Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.4
CVE-2023-40729
A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application lacks security control to prevent unencrypted…
Qms Automotive
12.39+
HIGH 8.1
CVE-2023-34998
An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A specially craft…
Oas Platform
Mitigation only
MEDIUM 5.9
CVE-2023-22870
IBM Aspera Faspex 5.0.5 transmits sensitive information in cleartext which could be obtained by an attacker using man in the middle techniques. IBM …
Aspera Faspex
after 5.0.5
MEDIUM 5.3
CVE-2023-25848
ArcGIS Enterprise Server versions 11.0 and below have an information disclosure vulnerability where a remote, unauthorized attacker may submit a craf…
Arcgis Server
after 11.0
MEDIUM 6.5
CVE-2023-34972
A cleartext transmission of sensitive information vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability p…
Qts
5.0.1.2425 / 5.1.0.2444+
MEDIUM 6.3
CVE-2023-36671
An issue was discovered in the Clario VPN client through 5.9.1.1662 for macOS. The VPN client insecurely configures the operating system such that al…
Vpn
after 5.9.1.1662
MEDIUM 5.7
CVE-2023-36672
An issue was discovered in the Clario VPN client through 5.9.1.1662 for macOS. The VPN client insecurely configures the operating system such that tr…
Vpn
after 5.9.1.1662
HIGH 7.3
CVE-2023-36673
An issue was discovered in Avira Phantom VPN through 2.23.1 for macOS. The VPN client insecurely configures the operating system such that all IP tra…
Phantom Vpn
after 2.23.1
HIGH 7.5
CVE-2023-39086
ASUS RT-AC66U B1 3.0.0.4.286_51665 was discovered to transmit sensitive information in cleartext.
Rt Ac66u B1 Firmware
Mitigation only
MEDIUM 6.8
CVE-2023-2754
The Cloudflare WARP client for Windows assigns loopback IPv4 addresses for the DNS Servers, since WARP acts as local DNS server that performs DNS que…
Warp
2023.7.160.0+
HIGH 7.5
CVE-2023-3763
A vulnerability was found in Intergard SGS 8.7.0. It has been declared as problematic. This vulnerability affects unknown code of the component SQL Q…
Smartgard Silver With Matrix Keyboard
No fix yet
HIGH 7.5
CVE-2023-3761
A vulnerability was found in Intergard SGS 8.7.0 and classified as problematic. Affected by this issue is some unknown functionality of the component…
Smartgard Silver With Matrix Keyboard
Mitigation only
HIGH 7.5
CVE-2023-34142
Cleartext Transmission of Sensitive Information vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Server, Device Manager Agen…
Device Manager
8.8.5-02+
MEDIUM 6.5
CVE-2023-35833
An issue was discovered in YSoft SAFEQ 6 Server before 6.0.82. When modifying the URL of the LDAP server configuration from LDAPS to LDAP, the system…
Safeq Server
6.0.82+
HIGH 7.5
CVE-2023-31823
An issue found in Marui Co Marui Official app v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token …
Marui
No fix yet
HIGH 7.5
CVE-2023-3272
Cleartext Transmission of Sensitive Information in the SICK ICR890-4 could allow a
remote attacker to gather sensitive information by intercepting ne…
Icr890 4 Firmware
2.5.0+
HIGH 7.5
CVE-2023-21219
there is a possible use of unencrypted transport over cellular networks due to an insecure default value. This could lead to remote information discl…
Android
Mitigation only
HIGH 7.5
CVE-2023-21220
there is a possible use of unencrypted transport over cellular networks due to an insecure default value. This could lead to remote information discl…
Android
Mitigation only
HIGH 7.4
CVE-2023-31410
A remote unprivileged attacker can intercept the communication via e.g. Man-In-The-Middle, due to the absence of Transport Layer Security (TLS) in th…
Sick Eventcam App
Mitigation only
HIGH 7.5
CVE-2023-23841
SolarWinds Serv-U is submitting an HTTP request when changing or updating the attributes for File Share or File request. Part of the URL of the requ…
Serv U
15.4+
MEDIUM 5.3
CVE-2023-31195
ASUS Router RT-AX3000 Firmware versions prior to 3.0.0.4.388.23403 uses sensitive cookies without 'Secure' attribute. When an attacker is in a positi…
Rt Ax3000 Firmware
3.0.0.4.388.23403+
MEDIUM 5.9
CVE-2023-27861
IBM Maximo Application Suite - Manage Component 8.8.0 and 8.9.0 transmits sensitive information in cleartext that could be intercepted by an attacker…
Maximo Application Suite
Mitigation only
HIGH 7.5
CVE-2023-30602
Hitron Technologies CODA-5310’s Telnet function transfers sensitive data in plaintext. An unauthenticated remote attacker can exploit this vulnerabil…
Coda 5310 Firmware
Mitigation only
HIGH 7.5
CVE-2023-33960
OpenProject is web-based project management software. For any OpenProject installation, a `robots.txt` file is generated through the server to denote…
Openproject
12.5.6+
CRITICAL 9.8
CVE-2023-3028
Insufficient authentication in the MQTT backend (broker) allows an attacker to access and even manipulate the telemetry data of the entire fleet of v…
Hqt401 Firmware
Mitigation only
CRITICAL 9.8
CVE-2023-33730
Privilege Escalation in the "GetUserCurrentPwd" function in Microworld Technologies eScan Management Console 14.0.1400.2281 allows any remote attacke…
Escan Management Console
No fix yet
HIGH 7.4
CVE-2023-28348
An issue was discovered in Faronics Insight 10.0.19045 on Windows. A suitably positioned attacker could perform a man-in-the-middle attack on either …
Insight
No fix yet
MEDIUM 6.5
CVE-2023-33187
Highlight is an open source, full-stack monitoring platform. Highlight may record passwords on customer deployments when a password html input is swi…
Highlight
6.0.0+
HIGH 7.5
CVE-2023-31193
Snap One OvrC Pro versions prior to 7.3 use HTTP connections when downloading a program from their servers. Because they do not use HTTPS, OvrC Pro d…
Orvc
7.3.0+
CRITICAL 9.8
CVE-2022-46680
A CWE-319: Cleartext transmission of sensitive information vulnerability exists that could
cause disclosure of sensitive information, denial of servi…
Powerlogic Ion9000 Firmware
4.0.0+