Vulnerability index

Browse CVEs

800 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cleartext TransmissionCWE-319 × clear
Mercedes Me HIGH 7.5
CVE-2018-18071

An issue was discovered in the Daimler Mercedes-Benz Me app 2.11.0-846 for iOS. The encrypted Connected Vehicle API data exchange between the app and…

No fix yet
Fix from $1,950 2018-10-09
Rp 210e Firmware MEDIUM 5.9
CVE-2018-5401

The Auto-Maskin DCU 210E, RP-210E, and Marine Pro Observer Android App transmit sensitive or security-critical data in cleartext in a communication c…

Mitigation only
Fix from $1,600 2018-10-08
Rp 210e Firmware HIGH 8.8
CVE-2018-5402

The Auto-Maskin DCU 210E, RP-210E, and Marine Pro Observer Android App use an embedded webserver that uses unencrypted plaintext for the transmission…

Mitigation only
Fix from $1,950 2018-10-08
Mensamax HIGH 8.1
CVE-2018-15752

An issue was discovered in the MensaMax (aka com.breustedt.mensamax) application 4.3 for Android. Cleartext Transmission of Sensitive Information all…

No fix yet
Fix from $1,950 2018-10-02
E Alert Firmware HIGH 8.8
CVE-2018-8842

Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software transmits sensitive or security-critical data in cleartext in a commu…

Mitigation only
Fix from $1,950 2018-09-26
Antidote 9 HIGH 8.1
CVE-2018-13140EPSS 7%

Druide Antidote through 9.5.1 on Windows and Linux allows remote code execution through the update mechanism by leveraging use of HTTP to download in…

Fix: after 5.1
Fix from $1,950 2018-09-24
Qbee Multi Sensor Camera Firmware MEDIUM 6.5
CVE-2018-16225

The QBee MultiSensor Camera through 4.16.4 accepts unencrypted network traffic from clients (such as the QBee Cam application through 1.0.5 for Andro…

Fix: after 10.7.2
Fix from $1,600 2018-09-18
Wildfly MEDIUM 5.9
CVE-2018-14627

The IIOP OpenJDK Subsystem in WildFly before version 14.0.0 does not honour configuration when SSL transport is required. Servers before this version…

Fix: 14.0.0+
Fix from $1,600 2018-09-04
Dir 601 Firmware HIGH 8.0
CVE-2018-12710EPSS 77%

An issue was discovered on D-Link DIR-601 2.02NA devices. Being local to the network and having only "User" account (which is a low privilege account…

No fix yet
Fix from $1,950 2018-08-29
Puppet Enterprise CRITICAL 9.8
CVE-2018-11749

When users are configured to use startTLS with RBAC LDAP, at login time, the user's credentials are sent via plaintext to the LDAP server. This affec…

Fix: after 2018.1.3
Fix from $2,300 2018-08-24
Emc Networker HIGH 8.8
CVE-2018-11050

Dell EMC NetWorker versions between 9.0 and 9.1.1.8 through 9.2.1.3, and the version 18.1.0.1 contain a Clear-Text authentication over network vulner…

Fix: after 9.2.1.3
Fix from $1,950 2018-08-01
Lacerte HIGH 7.5
CVE-2018-11338

Intuit Lacerte 2017 for Windows in a client/server environment transfers the entire customer list in cleartext over SMB, which allows attackers to (1…

Fix: after 2017
Fix from $1,950 2018-07-31
Smartserver 1 Firmware CRITICAL 9.8
CVE-2018-8855

Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The dev…

Fix: 4.11.007+
Fix from $2,300 2018-07-24
Wndr4500 Firmware HIGH 7.5
CVE-2016-5638

There are few web pages associated with the genie app on the Netgear WNDR4500 running firmware version V1.0.1.40_1.0.6877. Genie app adds some capabi…

No fix yet
Fix from $1,950 2018-07-24
Dgn2200 Firmware CRITICAL 9.8
CVE-2016-5649EPSS 27%

