Vulnerability index

Browse CVEs

800 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cleartext TransmissionCWE-319 × clear
Api Connect MEDIUM 5.3
CVE-2019-4382EPSS 8%

IBM API Connect 5.0.0.0 through 5.0.8.6 could allow an unauthorized user to obtain sensitive information about the system users using specially craft…

Fix: after 5.0.8.6
Fix from $1,600 2019-06-25
Digital Persona U.are.u 4500 Firmware MEDIUM 5.9
CVE-2019-12813

An issue was discovered in Digital Persona U.are.U 4500 Fingerprint Reader v24. The key and salt used for obfuscating the fingerprint image exhibit c…

No fix yet
Fix from $1,600 2019-06-13
Simatic Mv420 Firmware MEDIUM 5.3
CVE-2019-10926

A vulnerability has been identified in SIMATIC MV400 family (All Versions < V7.0.6). Communication with the device is not encrypted. Data transmitted…

Mitigation only
Fix from $1,600 2019-06-12
Wp2002 Firmware HIGH 8.8
CVE-2019-12504

Due to unencrypted and unauthenticated data communication, the wireless presenter Inateck WP2002 is prone to keystroke injection attacks. Thus, an at…

No fix yet
Fix from $1,950 2019-06-07
Wp1001 Firmware HIGH 8.8
CVE-2019-12505

Due to unencrypted and unauthenticated data communication, the wireless presenter Inateck WP1001 v1.3C is prone to keystroke injection attacks. Thus,…

No fix yet
Fix from $1,950 2019-06-07
R700 Laser Presentation Remote Firmware HIGH 8.8
CVE-2019-12506

Due to unencrypted and unauthenticated data communication, the wireless presenter Logitech R700 Laser Presentation Remote R-R0010 is prone to keystro…

No fix yet
Fix from $1,950 2019-06-07
Security Information Queue HIGH 7.5
CVE-2019-4162

IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 is missing the HTTP Strict Transport Security header. Users can navigate by mistake to …

Patch available
Fix from $1,950 2019-06-06
Oncommand Insight HIGH 7.5
CVE-2019-5496

Oncommand Insight versions prior to 7.3.5 shipped without certain HTTP Security headers configured which could allow an attacker to obtain sensitive …

Fix: 7.3.5+
Fix from $1,950 2019-05-10
Oncommand Unified Manager HIGH 7.5
CVE-2019-5494

OnCommand Unified Manager 7-Mode prior to version 5.2.4 shipped without certain HTTP Security headers configured which could allow an attacker to obt…

Fix: 5.2.4+
Fix from $1,950 2019-05-10
Big Ip Access Policy Manager MEDIUM 5.3
CVE-2019-6613

On BIG-IP 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, SNMP may expose sensitive configuration objects over insecure transmiss…

Fix: 11.5.9 / 11.6.4+
Fix from $1,600 2019-05-03
Ilnkp2p HIGH 8.1
CVE-2019-11220

An authentication flaw in Shenzhen Yunni Technology iLnkP2P allows remote attackers to actively intercept user-to-device traffic in cleartext, includ…

Mitigation only
Fix from $1,950 2019-04-26
Cf Deployment CRITICAL 9.8
CVE-2019-3801

Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an insecure protocol to fetch dependencies when building…

Fix: 1.9.10 / 2.1.3+
Fix from $2,300 2019-04-25
Fortimanager HIGH 8.1
CVE-2018-1360

A cleartext transmission of sensitive information vulnerability in Fortinet FortiManager 5.2.0 through 5.2.7, 5.4.0 and 5.4.1 may allow an unauthenti…

Fix: after 5.2.7
Fix from $1,950 2019-04-25
Application Service CRITICAL 9.8
CVE-2019-3793

Pivotal Apps Manager Release, versions 665.0.x prior to 665.0.28, versions 666.0.x prior to 666.0.21, versions 667.0.x prior to 667.0.7, contain an i…

Fix: 665.0.28 / 666.0.21+
Fix from $2,300 2019-04-24
Iks G6824a Firmware CRITICAL 9.8
CVE-2019-6526

