Vulnerability index

Browse CVEs

798 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cleartext TransmissionCWE-319 × clear
HIGH 7.4 CVE-2023-40729 A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application lacks security control to prevent unencrypted… Qms Automotive 12.39+ Fix from $1,9502023-09-12 HIGH 8.1 CVE-2023-34998 An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A specially craft… Oas Platform Mitigation only Fix from $1,9502023-09-05 MEDIUM 5.9 CVE-2023-22870 IBM Aspera Faspex 5.0.5 transmits sensitive information in cleartext which could be obtained by an attacker using man in the middle techniques. IBM … Aspera Faspex after 5.0.5 Fix from $1,6002023-09-05 MEDIUM 5.3 CVE-2023-25848 ArcGIS Enterprise Server versions 11.0 and below have an information disclosure vulnerability where a remote, unauthorized attacker may submit a craf… Arcgis Server after 11.0 Fix from $1,6002023-08-25 MEDIUM 6.5 CVE-2023-34972 A cleartext transmission of sensitive information vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability p… Qts 5.0.1.2425 / 5.1.0.2444+ Fix from $1,6002023-08-24 MEDIUM 6.3 CVE-2023-36671 An issue was discovered in the Clario VPN client through 5.9.1.1662 for macOS. The VPN client insecurely configures the operating system such that al… Vpn after 5.9.1.1662 Fix from $1,6002023-08-09 MEDIUM 5.7 CVE-2023-36672 An issue was discovered in the Clario VPN client through 5.9.1.1662 for macOS. The VPN client insecurely configures the operating system such that tr… Vpn after 5.9.1.1662 Fix from $1,6002023-08-09 HIGH 7.3 CVE-2023-36673 An issue was discovered in Avira Phantom VPN through 2.23.1 for macOS. The VPN client insecurely configures the operating system such that all IP tra… Phantom Vpn after 2.23.1 Fix from $1,9502023-08-09 HIGH 7.5 CVE-2023-39086 ASUS RT-AC66U B1 3.0.0.4.286_51665 was discovered to transmit sensitive information in cleartext. Rt Ac66u B1 Firmware Mitigation only Fix from $1,9502023-08-08 MEDIUM 6.8 CVE-2023-2754 The Cloudflare WARP client for Windows assigns loopback IPv4 addresses for the DNS Servers, since WARP acts as local DNS server that performs DNS que… Warp 2023.7.160.0+ Fix from $1,6002023-08-03 HIGH 7.5 CVE-2023-3763 A vulnerability was found in Intergard SGS 8.7.0. It has been declared as problematic. This vulnerability affects unknown code of the component SQL Q… Smartgard Silver With Matrix Keyboard No fix yet Fix from $1,9502023-07-19 HIGH 7.5 CVE-2023-3761 A vulnerability was found in Intergard SGS 8.7.0 and classified as problematic. Affected by this issue is some unknown functionality of the component… Smartgard Silver With Matrix Keyboard Mitigation only Fix from $1,9502023-07-19 HIGH 7.5 CVE-2023-34142 Cleartext Transmission of Sensitive Information vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Server, Device Manager Agen… Device Manager 8.8.5-02+ Fix from $1,9502023-07-18 MEDIUM 6.5 CVE-2023-35833 An issue was discovered in YSoft SAFEQ 6 Server before 6.0.82. When modifying the URL of the LDAP server configuration from LDAPS to LDAP, the system… Safeq Server 6.0.82+ Fix from $1,6002023-07-13 HIGH 7.5 CVE-2023-31823 An issue found in Marui Co Marui Official app v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token … Marui No fix yet Fix from $1,9502023-07-13 HIGH 7.5 CVE-2023-3272 Cleartext Transmission of Sensitive Information in the SICK ICR890-4 could allow a remote attacker to gather sensitive information by intercepting ne… Icr890 4 Firmware 2.5.0+ Fix from $1,9502023-07-10 HIGH 7.5 CVE-2023-21219 there is a possible use of unencrypted transport over cellular networks due to an insecure default value. This could lead to remote information discl… Android Mitigation only Fix from $1,9502023-06-28 HIGH 7.5 CVE-2023-21220 there is a possible use of unencrypted transport over cellular networks due to an insecure default value. This could lead to remote information discl… Android Mitigation only Fix from $1,9502023-06-28 HIGH 7.4 CVE-2023-31410 A remote unprivileged attacker can intercept the communication via e.g. Man-In-The-Middle, due to the absence of Transport Layer Security (TLS) in th… Sick Eventcam App Mitigation only Fix from $1,9502023-06-19 HIGH 7.5 CVE-2023-23841 SolarWinds Serv-U is submitting an HTTP request when changing or updating the attributes for File Share or File request.  Part of the URL of the requ… Serv U 15.4+ Fix from $1,9502023-06-15 MEDIUM 5.3 CVE-2023-31195 ASUS Router RT-AX3000 Firmware versions prior to 3.0.0.4.388.23403 uses sensitive cookies without 'Secure' attribute. When an attacker is in a positi… Rt Ax3000 Firmware 3.0.0.4.388.23403+ Fix from $1,6002023-06-13 MEDIUM 5.9 CVE-2023-27861 IBM Maximo Application Suite - Manage Component 8.8.0 and 8.9.0 transmits sensitive information in cleartext that could be intercepted by an attacker… Maximo Application Suite Mitigation only Fix from $1,6002023-06-05 HIGH 7.5 CVE-2023-30602 Hitron Technologies CODA-5310’s Telnet function transfers sensitive data in plaintext. An unauthenticated remote attacker can exploit this vulnerabil… Coda 5310 Firmware Mitigation only Fix from $1,9502023-06-02 HIGH 7.5 CVE-2023-33960 OpenProject is web-based project management software. For any OpenProject installation, a `robots.txt` file is generated through the server to denote… Openproject 12.5.6+ Fix from $1,9502023-06-01 CRITICAL 9.8 CVE-2023-3028 Insufficient authentication in the MQTT backend (broker) allows an attacker to access and even manipulate the telemetry data of the entire fleet of v… Hqt401 Firmware Mitigation only Fix from $2,3002023-06-01 CRITICAL 9.8 CVE-2023-33730 Privilege Escalation in the "GetUserCurrentPwd" function in Microworld Technologies eScan Management Console 14.0.1400.2281 allows any remote attacke… Escan Management Console No fix yet Fix from $2,3002023-05-31 HIGH 7.4 CVE-2023-28348 An issue was discovered in Faronics Insight 10.0.19045 on Windows. A suitably positioned attacker could perform a man-in-the-middle attack on either … Insight No fix yet Fix from $1,9502023-05-31 MEDIUM 6.5 CVE-2023-33187 Highlight is an open source, full-stack monitoring platform. Highlight may record passwords on customer deployments when a password html input is swi… Highlight 6.0.0+ Fix from $1,6002023-05-26 HIGH 7.5 CVE-2023-31193 Snap One OvrC Pro versions prior to 7.3 use HTTP connections when downloading a program from their servers. Because they do not use HTTPS, OvrC Pro d… Orvc 7.3.0+ Fix from $1,9502023-05-22 CRITICAL 9.8 CVE-2022-46680 A CWE-319: Cleartext transmission of sensitive information vulnerability exists that could cause disclosure of sensitive information, denial of servi… Powerlogic Ion9000 Firmware 4.0.0+ Fix from $2,3002023-05-22