A vulnerability is in the 'BSW_cxttongr.htm' page of the Netgear DGN2200, version DGN2200-V1.0.0.50_7.0.50, and DGND3700, version DGND3700-V1.0.0.17_…

No fix yet
Fix from $2,300 2018-07-24
Junos HIGH 8.1
CVE-2018-0025

When an SRX Series device is configured to use HTTP/HTTPS pass-through authentication services, a client sending authentication credentials in the in…

Mitigation only
Fix from $1,950 2018-07-11
Ssl Vpn Client HIGH 8.1
CVE-2018-8929

Improper restriction of communication channel to intended endpoints vulnerability in HTTP daemon in Synology SSL VPN Client before 1.2.4-0224 allows …

Fix: 1.2.4-0224+
Fix from $1,950 2018-07-06
Iphone Os HIGH 7.5
CVE-2018-4227

An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. The issue involves the "Mail" compo…

Fix: 10.13.5 / 11.4+
Fix from $1,950 2018-06-08
Infosphere Information Server MEDIUM 5.9
CVE-2018-1454

IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to obtain sensitive information, caused by the failure to proper…

Mitigation only
Fix from $1,600 2018-06-05
Gfe Sass HIGH 8.1
CVE-2017-16040

gfe-sass is a library for promises (CommonJS/Promises/A,B,D) gfe-sass downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It m…

Fix: after 1.0.19
Fix from $1,950 2018-06-04
Ikst MEDIUM 5.9
CVE-2017-16041

ikst versions before 1.1.2 download resources over HTTP, which leaves it vulnerable to MITM attacks.

Fix: 1.1.2+
Fix from $1,600 2018-06-04
Hubl Server HIGH 8.1
CVE-2017-16035

The hubl-server module is a wrapper for the HubL Development Server. During installation hubl-server downloads a set of dependencies from api.hubapi.…

Fix: after 1.1.5
Fix from $1,950 2018-06-04
Bigfix Platform HIGH 7.5
CVE-2018-1600

IBM BigFix Platform 9.2 and 9.5 transmits sensitive or security-critical data in clear text in a communication channel that can be sniffed by unautho…

Fix: after 9.5.8
Fix from $1,950 2018-06-04
Icar 2 Wi Fi Obd2 Firmware MEDIUM 6.5
CVE-2018-11477

An issue was discovered on Vgate iCar 2 Wi-Fi OBD2 Dongle devices. The data packets that are sent between the iOS or Android application and the OBD …

Mitigation only
Fix from $1,600 2018-05-30
U9k Kp1000 Firmware MEDIUM 6.6
CVE-2018-11402

SimpliSafe Original has Unencrypted Keypad Transmissions, which allows physically proximate attackers to discover the PIN.

Mitigation only
Fix from $1,600 2018-05-24
Secure Firewall Management Center MEDIUM 5.8
CVE-2018-0281

A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to restart an instance of …

Mitigation only
Fix from $1,600 2018-05-02
Secure Firewall Management Center MEDIUM 5.8
CVE-2018-0283

A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to restart an instance of …

Mitigation only
Fix from $1,600 2018-05-02
Accent Firmware MEDIUM 6.5
CVE-2017-12716

Abbott Laboratories Accent and Anthem pacemakers manufactured prior to Aug 28, 2017 transmit unencrypted patient information via RF communications to…

Mitigation only
Fix from $1,600 2018-04-25
66074 Mge Network Management Card Transverse CRITICAL 9.8
CVE-2018-7246

A cleartext transmission of sensitive information vulnerability exists in Schneider Electric's 66074 MGE Network Management Card Transverse installed…

Mitigation only
Fix from $2,300 2018-04-18
Honor 8 Lite Firmware MEDIUM 5.3
CVE-2017-8154

The Themes App Honor 8 Lite Huawei mobile phones with software of versions before Prague-L31C576B172, versions before Prague-L31C530B160, versions be…

Mitigation only
Fix from $1,600 2018-04-11