Vulnerability index

Browse CVEs

798 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cleartext TransmissionCWE-319 × clear
Concert MEDIUM 5.9
CVE-2024-41757

IBM Concert Software 1.0.0 and 1.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Str…

Mitigation only
Fix from $1,600 2025-01-24
Remote Access Server Firmware HIGH 8.6
CVE-2024-26155

All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 expose clear text credentials in the web portal. An attacker can access the …

Fix: 4.5.0+
Fix from $1,950 2025-01-17
Unclassified MEDIUM 6.5
CVE-2024-48121

The HI-SCAN 6040i Hitrax HX-03-19-I was discovered to transmit user credentials in cleartext over the GIOP protocol. This allows attackers to possibl…

Mitigation only
Fix from $1,600 2025-01-15
Unclassified MEDIUM 6.8
CVE-2024-45102

A privilege escalation vulnerability was discovered that could allow a valid, authenticated LXCA user to escalate their permissions for a connected X…

No fix yet
Fix from $1,600 2025-01-14
Dryice Myxalytics HIGH 7.5
CVE-2024-42181

HCL MyXalytics is affected by a cleartext transmission of sensitive information vulnerability. The application transmits sensitive or security-criti…

Mitigation only
Fix from $1,950 2025-01-12
Unclassified CRITICAL 9.1
CVE-2024-46505

Infoblox BloxOne v2.4 was discovered to contain a business logic flaw due to thick client vulnerabilities.

Mitigation only
Fix from $2,300 2025-01-09
Truenas Firmware MEDIUM 6.5
CVE-2024-11946

iXsystems TrueNAS CORE fetch_plugin_packagesites tar Cleartext Transmission of Sensitive Information Vulnerability. This vulnerability allows network…

Mitigation only
Fix from $1,600 2024-12-30
Cognos Analytics Mobile HIGH 7.5
CVE-2021-39081

IBM Cognos Analytics Mobile for Android 1.1.14 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sens…

Mitigation only
Fix from $1,950 2024-12-19
Unclassified MEDIUM 5.7
CVE-2024-10973

A vulnerability was found in Keycloak. The environment option `KC_CACHE_EMBEDDED_MTLS_ENABLED` does not work and the JGroups replication configuratio…

Mitigation only
Fix from $1,600 2024-12-17
Security Guardium Key Lifecycle Manager HIGH 7.5
CVE-2024-49819

IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information in cleartext i…

Mitigation only
Fix from $1,950 2024-12-17
Splunk HIGH 7.5
CVE-2024-53246

In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions below 9.3.2408.101, 9.2.2406.106, 9.2.2403.111, and 9.…

Fix: 9.1.7 / 9.1.2312.206+
Fix from $1,950 2024-12-10
Aspect Ent 2 Firmware HIGH 8.1
CVE-2024-6515

Web browser interface may manipulate application username/password in clear text or Base64 encoding providing a higher probability of unintended cre…

Fix: 3.08.03+
Fix from $1,950 2024-12-05
Cognos Controller MEDIUM 5.9
CVE-2021-29892

IBM Cognos Controller 11.0.0 and 11.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP …

Mitigation only
Fix from $1,600 2024-12-03
Unclassified CRITICAL 9.3
CVE-2024-9834

Improper data protection on the ventilator's serial interface could allow an attacker to send and receive messages that result in unauthorized disclo…

Mitigation only
Fix from $2,300 2024-11-14
Unclassified MEDIUM 5.4
CVE-2024-28169

Cleartext transmission of sensitive information for some BigDL software maintained by Intel(R) before version 2.5.0 may allow an authenticated user t…

Mitigation only
Fix from $1,600 2024-11-13
Moodle MEDIUM 5.3
CVE-2024-43432

A flaw was found in moodle. The cURL wrapper in Moodle strips HTTPAUTH and USERPWD headers during emulated redirects, but retains other original requ…

Fix: 4.1.12 / 4.2.9+
Fix from $1,600 2024-11-11
Watcharr HIGH 8.8
CVE-2024-50634

A vulnerability in a weak JWT token in Watcharr v1.43.0 and below allows attackers to perform privilege escalation using a crafted JWT token. This vu…

Fix: after 1.43.0
Fix from $1,950 2024-11-08
Wbr 6012 Firmware MEDIUM 5.9
CVE-2024-32946

A vulnerability in the LevelOne WBR-6012 router's firmware version R0.40e6 allows sensitive information to be transmitted in cleartext via Web and FT…

Mitigation only
Fix from $1,600 2024-10-30
Unclassified MEDIUM 5.9
CVE-2024-50624

ispdbservice.cpp in KDE Kmail before 6.2.0 allows man-in-the-middle attackers to trigger use of an attacker-controlled mail server because cleartext …

Mitigation only
Fix from $1,600 2024-10-28
Unclassified MEDIUM 5.3
CVE-2024-40595

An authentication-bypass issue in the RDP component of One Identity Safeguard for Privileged Sessions (SPS) On Premise before 7.5.1 (and LTS before 7…

Mitigation only
Fix from $1,600 2024-10-24
Cyber Protect HIGH 7.5
CVE-2024-49387

Cleartext transmission of sensitive information in acep-collector service. The following products are affected: Acronis Cyber Protect 16 (Linux, Wind…

Fix: after 15
Fix from $1,950 2024-10-15
Unclassified HIGH 7.5
CVE-2024-48788

An issue in YESCAM (com.yescom.YesCam.zwave) 1.0.2 allows a remote attacker to obtain sensitive information via the firmware update process.

Mitigation only
Fix from $1,950 2024-10-11
Taipy MEDIUM 6.5
CVE-2024-47833

Taipy is an open-source Python library for easy, end-to-end application development for data scientists and machine learning engineers. In affected v…

Fix: 4.0.0+
Fix from $1,600 2024-10-09
Unclassified MEDIUM 5.3
CVE-2024-9620

A flaw was found in Event-Driven Automation (EDA) in Ansible Automation Platform (AAP), which lacks encryption of sensitive information. An attacker …

Mitigation only
Fix from $1,600 2024-10-08
Unclassified HIGH 8.7
CVE-2024-47789

** UNSUPPORTED WHEN ASSIGNED ** This vulnerability exists in D3D Security IP Camera D8801 due to usage of weak authentication scheme of the HTTP head…

Mitigation only
Fix from $1,950 2024-10-04
Chatgpt Assistant HIGH 7.5
CVE-2024-7713

The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 discloses the Open AI API Key, allowing unauthenticated users …

Fix: 2.1.0+
Fix from $1,950 2024-09-27
Gotenna Pro MEDIUM 6.5
CVE-2024-47124

The goTenna Pro App does not encrypt callsigns in messages. It is recommended to not use sensitive information in callsigns when using this and pre…

Fix: 2.0.3+
Fix from $1,600 2024-09-26
Unclassified MEDIUM 6.8
CVE-2024-45101

A privilege escalation vulnerability was discovered when Single Sign On (SSO) is enabled that could allow an attacker to intercept a valid, authentic…

Mitigation only
Fix from $1,600 2024-09-13
Workspace Control HIGH 7.8
CVE-2024-44105

Cleartext transmission of sensitive information in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a loc…

Fix: 10.18.99.0+
Fix from $1,950 2024-09-10
Sterling Connect Direct Web Services MEDIUM 5.9
CVE-2024-39746

IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 could allow a remote attacker to obtain sensitive information, caused by the failure …

Mitigation only
Fix from $1,600 2024-08-22