Vulnerability index

Browse CVEs

798 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cleartext TransmissionCWE-319 × clear
Unclassified HIGH 8.2
CVE-2024-31206

dectalk-tts is a Node package to interact with the aeiou Dectalk web API. In `[email protected]`, network requests to the third-party API are sent ov…

Patch available
Fix from $1,950 2024-04-04
Unclassified MEDIUM 6.5
CVE-2024-28275

Puwell Cloud Tech Co, Ltd 360Eyes Pro v3.9.5.16(3090516) was discovered to transmit sensitive information in cleartext. This vulnerability allows att…

No fix yet
Fix from $1,600 2024-04-03
Powerscale Onefs HIGH 7.8
CVE-2024-25960

Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains a cleartext transmission of sensitive information vulnerability. A local low privileg…

Fix: 9.4.0.17 / 9.5.0.8+
Fix from $1,950 2024-03-28
Apollo Vx20 Firmware CRITICAL 9.1
CVE-2024-25735EPSS 51%

An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext passwords via a SoftAP /device/config…

Fix: 1.3.58+
Fix from $2,300 2024-03-27
Cilium MEDIUM 6.1
CVE-2024-28249

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.13.13, 1.14.8, and 1.15.2, in Cilium c…

Fix: 1.13.13 / 1.14.8+
Fix from $1,600 2024-03-18
Cilium MEDIUM 6.1
CVE-2024-28250

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.14.0 and prior to versions 1.14.8 an…

Fix: 1.14.8 / 1.15.2+
Fix from $1,600 2024-03-18
Edgeaggregator HIGH 7.5
CVE-2024-0860

The affected product is vulnerable to a cleartext transmission of sensitive information vulnerability, which may allow an attacker to capture packets…

Mitigation only
Fix from $1,950 2024-03-14
Distributed Engine MEDIUM 5.9
CVE-2024-25650

Insecure key exchange between Delinea PAM Secret Server 11.4 and the Distributed Engine 8.4.3 allows a PAM administrator to obtain the Symmetric Key …

Mitigation only
Fix from $1,600 2024-03-14
Charx Sec 3000 Firmware HIGH 8.7
CVE-2024-26288

An unauthenticated remote attacker can influence the communication due to the lack of encryption of sensitive data via a MITM. Charging is not affect…

Fix: 1.5.1+
Fix from $1,950 2024-03-12
Watson Cp4d Data Stores HIGH 7.5
CVE-2023-27291

IBM Watson CP4D Data Stores 4.6.0, 4.6.1, 4.6.2, and 4.6.3 does not encrypt sensitive or critical information before storage or transmission which co…

Mitigation only
Fix from $1,950 2024-03-03
Mq Operator MEDIUM 5.5
CVE-2023-47745

IBM MQ Operator 2.0.0 LTS, 2.0.18 LTS, 3.0.0 CD, 3.0.1 CD, 2.4.0 through 2.4.7, 2.3.0 through 2.3.3, 2.2.0 through 2.2.2, and 2.3.0 through 2.3.3 sto…

Fix: after 2.4.7
Fix from $1,600 2024-03-03
Cloud Pak For Security MEDIUM 5.9
CVE-2021-39090

IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 could allow a remote attacker to obtain sensitive information, caused by the failure to p…

Fix: 1.10.7.0+
Fix from $1,600 2024-02-29
Automation Studio HIGH 8.1
CVE-2024-0220

B&R Automation Studio Upgrade Service and B&R Technology Guarding use insufficient cryptography for communication to the upgrade and the licensing se…

Fix: 1.4.0 / 4.6+
Fix from $1,950 2024-02-22
Cilium MEDIUM 5.3
CVE-2024-25631

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who have enabled an external kvstore and …

Fix: 1.14.7+
Fix from $1,600 2024-02-20
Cilium MEDIUM 5.3
CVE-2024-25630

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who are using CRDs to store Cilium state …

Fix: 1.14.7+
Fix from $1,600 2024-02-20
Enterprise Storage Integrator For Sap Landscape Management CRITICAL 9.8
CVE-2023-39245

DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability in EHAC component. An remote un…

Fix: 10.0.0.0+
Fix from $2,300 2024-02-15
Windows 10 1607 HIGH 7.5
CVE-2024-21406

Windows Printing Service Spoofing Vulnerability

Fix: 10.0.14393.6709 / 10.0.17763.5458+
Fix from $1,950 2024-02-13
Security Verify Access CRITICAL 9.8
CVE-2023-32328

IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure protocols in some instances that could allow an attacker on the network to take co…

Fix: after 10.0.6.1
Fix from $2,300 2024-02-07
L206 F2g Firmware MEDIUM 5.7
CVE-2023-40544

An attacker with access to the network where the affected devices are located could maliciously actions to obtain, via a sniffer, sensitive informati…

Mitigation only
Fix from $1,600 2024-02-06
Powersc HIGH 7.5
CVE-2023-50962

IBM PowerSC 1.3, 2.0, and 2.1 MFA does not implement the "HTTP Strict Transport Security" (HSTS) web security policy mechanism. IBM X-Force ID: 276…

Mitigation only
Fix from $1,950 2024-02-02
Trv Firmware MEDIUM 5.5
CVE-2023-42144

Cleartext Transmission during initial setup in Shelly TRV 20220811-15234 v.2.1.8 allows a local attacker to obtain the Wi-Fi password.

Mitigation only
Fix from $1,600 2024-01-23
Msh30q Firmware MEDIUM 5.7
CVE-2023-46889

Meross MSH30Q 4.5.23 is vulnerable to Cleartext Transmission of Sensitive Information. During the device setup phase, the MSH30Q creates an unprotect…

Mitigation only
Fix from $1,600 2024-01-23
E880 Ir01 Firmware HIGH 7.5
CVE-2023-50614

An issue discovereed in EBYTE E880-IR01-V1.1 allows an attacker to obtain sensitive information via crafted POST request to /cgi-bin/luci.

No fix yet
Fix from $1,950 2024-01-18
Cm5100 Firmware HIGH 7.5
CVE-2023-51741

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to transmission of authentication credentials in plaintext over the network…

Mitigation only
Fix from $1,950 2024-01-17
Cm5100 Firmware HIGH 7.5
CVE-2023-51740

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to transmission of authentication credentials in plaintext over the network…

Mitigation only
Fix from $1,950 2024-01-17
Microsoft.data.sqlclient HIGH 8.7
CVE-2024-0056

Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability

Fix: 2.1.7 / 3.1.5+
Fix from $1,950 2024-01-09
Oncell G3150a Lte Firmware MEDIUM 5.3
CVE-2023-6094

A vulnerability has been identified in OnCell G3150A-LTE Series firmware versions v1.3 and prior. The vulnerability results from lack of protection f…

Fix: after 1.3
Fix from $1,600 2023-12-31
Cash Point \& Transport Optimizer HIGH 7.5
CVE-2023-31300

An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive informa…

Mitigation only
Fix from $1,950 2023-12-29
Tapo MEDIUM 6.5
CVE-2023-34829

Incorrect access control in TP-Link Tapo before v3.1.315 allows attackers to access user credentials in plaintext.

Fix: 3.1.315+
Fix from $1,600 2023-12-28
Stormshield Network Security HIGH 7.5
CVE-2023-28616

An issue was discovered in Stormshield Network Security (SNS) before 4.3.17, 4.4.x through 4.6.x before 4.6.4, and 4.7.x before 4.7.1. It affects use…

Fix: 4.3.17 / 4.6.4+
Fix from $1,950 2023-12-26