Vulnerability index

Browse CVEs

798 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cleartext TransmissionCWE-319 × clear
Helpflash Iot Firmware MEDIUM 6.6
CVE-2025-65855

The OTA firmware update mechanism in Netun Solutions HelpFlash IoT (firmware v18_178_221102_ASCII_PRO_1R5_50) uses hard-coded WiFi credentials identi…

Mitigation only
Fix from $1,600 2025-12-17
Hcl Devops Deploy MEDIUM 5.9
CVE-2025-62330

HCL DevOps Deploy is susceptible to a cleartext transmission of sensitive information because the HTTP port remains accessible and does not redirect …

Fix: 8.1.2.4+
Fix from $1,600 2025-12-16
Gom Player HIGH 8.8
CVE-2023-53875

GOM Player 2.3.90.5360 contains a remote code execution vulnerability in its Internet Explorer component that allows attackers to execute arbitrary c…

No fix yet
Fix from $1,950 2025-12-15
Reyee Os HIGH 8.1
CVE-2023-53881

ReyeeOS 1.204.1614 contains an unencrypted CWMP communication vulnerability that allows attackers to intercept and manipulate device communication th…

No fix yet
Fix from $1,950 2025-12-15
Devops Deploy MEDIUM 5.9
CVE-2025-13489

IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 IBM DevOps Deploy transmits data in clear text that could allow an attacker to obtain sensitive infor…

Fix: 8.1.2.4+
Fix from $1,600 2025-12-15
Meatmeet CRITICAL 9.1
CVE-2025-65827

The mobile application is configured to allow clear text traffic to all domains and communicates with an API server over HTTP. As a result, an advers…

Mitigation only
Fix from $2,300 2025-12-10
Solstice Pod Firmware HIGH 7.5
CVE-2025-66573

Solstice Pod API (version 5.5, 6.2) contains an unauthenticated API endpoint (`/api/config`) that exposes sensitive information such as the session k…

No fix yet
Fix from $1,950 2025-12-04
Rs232\/485 To Wifi Eth \(b\) Firmware HIGH 7.5
CVE-2025-63364

Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.002880.0301 was discovered to t…

No fix yet
Fix from $1,950 2025-12-04
Diris M 70 Firmware HIGH 7.5
CVE-2024-48894

A cleartext transmission vulnerability exists in the WEBVIEW-M functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted HTTP request c…

Mitigation only
Fix from $1,950 2025-12-01
Keros HIGH 7.4
CVE-2024-32384

Kerlink gateways running KerOS prior to version 5.10 expose their web interface exclusively over HTTP, without HTTPS support. This lack of transport …

Fix: 5.10+
Fix from $1,950 2025-12-01
Unclassified HIGH 7.5
CVE-2025-62765

General Industrial Controls Lynx+ Gateway is vulnerable to a cleartext transmission vulnerability that could allow an attacker to observe network tr…

Mitigation only
Fix from $1,950 2025-11-15
Unclassified HIGH 8.4
CVE-2025-12508

When using domain users as BRAIN2 users, communication with Active Directory services is unencrypted. This can lead to the interception of authentica…

Mitigation only
Fix from $1,950 2025-10-31
Unclassified HIGH 8.3
CVE-2025-64389

The web server of the device performs exchanges of sensitive information in clear text through an insecure protocol.

Mitigation only
Fix from $1,950 2025-10-31
Log Server CRITICAL 9.8
CVE-2025-34271

Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the cluster manager component when requesting sensitive credentials from pe…

Fix: 2024+
Fix from $2,300 2025-10-30
Unclassified CRITICAL 10.0
CVE-2025-61481

An issue in MikroTik RouterOS v.7.14.2 and SwOS v.2.18 exposes the WebFig management interface over cleartext HTTP by default, allowing an on-path at…

Mitigation only
Fix from $2,300 2025-10-27
Unclassified CRITICAL 9.8
CVE-2025-56447

TM2 Monitoring v3.04 contains an authentication bypass and plaintext credential disclosure.

