Vulnerability index

Browse CVEs

798 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cleartext TransmissionCWE-319 × clear
HIGH 7.5 CVE-2023-32784 In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a workspace is locked or no longer … Keepass 2.54+ Fix from $1,9502023-05-15 CRITICAL 9.8 CVE-2023-30354 Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 does not defend against physical access to U-Boot via the UART: the Wi-Fi password is sho… Cp3 Firmware Mitigation only Fix from $2,3002023-05-10 MEDIUM 6.5 CVE-2023-25070 Cleartext transmission of sensitive information exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier. If the telnet connection is enabled,… Skybridge Mb A110 Firmware after 4.2.0 Fix from $1,6002023-05-10 HIGH 7.5 CVE-2023-32290 The myMail app through 14.30 for iOS sends cleartext credentials in a situation where STARTTLS is expected by a server. Mymail after 14.30 Fix from $1,9502023-05-07 MEDIUM 5.7 CVE-2023-29680 Cleartext Transmission in set-cookie:ecos_pw: Tenda N301 v6.0, Firmware v12.02.01.61_multi allows an authenticated attacker on the LAN or WLAN to int… N301 Firmware No fix yet Fix from $1,6002023-05-01 MEDIUM 5.7 CVE-2023-29681 Cleartext Transmission in cookie:ecos_pw: in Tenda N301 v6.0, firmware v12.03.01.06_pt allows an authenticated attacker on the LAN or WLAN to interce… N301 Firmware No fix yet Fix from $1,6002023-05-01 HIGH 8.8 CVE-2023-25437EPSS 14% An issue was discovered in vTech VCS754 version 1.1.1.A before 1.1.1.H, allows attackers to gain escalated privileges and gain sensitive information … Vcs754a Firmware 1.1.1.h+ Fix from $1,9502023-04-27 MEDIUM 5.5 CVE-2023-30841 Baremetal Operator (BMO) is a bare metal host provisioning integration for Kubernetes. Prior to version 0.3.0, ironic and ironic-inspector deployed w… Baremetal Operator 0.3.0+ Fix from $1,6002023-04-26 HIGH 7.5 CVE-2023-1831 Mattermost fails to redact from audit logs the user password during user creation and the user password hash in other operations if the experimental … Mattermost Server 7.7.3 / 7.8.2+ Fix from $1,9502023-04-17 MEDIUM 5.9 CVE-2019-14942 An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.1.6. Cookies for GitLab Pages… GitLab 11.11.8 / 12.0.6+ Fix from $1,6002023-04-16 HIGH 7.5 CVE-2023-30514 Jenkins Azure Key Vault Plugin 187.va_cd5fecd198a_ and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log whe… Azure Key Vault after 187.va_cd5fecd198a Fix from $1,9502023-04-12 HIGH 7.5 CVE-2023-30515 Jenkins Thycotic DevOps Secrets Vault Plugin 1.0.0 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log whe… Thycotic Devops Secrets Vault after 1.0.0 Fix from $1,9502023-04-12 HIGH 7.5 CVE-2023-30513 Jenkins Kubernetes Plugin 3909.v1f2c633e8590 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push… Kubernetes after 3909.v1f2c633e8590 Fix from $1,9502023-04-12 HIGH 7.5 CVE-2023-1802 In Docker Desktop 4.17.x the Artifactory Integration falls back to sending registry credentials over plain HTTP if the HTTPS health check has failed.… Desktop No fix yet Fix from $1,9502023-04-06 MEDIUM 5.9 CVE-2023-0922 The Samba AD DC administration tool, when operating against a remote LDAP server, will by default send new or reset passwords over a signed-only conn… Samba 4.16.10 / 4.17.7+ Fix from $1,6002023-04-03 HIGH 7.5 CVE-2023-1656 Cleartext Transmission of Sensitive Information vulnerability in ForgeRock Inc. OpenIDM and Java Remote Connector Server (RCS) LDAP Connector on Wind… Ldap Connector 1.5.20.14+ Fix from $1,9502023-03-29 MEDIUM 6.5 CVE-2023-27927 An authenticated malicious user could acquire the simple mail transfer protocol (SMTP) Password in cleartext format, despite it being protected and h… Ey As525f001 Firmware Mitigation only Fix from $1,6002023-03-27 MEDIUM 5.9 CVE-2022-38458 A cleartext transmission vulnerability exists in the Remote Management functionality of Netgear Orbi Router RBR750 4.6.8.5. A specially-crafted man-i… Rbs750 Firmware No fix yet Fix from $1,6002023-03-21 HIGH 7.5 CVE-2023-0053 SAUTER Controls Nova 200–220 Series with firmware version 3.3-006 and prior and BACnetstac version 4.2.1 and prior have only FTP and Telnet availab… Nova 220 Eyk220f001 Firmware after 4.2.1 Fix from $1,9502023-03-02 MEDIUM 5.3 CVE-2022-32906 This issue was addressed with using HTTPS when sending information over the network. This issue is fixed in Apple Music 3.9.10 for Android. A user in… Music 3.9.10+ Fix from $1,6002023-02-27 CRITICAL 9.1 CVE-2023-23914 A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs a… Curl 7.88.0 / 8.2.12+ Fix from $2,3002023-02-23 MEDIUM 6.5 CVE-2023-23915 A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrectly whe… Curl 7.88.0 / 8.2.12+ Fix from $1,6002023-02-23 HIGH 7.5 CVE-2022-45546 Information Disclosure in Authentication Component of ScreenCheck BadgeMaker 2.6.2.0 application allows internal attacker to obtain credentials for a… Badgemaker No fix yet Fix from $1,9502023-02-15 HIGH 7.5 CVE-2023-22806 LS ELECTRIC XBC-DN32U with operating system version 01.80 transmits sensitive information in cleartext when communicating over its XGT protocol. This… Xbc Dn32u Firmware Mitigation only Fix from $1,9502023-02-15 MEDIUM 6.7 CVE-2023-0001 An information exposure vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local system administrator to disclose t… Cortex Xdr Agent 7.5.101+ Fix from $1,6002023-02-08 HIGH 7.5 CVE-2022-40693 A cleartext transmission vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A speciall… Sds 3008 Firmware after 2.1 Fix from $1,9502023-02-07 HIGH 7.5 CVE-2023-25016 Couchbase Server before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2 exposes Sensitive Information to an Unauthorized Actor. Couchbase Server 6.6.6 / 7.0.5+ Fix from $1,9502023-02-06 MEDIUM 5.9 CVE-2023-23130 Connectwise Automate 2022.11 is vulnerable to Cleartext authentication. Authentication is being done via HTTP (cleartext) with SSL disabled. OTE: the… Automate Mitigation only Fix from $1,6002023-02-01 CRITICAL 9.8 CVE-2022-47714 Last Yard 22.09.8-1 does not enforce HSTS headers Last Yard No fix yet Fix from $2,3002023-02-01 MEDIUM 5.5 CVE-2023-24440 Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier transmits the private key in plain text as part of the global Jenkins configurat… Jira Pipeline Steps after 2.0.165.v8846cf59f3db Fix from $1,6002023-01-26