Vulnerability index

Browse CVEs

798 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cleartext TransmissionCWE-319 × clear
Qradar Network Packet Capture MEDIUM 5.9
CVE-2024-31905

IBM QRadar Network Packet Capture 7.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP St…

Mitigation only
Fix from $1,600 2024-08-15
.net MEDIUM 6.5
CVE-2024-38167

.NET and Visual Studio Information Disclosure Vulnerability

Fix: 8.0.8 / 17.6.18+
Fix from $1,600 2024-08-13
Pm2.5 Pm10 Monitor Firmware MEDIUM 6.5
CVE-2024-7408

This vulnerability exists in Airveda Air Quality Monitor PM2.5 PM10 due to transmission of sensitive information in plain text during AP pairing mode…

Fix: 7.4.4.39+
Fix from $1,600 2024-08-12
Caterease HIGH 7.5
CVE-2024-38891

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform…

Fix: after 24.0.1.2405
Fix from $1,950 2024-08-02
Exacqvision Web Service HIGH 8.1
CVE-2024-32864

Under certain circumstances exacqVision Web Services will not enforce secure web communications (HTTPS)

Fix: after 24.03
Fix from $1,950 2024-08-01
Immudb HIGH 7.4
CVE-2024-41262

mmudb v1.9.3 was discovered to use the HTTP protocol in the ShowMetricsRaw and ShowMetricsAsText functions, possibly allowing attackers to intercept …

Mitigation only
Fix from $1,950 2024-07-31
Sy Gpon 1110 Wdont Firmware HIGH 7.5
CVE-2024-41687

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to transmission of password in plain text. A remote attacker could exploit this v…

Mitigation only
Fix from $1,950 2024-07-26
Octopus Server MEDIUM 6.5
CVE-2024-6972

In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the task log in clear-text.

Fix: 2024.1.12759 / 2024.2.9193+
Fix from $1,600 2024-07-25
Unclassified MEDIUM 6.3
CVE-2024-41124

Puncia is the Official CLI utility for Subdomain Center & Exploit Observer. `API_URLS` is utilizing HTTP instead of HTTPS for communication that can …

Patch available
Fix from $1,600 2024-07-19
Unclassified MEDIUM 6.0
CVE-2024-5631

Longse NVR (Network Video Recorder) model NVR3608PGE2W, as well as products based on this device, are transmitting user's login and password to a rem…

Mitigation only
Fix from $1,600 2024-07-09
Ubuntu Advantage Desktop Daemon MEDIUM 5.5
CVE-2024-6388

Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivileged users by passing the tok…

Fix: 1.12+
Fix from $1,600 2024-06-27
L210 F2g Firmware HIGH 7.5
CVE-2024-37183

Plain text credentials and session ID can be captured with a network sniffer.

Mitigation only
Fix from $1,950 2024-06-20
Unclassified MEDIUM 5.3
CVE-2024-0066

Johan Fagerström, member of the AXIS OS Bug Bounty Program, has found that a O3C feature may expose sensitive traffic between the client (Axis device…

No fix yet
Fix from $1,600 2024-06-18
Unclassified HIGH 7.4
CVE-2024-27166

Coredump binaries in Toshiba printers have incorrect permissions. A local attacker can steal confidential information. As for the affected products/m…

No fix yet
Fix from $1,950 2024-06-14
Unclassified MEDIUM 6.5
CVE-2024-27163

Toshiba printers will display the password of the admin user in clear-text and additional passwords when sending 2 specific HTTP requests to the inte…

Mitigation only
Fix from $1,600 2024-06-14
Sinec Traffic Analyzer MEDIUM 5.1
CVE-2024-35210

A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server is not enforcing HS…

Fix: 1.2+
Fix from $1,600 2024-06-11
Multi Factor Authentication Solutions HIGH 7.5
CVE-2024-37393

Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-supplied input. An unauthenticated…

Fix: 9.4.514+
Fix from $1,950 2024-06-10
Skyscraper HIGH 7.5
CVE-2024-37163

SkyScrape is a GUI Dashboard for AWS Infrastructure and Managing Resources and Usage Costs. SkyScrape's API requests are currently unsecured HTTP re…

Mitigation only
Fix from $1,950 2024-06-07
Unclassified HIGH 7.5
CVE-2024-36426

In TARGIT Decision Suite 23.2.15007.0 before Autumn 2023, the session token is part of the URL and may be sent in a cleartext HTTP session.

Mitigation only
Fix from $1,950 2024-05-27
Ait Core HIGH 7.5
CVE-2024-35059

An issue in the Pickle Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands.

Fix: after 2.5.2
Fix from $1,950 2024-05-21
Ait Core HIGH 7.5
CVE-2024-35060

An issue in the YAML Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands via supplying a crafted YAML file.

Fix: after 2.5.2
Fix from $1,950 2024-05-21
Ait Core HIGH 7.5
CVE-2024-35057

An issue in NASA AIT-Core v2.5.2 allows attackers to execute arbitrary code via a crafted packet.

Fix: after 2.5.2
Fix from $1,950 2024-05-21
Ait Core HIGH 7.5
CVE-2024-35058

An issue in the API wait function of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary code via supplying a crafted string.

Fix: after 2.5.2
Fix from $1,950 2024-05-21
Embrace MEDIUM 6.5
CVE-2024-31840

An issue was discovered in Italtel Embrace 1.6.4. The web application inserts cleartext passwords in the HTML source code. An authenticated user is a…

No fix yet
Fix from $1,600 2024-05-21
Unclassified CRITICAL 9.6
CVE-2024-30209

A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT278…

Mitigation only
Fix from $2,300 2024-05-14
Charx Sec 3000 Firmware HIGH 7.0
CVE-2024-28134

An unauthenticated remote attacker can extract a session token with a MitM attack and gain web-based management access with the privileges of the cur…

Fix: after 1.5.1
Fix from $1,950 2024-05-14
Chatrtx MEDIUM 5.5
CVE-2024-0098

NVIDIA ChatRTX for Windows contains a vulnerability in the ChatRTX UI and backend, where a user can cause a clear-text transmission of sensitive info…

Fix: 0.3+
Fix from $1,600 2024-05-14
Unclassified HIGH 7.1
CVE-2022-32510

An issue was discovered on certain Nuki Home Solutions devices. The HTTP API exposed by a Bridge used an unencrypted channel to provide an administra…

Mitigation only
Fix from $1,950 2024-05-14
Unclassified HIGH 8.1
CVE-2024-1657

A flaw was found in the ansible automation platform. An insecure WebSocket connection was being used in installation from the Ansible rulebook EDA se…

Mitigation only
Fix from $1,950 2024-04-25
Brocade Sannav HIGH 7.5
CVE-2024-4161

In Brocade SANnav, before Brocade SANnav v2.3.0, syslog traffic received clear text. This could allow an unauthenticated, remote attacker to captur…

Fix: 2.3.0+
Fix from $1,950 2024-04-25