Mitigation only
Fix from $2,300 2025-10-22
Unclassified HIGH 7.1
CVE-2025-10641

All WorkExaminer Professional traffic between monitoring client, console and server is transmitted as plain text. This allows an attacker with access…

Mitigation only
Fix from $1,950 2025-10-21
Restaurant Brands International Assistant HIGH 8.6
CVE-2025-62643

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 transmits passwords of user accounts in cleartext e-mail messages.

Fix: after 2025-09-06
Fix from $1,950 2025-10-17
Automate HIGH 7.5
CVE-2025-11492

In the ConnectWise Automate Agent, communications could be configured to use HTTP instead of HTTPS. In such cases, an on-path threat actor with a man…

Fix: 2025.9+
Fix from $1,950 2025-10-16
Windows 10 21h2 HIGH 7.1
CVE-2025-53139

Cleartext transmission of sensitive information in Windows Hello allows an unauthorized attacker to bypass a security feature locally.

Fix: 10.0.19044.6456 / 10.0.19045.6456+
Fix from $1,950 2025-10-14
Unclassified HIGH 7.5
CVE-2025-41718

A cleartext transmission of sensitive information vulnerability in the affected products allows an unauthorized remote attacker to gain login credent…

Mitigation only
Fix from $1,950 2025-10-14
Furbo Mini Firmware MEDIUM 5.3
CVE-2025-11640

A vulnerability was found in Tomofun Furbo 360 and Furbo Mini. This affects an unknown function of the component Bluetooth Low Energy. The manipulati…

Fix: after 074
Fix from $1,600 2025-10-12
Flock Safety MEDIUM 6.2
CVE-2025-59406

The Flock Safety Pisco com.flocksafety.android.pisco application 6.21.11 for Android (installed on Falcon and Sparrow License Plate Readers and Bravo…

No fix yet
Fix from $1,600 2025-10-02
Aspera Http Gateway HIGH 7.5
CVE-2025-36274

IBM Aspera HTTP Gateway 2.0.0 through 2.3.1 stores sensitive information in clear text in easily obtainable files which can be read by an unauthentic…

Fix: 2.3.2+
Fix from $1,950 2025-09-26
Unclassified MEDIUM 6.5
CVE-2025-10540

iMonitor EAM 9.6394 transmits communication between the EAM client agent and the EAM server, as well as between the EAM monitor management software a…

Mitigation only
Fix from $1,600 2025-09-25
Unclassified HIGH 8.0
CVE-2025-54818

Cognex In-Sight Explorer and In-Sight Camera Firmware expose a proprietary protocol on TCP port 1069 to perform management operations such as modi…

Mitigation only
Fix from $1,950 2025-09-18
Unclassified HIGH 8.6
CVE-2025-47698

An adjacent attacker without authentication can exploit this vulnerability to retrieve a set of user-privileged credentials. These credentials are pr…

Mitigation only
Fix from $1,950 2025-09-18
Omaspot CRITICAL 9.6
CVE-2025-7743

Cleartext Transmission of Sensitive Information vulnerability in Dolusoft Omaspot allows Interception, Privilege Escalation. This issue affects Omas…

Fix: 12.09.2025+
Fix from $2,300 2025-09-16
Unclassified HIGH 8.8
CVE-2025-50110

An issue was discovered in the method push.lite.avtech.com.AvtechLib.GetHttpsResponse in AVTECH EagleEyes Lite 2.0.0, the GetHttpsResponse method tra…

Mitigation only
Fix from $1,950 2025-09-15
Iwr 3000n Firmware HIGH 8.4
CVE-2025-55976

Intelbras IWR 3000N 1.9.8 exposes the Wi-Fi password in plaintext via the /api/wireless endpoint. Any unauthenticated user on the local network can d…

Fix: after 1.9.8
Fix from $1,950 2025-09-10