x prior to 2.4.12, 2.5.x prior to 2.5.8, and 2.6.x …

Fix: 2.3.16 / 2.4.12+
Fix from $1,600 2019-08-19
Dds Security HIGH 7.5
CVE-2019-15135

The handshake protocol in Object Management Group (OMG) DDS Security 1.1 sends cleartext information about all of the capabilities of a participant (…

Mitigation only
Fix from $1,950 2019-08-18
Businessobjects Business Intelligence MEDIUM 6.5
CVE-2019-0346

Unencrypted communication error in SAP Business Objects Business Intelligence Platform (Central Management Console), version 4.2, leads to disclosure…

Mitigation only
Fix from $1,600 2019-08-14
Businessobjects Business Intelligence MEDIUM 6.5
CVE-2019-0348

SAP BusinessObjects Business Intelligence Platform (Web Intelligence), versions 4.1, 4.2, can access database with unencrypted connection, even if th…

Mitigation only
Fix from $1,600 2019-08-14
Fedora MEDIUM 6.5
CVE-2019-14664

In Enigmail below 2.1, an attacker in possession of PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted p…

Fix: 2.1+
Fix from $1,600 2019-08-05
Yarn HIGH 8.1
CVE-2019-5448

Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be s…

Fix: 1.17.3+
Fix from $1,950 2019-07-30
Cloud Access Manager HIGH 7.4
CVE-2019-13498

One Identity Cloud Access Manager 8.1.3 does not use HTTP Strict Transport Security (HSTS), which may allow man-in-the-middle (MITM) attacks. This is…

No fix yet
Fix from $1,950 2019-07-29
I3 Firmware MEDIUM 5.6
CVE-2019-12820

A vulnerability was found in the app 2.0 of the Shenzhen Jisiwei i3 robot vacuum cleaner. Actions performed on the app such as changing a password, a…

Mitigation only
Fix from $1,600 2019-07-19
Kotlin HIGH 8.1
CVE-2019-10101

JetBrains Kotlin versions before 1.3.30 were resolving artifacts using an http connection during the build process, potentially allowing an MITM atta…

Fix: 1.3.30+
Fix from $1,950 2019-07-03
Kotlin HIGH 8.1
CVE-2019-10102

JetBrains Ktor framework (created using the Kotlin IDE template) versions before 1.1.0 were resolving artifacts using an http connection during the b…

Fix: 1.1.0 / 1.3.30+
Fix from $1,950 2019-07-03
Big Ip Local Traffic Manager MEDIUM 5.3
CVE-2019-6640

On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.1-11.5.8, SNMP exposes sensitive configuration …

Fix: 11.5.9 / 11.6.3+
Fix from $1,600 2019-07-03
Oncell G3150 Hspa Firmware CRITICAL 9.8
CVE-2018-11421

Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior use a proprietary monitoring protocol that does not provide confidentiality, integ…

Fix: after 1.6
Fix from $2,300 2019-07-03
Oncell G3150 Hspa Firmware CRITICAL 9.8
CVE-2018-11422

Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior use a proprietary configuration protocol that does not provide confidentiality, in…

Fix: after 1.6
Fix from $2,300 2019-07-03
Django MEDIUM 5.3
CVE-2019-12781

An issue was discovered in Django 1.11 before 1.11.22, 2.1 before 2.1.10, and 2.2 before 2.2.3. An HTTP request is not redirected to HTTPS when the S…

Fix: 1.11.22 / 2.1.10+
Fix from $1,600 2019-07-01