Vulnerability index

Browse CVEs

800 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cleartext TransmissionCWE-319 × clear
Spark Hybrid Calendar Service HIGH 7.5
CVE-2017-12310

A vulnerability in the auto discovery phase of Cisco Spark Hybrid Calendar Service could allow an unauthenticated, remote attacker to view sensitive …

Mitigation only
Fix from $1,950 2018-03-27
GitLab HIGH 7.2
CVE-2017-0925

Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration API endpoin…

Fix: after 10.3.3
Fix from $1,950 2018-03-21
Snh V6410pn Firmware CRITICAL 9.8
CVE-2018-6295

Unencrypted way of remote control and communications in Hanwha Techwin Smartcams

Mitigation only
Fix from $2,300 2018-03-13
Hirschmann Rs20 0900mmm2tdau MEDIUM 5.9
CVE-2018-5471

A Cleartext Transmission of Sensitive Information issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPU…

Mitigation only
Fix from $1,600 2018-03-06
Display Solutions MEDIUM 5.9
CVE-2018-6019

Samsung Display Solutions App before 3.02 for Android allows man-in-the-middle attackers to spoof B2B content by leveraging failure to use encryption…

Fix: after 3.01
Fix from $1,600 2018-03-06
Homematic Central Control Unit Ccu2 Firmware HIGH 8.1
CVE-2018-7298

In /usr/local/etc/config/addons/mh/loopupd.sh on eQ-3 AG HomeMatic CCU2 2.29.22 devices, software update packages are downloaded via the HTTP protoco…

Mitigation only
Fix from $1,950 2018-02-22
A320 X CRITICAL 9.8
CVE-2018-7259

The FSX / P3Dv4 installer 2.0.1.231 for Flight Sim Labs A320-X sends a user's Google account credentials to http://installLog.flightsimlabs.com/LogHa…

Mitigation only
Fix from $2,300 2018-02-20
Jmeter CRITICAL 9.8
CVE-2018-1297EPSS 10%

When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection. This could allow an attacker to get Access …

Mitigation only
Fix from $2,300 2018-02-13
Tinder CRITICAL 9.1
CVE-2018-6017

Unencrypted transmission of images in Tinder iOS app and Tinder Android app allows an attacker to extract private sensitive information by sniffing n…

Mitigation only
Fix from $2,300 2018-01-24
Tinder CRITICAL 9.1
CVE-2018-6018

Fixed sizes of HTTPS responses in Tinder iOS app and Tinder Android app allow an attacker to extract private sensitive information by sniffing networ…

Mitigation only
Fix from $2,300 2018-01-24
Debian Linux MEDIUM 6.5
CVE-2017-17844

An issue was discovered in Enigmail before 1.9.9. A remote attacker can obtain cleartext content by sending an encrypted data block (that the attacke…

Fix: 1.9.9+
Fix from $1,600 2017-12-27
Cnpilot R190v Firmware HIGH 8.8
CVE-2017-5259EPSS 39%

In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, an undocumented, root-privilege administration web shell is available using the …

Fix: after 4.3.2-r4
Fix from $1,950 2017-12-20
Integration Bus HIGH 8.1
CVE-2017-1694

IBM Integration Bus 9.0 and 10.0 transmits user credentials in plain in clear text which can be read by an attacker using man in the middle technique…

Mitigation only
Fix from $1,950 2017-12-20
Chat HIGH 7.5
CVE-2017-14486

The Vibease Wireless Remote Vibrator app for Android and the Vibease Chat app for iOS use cleartext to exchange messages with other apps and the PLAI…

Mitigation only
Fix from $1,950 2017-12-01
Contacts Backup \& Restore CRITICAL 9.8
CVE-2017-15999

In the "NQ Contacts Backup & Restore" application 1.1 for Android, no HTTPS is used for transmitting login and synced user data. When logging in, the…

Mitigation only
Fix from $2,300 2017-10-29
Bigfix Platform MEDIUM 5.9
CVE-2017-1232

IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) transmits sensitive or security-critical data in cleartext in a communication channel t…

Patch available
Fix from $1,600 2017-10-26
Apple Support MEDIUM 5.3
CVE-2017-7147

An issue was discovered in certain Apple products. The Apple Support app before 1.2 for iOS is affected. The issue involves the "Analytics" component…

Fix: after 1.1.1
Fix from $1,600 2017-10-23
Iphone Os HIGH 7.5
CVE-2017-7133

An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "MobileBackup" component. It allows remote attac…

Fix: after 10.3.3
Fix from $1,950 2017-10-23
Mac Os X MEDIUM 5.5
CVE-2017-7143

An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the "Captive Network Assistant" component. It a…

Fix: after 10.12.6
Fix from $1,600 2017-10-23
Iphone Os MEDIUM 5.3
CVE-2017-7078

An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. The issue involves the "Mail Drafts" co…

Fix: after 10.12.6
Fix from $1,600 2017-10-23
Multiflex M10a Controller Firmware MEDIUM 6.5
CVE-2017-14009

An Information Exposure issue was discovered in ProMinent MultiFLEX M10a Controller web interface. When an authenticated user uses the Change Passwor…

Mitigation only
Fix from $1,600 2017-10-17
Video Management System HIGH 7.5
CVE-2017-15290

Mirasys Video Management System (VMS) 6.x before 6.4.6, 7.x before 7.5.15, and 8.x before 8.1.1 has a login process in which cleartext data is sent f…

Mitigation only
Fix from $1,950 2017-10-12
Go MEDIUM 5.9
CVE-2017-15042

An unintended cleartext issue exists in Go before 1.8.4 and 1.9.x before 1.9.1. RFC 4954 requires that, during SMTP, the PLAIN auth scheme must only …

Fix: after 1.8.3
Fix from $1,600 2017-10-05
Cloud Enterprise MEDIUM 5.9
CVE-2017-8444

The client-forwarder in Elastic Cloud Enterprise versions prior to 1.0.2 do not properly encrypt traffic to ZooKeeper. If an attacker is able to man …

Mitigation only
Fix from $1,600 2017-09-29
iOS MEDIUM 6.5
CVE-2017-6665

A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker…

Mitigation only
Fix from $1,600 2017-08-07
Tivoli Monitoring HIGH 7.0
CVE-2017-1181

IBM Tivoli Monitoring Portal V6 client could allow a local attacker to gain elevated privileges for IBM Tivoli Monitoring, caused by the default cons…

Mitigation only
Fix from $1,950 2017-07-17
Shotwell HIGH 7.5
CVE-2017-1000024

Shotwell version 0.24.4 or earlier and 0.25.3 or earlier is vulnerable to an information disclosure in the web publishing plugins resulting in potent…

Fix: after 0.25.3
Fix from $1,950 2017-07-17
Impala HIGH 7.5
CVE-2017-5652

During a routine security analysis, it was found that one of the ports in Apache Impala (incubating) 2.7.0 to 2.8.0 sent data in plaintext even when …

Mitigation only
Fix from $1,950 2017-07-10
Serverprotect HIGH 7.4
CVE-2017-9035

Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows attackers to eavesdrop and tamper with updates by leveraging unencrypted communications…

Patch available
Fix from $1,950 2017-05-26
Oxygenos MEDIUM 5.9
CVE-2017-8850

An issue was discovered on OnePlus One, X, 2, 3, and 3T devices. Due to a lenient updater-script in the OnePlus OTA images, and the fact that both RO…

No fix yet
Fix from $1,600 2017-05-11