Vulnerability index

Browse CVEs

798 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cleartext TransmissionCWE-319 × clear
Unclassified CRITICAL 10.0
CVE-2025-47419

Cleartext Transmission of Sensitive Information vulnerability in Crestron Automate VX allows Sniffing Network Traffic. The device allows Web UI and …

Mitigation only
Fix from $2,300 2025-05-06
Mesh Firmware MEDIUM 6.5
CVE-2025-32884

An issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. By default, a GID is the user's phone number unless they specific…

Mitigation only
Fix from $1,600 2025-05-01
Mesh Firmware MEDIUM 6.5
CVE-2025-32887

An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. A command channel includes the next hop. which can be intercepted a…

Mitigation only
Fix from $1,600 2025-05-01
Mesh Firmware MEDIUM 6.5
CVE-2025-32881

An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. By default, the GID is the user's phone number unless they specific…

Mitigation only
Fix from $1,600 2025-05-01
Unclassified HIGH 8.7
CVE-2025-42603

This vulnerability exists in the Meon KYC solutions due to transmission of sensitive data in plain text within the response payloads of certain API e…

Mitigation only
Fix from $1,950 2025-04-23
Toolbox HIGH 7.5
CVE-2025-43013

In JetBrains Toolbox App before 2.6 unencrypted credential transmission during SSH authentication was possible

Fix: 2.6+
Fix from $1,950 2025-04-17
Unclassified MEDIUM 5.9
CVE-2025-27722

Cleartext transmission of sensitive information issue exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, a man-in-the-middle attack may allo…

Mitigation only
Fix from $1,600 2025-04-09
Unclassified MEDIUM 6.8
CVE-2025-26654

SAP Commerce Cloud (Public Cloud) does not allow to disable unencrypted HTTP (port 80) entirely, but instead allows a redirect from port 80 to 443 (H…

Mitigation only
Fix from $1,600 2025-04-08
Satech Bcu Firmware HIGH 7.5
CVE-2025-2861

SaTECH BCU in its firmware version 2.1.3 uses the HTTP protocol. The use of the HTTP protocol for web browsing has the problem that information is ex…

Mitigation only
Fix from $1,950 2025-03-28
Unclassified MEDIUM 6.5
CVE-2024-45361

A protocol flaw vulnerability exists in the Xiaomi Mi Connect Service APP. The vulnerability is caused by the validation logic is flawed and can be e…

Mitigation only
Fix from $1,600 2025-03-27
Unclassified CRITICAL 9.0
CVE-2025-2311

Incorrect Use of Privileged APIs, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in Sechard Info…

Mitigation only
Fix from $2,300 2025-03-20
Phpipam HIGH 7.5
CVE-2024-10718

In phpipam/phpipam version 1.5.1, the Secure attribute for sensitive cookies in HTTPS sessions is not set. This could cause the user agent to send th…

Fix: 1.7.0+
Fix from $1,950 2025-03-20
Ipados HIGH 7.3
CVE-2024-44276

This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in iOS 18.2 and iPadOS 18.2. A user in a privi…

Fix: 18.2+
Fix from $1,950 2025-03-17
Unclassified HIGH 7.5
CVE-2025-27594

The device uses an unencrypted, proprietary protocol for communication. Through this protocol, configuration data is transmitted and device authentic…

Mitigation only
Fix from $1,950 2025-03-14
Box Firmware HIGH 7.5
CVE-2024-13872

Bitdefender Box, versions 1.3.11.490 through 1.3.11.505, uses the insecure HTTP protocol to download assets over the Internet to update and restart d…

Fix: after 1.3.11.505
Fix from $1,950 2025-03-12
Unclassified MEDIUM 5.6
CVE-2025-22493

Secure flag not set and SameSIte was set to Lax in the Foreseer Reporting Software (FRS). Absence of this secure flag could lead into the session coo…

Mitigation only
Fix from $1,600 2025-03-05
Unclassified HIGH 7.1
CVE-2025-24849

Lack of encryption in transit for cloud infrastructure facilitating potential for sensitive data manipulation or exposure.

No fix yet
Fix from $1,950 2025-02-28
Unclassified MEDIUM 6.5
CVE-2025-25728

Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 were discovered to send communications to the update API i…

Mitigation only
Fix from $1,600 2025-02-28
C7800 Firmware MEDIUM 6.4
CVE-2022-41545

The administrative web interface of a Netgear C7800 Router running firmware version 6.01.07 (and possibly others) authenticates users via basic authe…

Mitigation only
Fix from $1,600 2025-02-18
Fabric Operating System HIGH 7.5
CVE-2024-5462

If Brocade Fabric OS before Fabric OS 9.2.0 configuration settings are not set to encrypt SNMP passwords, then the SNMP privsecret / authsecret field…

Fix: 9.2.0+
Fix from $1,950 2025-02-15
Unclassified HIGH 7.5
CVE-2025-1060

CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists that could result in the exposure of data when network traffic is being…

Mitigation only
Fix from $1,950 2025-02-13
Telerik Report Server MEDIUM 6.5
CVE-2025-0556

In Progress® Telerik® Report Server, versions prior to 2025 Q1 (11.0.25.211) when using the older .NET Framework implementation, communication of non…

Fix: 11.0.25.211+
Fix from $1,600 2025-02-12
Unclassified HIGH 7.5
CVE-2024-36558

Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h suffers from Cleartext Transmission of Sensitive Information due to …

Mitigation only
Fix from $1,950 2025-02-06
Security Verify Access HIGH 7.5
CVE-2024-43187

IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 transmits sensitive or security-critical data in cleartext in a communicatio…

Fix: 10.0.9.0+
Fix from $1,950 2025-02-04
Clearpass Policy Manager HIGH 8.1
CVE-2025-23060

A vulnerability in HPE Aruba Networking ClearPass Policy Manager may, under certain circumstances, expose sensitive unencrypted information. Exploiti…

Fix: 6.11.10 / 6.12.4+
Fix from $1,950 2025-02-04
Security Verify Governance MEDIUM 5.9
CVE-2023-35017

IBM Security Verify Governance 10.0.2 Identity Manager can transmit user credentials in clear text that could be obtained by an attacker using man in…

Mitigation only
Fix from $1,600 2025-01-29
Incontrol Web MEDIUM 5.9
CVE-2025-0784

A vulnerability has been found in Intelbras InControl up to 2.21.58 and classified as problematic. This vulnerability affects unknown code of the fil…

Fix: 2.21.59+
Fix from $1,600 2025-01-28
Unclassified HIGH 8.7
CVE-2025-0631

A Credential Exposure Vulnerability exists in the above-mentioned product and version. The vulnerability is due to using HTTP resulting in credential…

Mitigation only
Fix from $1,950 2025-01-28
Unclassified MEDIUM 5.7
CVE-2025-0432

EWON Flexy 202 transmits user credentials in clear text with no encryption when a user is added, or user credentials are changed via its webpage.

Mitigation only
Fix from $1,600 2025-01-28
Qradar Security Information And Event Manager MEDIUM 6.5
CVE-2024-28786

IBM QRadar SIEM 7.5 transmits sensitive or security-critical data in cleartext in a communication channel that could be obtained by an unauthorized a…

Mitigation only
Fix from $1,600 2025-01-28