Moxa IKS-G6824A series Versions 4.5 and prior, EDS-405A series Version 3.8 and prior, EDS-408A series Version 3.8 and prior, and EDS-510A series Vers…

Fix: after 4.5
Fix from $2,300 2019-04-15
Hawkbit HIGH 8.1
CVE-2019-10240

Eclipse hawkBit versions prior to 0.3.0M2 resolved Maven build artifacts for the Vaadin based UI over HTTP instead of HTTPS. Any of these dependent a…

Fix: after 0.2.5
Fix from $1,950 2019-04-03
Ktlint HIGH 8.1
CVE-2019-1010260

Using ktlint to download and execute custom rulesets can result in arbitrary code execution as the served jars can be compromised by a MITM. This att…

Fix: 0.30.0+
Fix from $1,950 2019-04-02
Uc Browser MEDIUM 5.9
CVE-2019-10251

The UCWeb UC Browser application through 2019-03-26 for Android uses HTTP to download certain modules associated with PDF and Microsoft Office files …

Fix: after 2019-03-26
Fix from $1,600 2019-03-28
Uc Browser MEDIUM 5.9
CVE-2019-10250

UCWeb UC Browser 7.0.185.1002 on Windows uses HTTP for downloading certain PDF modules, which allows MITM attacks.

No fix yet
Fix from $1,600 2019-03-28
Secvest Wireless Alarm System Fuaa50000 Firmware HIGH 7.5
CVE-2019-9860

Due to unencrypted signal communication and predictability of rolling codes, an attacker can "desynchronize" an ABUS Secvest wireless remote control …

Mitigation only
Fix from $1,950 2019-03-27
Mycarelink Monitor 24950 Firmware MEDIUM 6.5
CVE-2019-6540

The Conexus telemetry protocol utilized within Medtronic MyCareLink Monitor versions 24950 and 24952, CareLink Monitor version 2490C, CareLink 2090 P…

Mitigation only
Fix from $1,600 2019-03-26
Sterling B2b Integrator MEDIUM 5.9
CVE-2019-4063

IBM Sterling B2B Integrator 5.2.0.1 through 6.0.0.0 Standard Edition could allow highly sensitive information to be transmitted in plain text. An att…

Fix: after 6.0.0.0
Fix from $1,600 2019-03-05
S14 Firmware HIGH 7.5
CVE-2019-7675

An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. The default management application is delivered over cleartext HTTP with Basic Authentic…

No fix yet
Fix from $1,950 2019-02-09
Sky Go MEDIUM 5.9
CVE-2018-18908

The Sky Go Desktop application 1.0.19-1 through 1.0.23-1 for Windows performs several requests over cleartext HTTP. This makes the data submitted in …

Fix: after 1.0.23-1
Fix from $1,600 2019-01-20
Linux Kernel MEDIUM 5.5
CVE-2019-5489

The mincore() implementation in mm/mincore.c in the Linux kernel through 4.19.13 allowed local attackers to observe page cache access patterns of oth…

Fix: after 4.19.13
Fix from $1,600 2019-01-07
Nifi HIGH 7.5
CVE-2018-17195

The template upload API endpoint accepted requests from different domain when sent in conjunction with ARP spoofing + man in the middle (MiTM) attack…

Fix: after 1.7.1
Fix from $1,950 2018-12-19
I2 Enterprise Insight Analysis MEDIUM 5.9
CVE-2018-1525

IBM i2 Enterprise Insight Analysis 2.1.7 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP…

Mitigation only
Fix from $1,600 2018-12-06
Espace 7950 Firmware HIGH 7.4
CVE-2018-7960

There is a SRTP icon display vulnerability in Huawei eSpace product. An unauthenticated, remote attacker launches man-in-the-middle attack to interce…

Mitigation only
Fix from $1,950 2018-11-27
Cardboard MEDIUM 5.3
CVE-2018-19111

The Google Cardboard application 1.8 for Android and 1.2 for iOS sends potentially private cleartext information to the Unity 3D Stats web site, as d…

Mitigation only
Fix from $1,600 2018-11-08
H.264 Poe Ip Camera Firmware MEDIUM 5.7
CVE-2018-12674

The SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) stores the username and password within the cookies o…

No fix yet
Fix from $1,600 2018-10-19