Vulnerability index

Browse CVEs

800 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cleartext TransmissionCWE-319 × clear
HIGH 8.1 CVE-2020-14157 The wireless-communication feature of the ABUS Secvest FUBE50001 device does not encrypt sensitive data such as PIN codes or IDs of used proximity ch… Secvest Wireless Control Fube50001 Firmware No fix yet Fix from $1,9502020-06-17 MEDIUM 5.9 CVE-2020-14093 Mutt before 1.14.3 allows an IMAP fcc/postpone man-in-the-middle attack via a PREAUTH response. Ubuntu Linux 1.14.3+ Fix from $1,6002020-06-15 HIGH 8.1 CVE-2020-11614 Mids' Reborn Hero Designer 2.6.0.7 downloads the update manifest, as well as update files, over cleartext HTTP. Additionally, the application does no… Mids\' Reborn Hero Designer No fix yet Fix from $1,9502020-06-11 MEDIUM 5.9 CVE-2020-1343 An information disclosure vulnerability exists in Visual Studio Code Live Share Extension when it exposes tokens in plain text, aka 'Visual Studio Co… Visual Studio Live Share Patch available Fix from $1,6002020-06-09 HIGH 7.5 CVE-2020-13787 D-Link DIR-865L Ax 1.20B01 Beta devices have Cleartext Transmission of Sensitive Information. Dir 865l Firmware No fix yet Fix from $1,9502020-06-03 HIGH 8.8 CVE-2020-2013 A cleartext transmission of sensitive information vulnerability in Palo Alto Networks PAN-OS Panorama that discloses an authenticated PAN-OS administ… Pan Os 8.1.13 / 9.0.6+ Fix from $1,9502020-05-13 MEDIUM 5.9 CVE-2019-4667 IBM UrbanCode Deploy (UCD) 7.0.5.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Stric… Urbancode Deploy Mitigation only Fix from $1,6002020-05-11 MEDIUM 5.3 CVE-2020-4092 "If port encryption is not enabled on the Domino Server, HCL Nomad on Android and iOS Platforms will communicate in clear text and does not currently… Hcl Nomad Mitigation only Fix from $1,6002020-05-06 CRITICAL 9.1 CVE-2020-5885 On versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, and 12.1.0-12.1.5.1, BIG-IP systems set up for connection mirroring in a high availabi… Big Ip Access Policy Manager after 15.1.0.1 Fix from $2,3002020-04-30 CRITICAL 9.1 CVE-2020-5886 On versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, and 12.1.0-12.1.5.1, BIG-IP systems setup for connection mirroring in a High Availabil… Big Ip Access Policy Manager after 15.1.0.1 Fix from $2,3002020-04-30 HIGH 8.1 CVE-2020-5876 On BIG-IP 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, a race condition exists where mcpd and other proce… Big Ip Access Policy Manager after 15.1.0.3 Fix from $1,9502020-04-30 HIGH 7.5 CVE-2020-5879 On BIG-IP ASM 11.6.1-11.6.5.1, under certain configurations, the BIG-IP system sends data plane traffic to back-end servers unencrypted, even when a … Big Ip Application Security Manager after 11.6.5.1 Fix from $1,9502020-04-30 HIGH 8.1 CVE-2020-5867 In versions prior to 3.3.0, the NGINX Controller Agent installer script 'install.sh' uses HTTP instead of HTTPS to check and install packages Nginx Controller 3.3.0+ Fix from $1,9502020-04-23 HIGH 7.5 CVE-2020-7488 A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists which could leak sensitive information transmitted between the softwa… Ecostruxure Machine Expert Mitigation only Fix from $1,9502020-04-22 MEDIUM 5.5 CVE-2019-19107 The Configuration pages in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway for user profiles and services transfer the passwo… Tg\/s3.2 Firmware Mitigation only Fix from $1,6002020-04-22 HIGH 8.1 CVE-2020-11539 An issue was discovered on Tata Sonata Smart SF Rush 1.12 devices. It has been identified that the smart band has no pairing (mode 0 Bluetooth LE sec… Sf Rush Smart Band Firmware No fix yet Fix from $1,9502020-04-22 HIGH 7.5 CVE-2020-11685 In JetBrains GoLand before 2019.3.2, the plugin repository was accessed via HTTP instead of HTTPS. Goland 2019.3.2+ Fix from $1,9502020-04-22 HIGH 7.5 CVE-2020-7483 **VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability could cause certain data to be visible on the network when the 'password' feature is enabled.… Tristation 1131 after 4.12.0 Fix from $1,9502020-04-16 MEDIUM 5.9 CVE-2019-4594 IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict… Qradar Security Information And Event Manager 7.3.3+ Fix from $1,6002020-04-15 CRITICAL 9.8 CVE-2020-6195 SAP Business Objects Business Intelligence Platform (CMC), version 4.1, 4.2, shows cleartext password in the response, leading to Information Disclos… Businessobjects Business Intelligence Platform Mitigation only Fix from $2,3002020-04-14 HIGH 7.5 CVE-2020-11557 An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It includes the username and password values in cleartext within each… Snmpc Online 2020-01-28+ Fix from $1,9502020-04-09 CRITICAL 9.8 CVE-2020-11542 3xLOGIC Infinias eIDC32 2.213 devices with Web 1.107 allow Authentication Bypass via CMD.HTM?CMD= because authentication depends on the client side's… Infinias Eidc32 Firmware No fix yet Fix from $2,3002020-04-04 HIGH 8.1 CVE-2020-5860 On BIG-IP 15.0.0-15.1.0.2, 14.1.0-14.1.2.3, 13.1.0-13.1.3.2, 12.1.0-12.1.5.1, and 11.5.2-11.6.5.1 and BIG-IQ 7.0.0, 6.0.0-6.1.0, and 5.2.0-5.4.0, in … Big Iq Centralized Management after 15.1.0 Fix from $1,9502020-03-27 HIGH 8.1 CVE-2019-19127 An authentication bypass vulnerability is present in the standalone SITS:Vision 9.7.0 component of Tribal SITS in its default configuration, related … Sits\ No fix yet Fix from $1,9502020-03-25 HIGH 7.5 CVE-2020-6997 In Moxa EDS-G516E Series firmware, Version 5.2 or lower, sensitive information is transmitted over some web applications in cleartext. Eds G516e Firmware after 5.2 Fix from $1,9502020-03-24 HIGH 7.5 CVE-2020-7003 In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, sensitive information is tran… Iologik 2512 Firmware after 3.0 Fix from $1,9502020-03-24 HIGH 7.5 CVE-2019-16063 NETSAS Enigma NMS 65.0.0 and prior does not encrypt sensitive data rendered within web pages. It is possible for an attacker to expose unencrypted se… Enigma Network Management Solution after 65.0.0 Fix from $1,9502020-03-19 HIGH 7.5 CVE-2019-16067 NETSAS Enigma NMS 65.0.0 and prior utilises basic authentication over HTTP for enforcing access control to the web application. The use of weak authe… Enigma Network Management Solution after 65.0.0 Fix from $1,9502020-03-19 MEDIUM 6.5 CVE-2019-12122 An issue was discovered in ONAP Portal through Dublin. By executing a call to ONAPPORTAL/portalApi/loggedinUser, an attacker who possesses a user's c… Open Network Automation Platform 4.0.0+ Fix from $1,6002020-03-18 CRITICAL 9.8 CVE-2019-13394 The Voo branded NETGEAR CG3700b custom firmware V2.02.03 uses HTTP Basic Authentication over cleartext HTTP. Cg3700b Firmware No fix yet Fix from $2,3002020-03-13