Vulnerability index

Browse CVEs

798 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cleartext TransmissionCWE-319 × clear
MEDIUM 5.9 CVE-2023-22863 IBM Robotic Process Automation 20.12.0 through 21.0.2 defaults to HTTP in some RPA commands when the prefix is not explicitly specified in the URL. … Robotic Process Automation 21.0.3+ Fix from $1,6002023-01-18 MEDIUM 5.9 CVE-2023-22597 InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CW… Inrouter302 Firmware 2.3.0.r5542 / 3.5.56+ Fix from $1,6002023-01-12 MEDIUM 6.0 CVE-2022-23509 Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. GitOps r… Weave Gitops 0.12.0+ Fix from $1,6002023-01-09 CRITICAL 9.8 CVE-2022-3929 Communication between the client and the server application of the affected products is partially done using CORBA (Common Object Request Broker Arch… Foxman Un Mitigation only Fix from $2,3002023-01-05 MEDIUM 5.3 CVE-2023-0055 Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository pyload/pyload prior to 0.5.0b3.dev32. Pyload Patch available Fix from $1,6002023-01-04 HIGH 7.5 CVE-2022-43551EPSS 17% A vulnerability exists in curl <7.87.0 HSTS check that could be bypassed to trick it to keep using HTTP. Using its HSTS support, curl can be instruct… Curl 7.87.0 / 8.2.12+ Fix from $1,9502022-12-23 HIGH 8.8 CVE-2022-22758 When clicking on a tel: link, USSD codes, specified after a <code>\*</code> character, would be included in the phone number. On certain phones, or o… Firefox 97.0+ Fix from $1,9502022-12-22 HIGH 7.5 CVE-2022-47895 In JetBrains IntelliJ IDEA before 2022.3.1 the "Validate JSP File" action used the HTTP protocol to download required JAR files. Intellij Idea 2022.3.1+ Fix from $1,9502022-12-22 MEDIUM 5.3 CVE-2022-42454 Insights for Vulnerability Remediation (IVR) is vulnerable to man-in-the-middle attacks that may lead to information disclosure.  This requires privi… Bigfix Insights For Vulnerability Remediation after 2.0 Fix from $1,6002022-12-21 HIGH 7.5 CVE-2021-4258 A vulnerability was found in whohas. It has been rated as problematic. This issue affects some unknown processing of the component Package Informatio… Whohas 2021-11-01+ Fix from $1,9502022-12-19 MEDIUM 5.9 CVE-2020-4497 IBM Spectrum Protect Plus 10.1.0 through 10.1.12 discloses sensitive information due to unencrypted data being used in the communication flow between… Spectrum Protect Plus 10.1.13+ Fix from $1,6002022-12-14 MEDIUM 6.5 CVE-2020-9420 The login password of the web administrative dashboard in Arcadyan Wifi routers VRV9506JAC23 is sent in cleartext, allowing an attacker to sniff and … Vrv9506jac23 Firmware No fix yet Fix from $1,6002022-12-14 CRITICAL 9.8 CVE-2022-43724 A vulnerability has been identified in SICAM PAS/PQS (All versions < V7.0). Affected software transmits the database credentials for the inbuilt SQL … Sicam Pas\/pqs 7.0+ Fix from $2,3002022-12-13 MEDIUM 5.3 CVE-2022-45877 OpenHarmony-v3.1.4 and prior versions had an vulnerability. PIN code is transmitted to the peer device in plain text during cross-device authenticati… Openharmony after 3.1.4 Fix from $1,6002022-12-08 MEDIUM 5.9 CVE-2022-45478 Telepad allows an attacker (in a man-in-the-middle position between the server and a connected device) to see all data (including keypresses) in clea… Telepad after 1.0.7 Fix from $1,6002022-12-05 MEDIUM 5.9 CVE-2022-45480 PC Keyboard WiFi & Bluetooth allows an attacker (in a man-in-the-middle position between the server and a connected device) to see all data (includin… Pc Keyboard Wifi \& Bluetooth after 30 Fix from $1,6002022-12-02 MEDIUM 5.9 CVE-2022-45483 Lazy Mouse allows an attacker (in a man in the middle position between the server and a connected device) to see all data (including keypresses) in c… Lazy Mouse after 2.0.1 Fix from $1,6002022-12-02 HIGH 7.5 CVE-2022-44411 Web Based Quiz System v1.0 transmits user passwords in plaintext during the authentication process, allowing attackers to obtain users' passwords via… Web Based Quiz System No fix yet Fix from $1,9502022-11-25 MEDIUM 5.3 CVE-2021-35246 The application fails to prevent users from connecting to it over unencrypted connections. An attacker able to modify a legitimate user's network tra… Engineer\'s Toolset Patch available Fix from $1,6002022-11-23 MEDIUM 5.3 CVE-2022-43691 Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 inadvertently disclose server-side sensitive information (secrets in envir… Concrete Cms 8.5.10+ Fix from $1,6002022-11-14 MEDIUM 5.3 CVE-2021-38828 Xiongmai Camera XM-JPR2-LX V4.02.R12.A6420987.10002.147502.00000 is vulnerable to plain-text traffic sniffing. Xm Jpr2 Lx Firmware after 4.02.r12.a6420987.10002.147502.00000 Fix from $1,6002022-11-14 HIGH 7.5 CVE-2022-38122 UPSMON PRO transmits sensitive data in cleartext over HTTP protocol. An unauthenticated remote attacker can exploit this vulnerability to access sens… Upsmon Pro Mitigation only Fix from $1,9502022-11-10 CRITICAL 9.8 CVE-2022-33321 Cleartext Transmission of Sensitive Information vulnerability due to the use of Basic Authentication for HTTP connections in Mitsubishi Electric cons… Mac 557if E Firmware Mitigation only Fix from $2,3002022-11-08 HIGH 7.5 CVE-2021-45447 Hitachi Vantara Pentaho Business Analytics Server versions before 9.3.0.0, 9.2.0.2 and 8.3.0.25 with the Data Lineage feature enabled transmits data… Vantara Pentaho 8.3.0.25 / 9.2.0.2+ Fix from $1,9502022-11-02 HIGH 7.5 CVE-2022-42916 In curl before 7.86.0, the HSTS check could be bypassed to trick it into staying with HTTP. Using its HSTS support, curl can be instructed to use HTT… Curl 7.86.0 / 8.2.12+ Fix from $1,9502022-10-29 HIGH 7.5 CVE-2022-41636 Communication traffic involving "Ethernet Q Commands" service of Haas Controller version 100.20.000.1110 is transmitted in cleartext. This allows an … Haas Controller Mitigation only Fix from $1,9502022-10-28 HIGH 7.6 CVE-2022-41627 The physical IoT device of the AliveCor's KardiaMobile, a smartphone-based personal electrocardiogram (EKG) has no encryption for its data-over-sound… Kardiamobile Firmware Mitigation only Fix from $1,9502022-10-27 MEDIUM 5.9 CVE-2022-3206 The Passster WordPress plugin before 3.5.5.5.2 stores the password inside a cookie named "passster" using base64 encoding method which is easy to dec… Passster 3.5.5.5.2+ Fix from $1,6002022-10-17 MEDIUM 6.5 CVE-2022-39287 tiny-csrf is a Node.js cross site request forgery (CSRF) protection middleware. In versions prior to 1.1.0 cookies were not encrypted and thus CSRF t… Tiny Csrf 1.1.0+ Fix from $1,6002022-10-07 CRITICAL 9.1 CVE-2022-39269 PJSIP is a free and open source multimedia communication library written in C. When processing certain packets, PJSIP may incorrectly switch from usi… Pjsip 2.13+ Fix from $2,3002022-10-06