Vulnerability index

Browse CVEs

798 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cleartext TransmissionCWE-319 × clear
HIGH 7.5 CVE-2023-51390 journalpump is a daemon that takes log messages from journald and pumps them to a given output. A logging vulnerability was found in journalpump whic… Journalpump 2.5.0+ Fix from $1,9502023-12-21 MEDIUM 5.9 CVE-2023-50703 An attacker with network access could perform a man-in-the-middle (MitM) attack and capture sensitive information to gain unauthorized access to the … Uc 500e Firmware No fix yet Fix from $1,6002023-12-20 CRITICAL 9.1 CVE-2023-39172 The affected devices transmit sensitive information unencrypted allowing a remote unauthenticated attacker to capture and modify network traffic. Senec Storage Box Firmware Mitigation only Fix from $2,3002023-12-07 MEDIUM 6.5 CVE-2023-24547 On affected platforms running Arista MOS, the configuration of a BGP password will cause the password to be logged in clear text that can be revealed… Mos after 0.39.4 Fix from $1,6002023-12-06 MEDIUM 5.3 CVE-2023-42579 Improper usage of insecure protocol (i.e. HTTP) in SogouSDK of Chinese Samsung Keyboard prior to versions 5.3.70.1 in Android 11, 5.4.60.49, 5.4.85.5… Samsung Keyboard 5.3.70.1 / 5.4.60.49+ Fix from $1,6002023-12-05 HIGH 7.5 CVE-2023-46383 LOYTEC electronics GmbH LINX Configurator (all versions) uses HTTP Basic Authentication, which transmits usernames and passwords in base64-encoded cl… L Inx Configurator No fix yet Fix from $1,9502023-11-30 HIGH 7.5 CVE-2023-46385 LOYTEC electronics GmbH LINX Configurator (all versions) is vulnerable to Insecure Permissions. An admin credential is passed as a value of URL param… L Inx Configurator No fix yet Fix from $1,9502023-11-30 CRITICAL 9.8 CVE-2023-6248 The Syrus4 IoT gateway utilizes an unsecured MQTT server to download and execute arbitrary commands, allowing a remote unauthenticated attacker to ex… Syrus 4g Iot Telematics Gateway Firmware Mitigation only Fix from $2,3002023-11-21 HIGH 7.5 CVE-2023-43503 A vulnerability has been identified in COMOS (All versions < V10.4.4). Caching system in the affected application leaks sensitive information such as… Comos 10.4.4+ Fix from $1,9502023-11-14 HIGH 7.5 CVE-2023-46382 LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) use cleartext HTTP for login. Linx 212 Firmware No fix yet Fix from $1,9502023-11-04 HIGH 7.5 CVE-2023-46380 LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) send password-change requests vi… Linx 212 Firmware No fix yet Fix from $1,9502023-11-04 HIGH 7.5 CVE-2017-7252 bcrypt password hashing in Botan before 2.1.0 does not correctly handle passwords with a length between 57 and 72 characters, which makes it easier f… Botan 2.1.0+ Fix from $1,9502023-11-03 MEDIUM 5.3 CVE-2023-5035 A vulnerability has been identified in PT-G503 Series firmware versions prior to v5.2, where the Secure attribute for sensitive cookies in HTTPS sess… Eds G503 Firmware 5.2+ Fix from $1,6002023-11-02 HIGH 8.8 CVE-2023-45321 The Android Client application, when enrolled with the define method 1 (the user manually inserts the server ip address), use HTTP protocol to retri… Ctrlx Hmi Web Panel Wr2107 Firmware Mitigation only Fix from $1,9502023-10-25 HIGH 7.5 CVE-2023-33837 IBM Security Verify Governance 10.0 does not encrypt sensitive or critical information before storage or transmission. IBM X-Force ID: 256020. Security Verify Governance Patch available Fix from $1,9502023-10-23 HIGH 7.5 CVE-2023-38276 IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in environment variables which could aid in further attacks against t… Cognos Dashboards On Cloud Pak For Data Patch available Fix from $1,9502023-10-22 HIGH 7.5 CVE-2023-38275 IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in container images which could lead to further attacks against the s… Cognos Dashboards On Cloud Pak For Data Patch available Fix from $1,9502023-10-22 MEDIUM 6.5 CVE-2023-41088 The affected product is vulnerable to a cleartext transmission of sensitive information vulnerability, which may allow an attacker with access to the… Dexgate Mitigation only Fix from $1,6002023-10-19 HIGH 8.2 CVE-2023-34441 Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05 contains a cleartext transmission vulnerability which could allow an attacker to… Bentley Nevada 3500 System Firmware Mitigation only Fix from $1,9502023-10-19 HIGH 7.5 CVE-2022-22385 IBM Security Verify Privilege On-Premises 11.5 could disclose sensitive information to an attacked due to the transmission of data in clear text. IB… Security Verify Privilege On Premises 11.5+ Fix from $1,9502023-10-17 MEDIUM 5.9 CVE-2023-5461 A vulnerability was found in Delta Electronics WPLSoft 2.51. It has been classified as problematic. Affected is an unknown function of the component … Wplsoft Mitigation only Fix from $1,6002023-10-09 MEDIUM 6.5 CVE-2023-5100 Cleartext Transmission of Sensitive Information in RDT400 in SICK APU allows an unprivileged remote attacker to retrieve potentially sensitive inform… Apu0200 Firmware 4.0.0.6+ Fix from $1,6002023-10-09 HIGH 7.5 CVE-2023-3361 A flaw was found in Red Hat OpenShift Data Science. When exporting a pipeline from the Elyra notebook pipeline editor as Python DSL or YAML, it reads… Openshift Data Science 1.28.1+ Fix from $1,9502023-10-04 HIGH 7.5 CVE-2022-47892 All versions of NetMan 204 could allow an unauthenticated remote attacker to read a file (config.cgi) containing sensitive information, like credenti… Netman 204 Firmware Mitigation only Fix from $1,9502023-10-03 HIGH 8.2 CVE-2023-43125 BIG-IP APM clients may send IP traffic outside of the VPN tunnel.  Note: Software versions which have reached End of Technical Support (EoTS) are not… Big Ip Access Policy Manager after 16.1.4 Fix from $1,9502023-09-27 HIGH 7.1 CVE-2023-43124 BIG-IP APM clients may send IP traffic outside of the VPN tunnel.  Note: Software versions which have reached End of Technical Support (EoTS) are not… Big Ip Access Policy Manager after 16.1.4 Fix from $1,9502023-09-27 HIGH 7.5 CVE-2023-42147 An issue in CloudExplorer Lite 1.3.1 allows an attacker to obtain sensitive information via the login key component. Cloudexplorer Lite No fix yet Fix from $1,9502023-09-20 MEDIUM 6.5 CVE-2022-47560 The lack of web request control on ekorCCP and ekorRCI devices allows a potential attacker to create custom requests to execute malicious actions whe… Ekorrci Firmware Mitigation only Fix from $1,6002023-09-20 HIGH 7.5 CVE-2022-3261 A flaw was found in OpenStack. Multiple components show plain-text passwords in /var/log/messages during the OpenStack overcloud update run, leading … Openstack Platform Mitigation only Fix from $1,9502023-09-15 HIGH 8.8 CVE-2023-4918 A flaw was found in the Keycloak package, more specifically org.keycloak.userprofile. When a user registers itself through registration flow, the "pa… Keycloak Mitigation only Fix from $1,9502023-09-12