Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.1
CVE-2019-16732
Unencrypted HTTP communications for firmware upgrades in Petalk AI and PF-103 allow man-in-the-middle attackers to run arbitrary code as the root use…
Petalk Ai Firmware
No fix yet
MEDIUM 5.9
CVE-2019-18285
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The RMI communication between the client…
Sppa T3000 Application Server
No fix yet
MEDIUM 5.3
CVE-2019-19251
The Last.fm desktop app (Last.fm Scrobbler) through 2.1.39 on macOS makes HTTP requests that include an API key without the use of SSL/TLS. Although …
Last.fm Desktop
after 2.1.39
CRITICAL 9.8
CVE-2019-16672
An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 dev…
Ie Sw Pl09m 5gc 4gt Firmware
after 3.4.4
MEDIUM 5.3
CVE-2015-7542
A vulnerability exists in libgwenhywfar through 4.12.0 due to the usage of outdated bundled CA certificates.
Debian Linux
after 4.12.0
HIGH 7.5
CVE-2019-19316
When using the Azure backend with a shared access signature (SAS), Terraform versions prior to 0.12.17 may transmit the token and state snapshot usin…
Terraform
0.12.17+
HIGH 8.6
CVE-2012-5562
A flaw was found in rhn-proxy. This vulnerability may allow the rhn-proxy to transmit user credentials in clear-text when it accesses RHN Satellite. …
Satellite
5.6+
CRITICAL 9.8
CVE-2019-12503
Due to unencrypted and unauthenticated data communication, the wireless barcode scanner Inateck BCST-60 is prone to keystroke injection attacks. Thus…
Bcst 60 Firmware
No fix yet
HIGH 7.5
CVE-2019-12388
Anviz access control devices perform cleartext transmission of sensitive information (passwords/pins and names) when replying to query on port tcp/50…
Anviz Firmware
Mitigation only
MEDIUM 5.3
CVE-2019-19463
The Anhui Huami Mi Fit application before 4.0.11 for Android has an Unencrypted Update Check.
Mi Fit
4.0.11+
MEDIUM 6.5
CVE-2019-16545
Jenkins QMetry for JIRA - Test Management Plugin transmits credentials in its configuration in plain text as part of job configuration forms, potenti…
Jenkins Qmetry For Jira
after 1.12
MEDIUM 5.5
CVE-2012-1257
Pidgin 2.10.0 uses DBUS for certain cleartext communication, which allows local users to obtain sensitive information via a dbus session monitor.
Pidgin
Mitigation only
MEDIUM 6.5
CVE-2019-3640
Unprotected Transport of Credentials in ePO extension in McAfee Data Loss Prevention 11.x prior to 11.4.0 allows remote attackers with access to the …
Data Loss Prevention
after 11.4.0
MEDIUM 5.5
CVE-2010-4177
mysql-gui-tools (mysql-query-browser and mysql-admin) before 5.0r14+openSUSE-2.3 exposes the password of a user connected to the MySQL server in clea…
Fedora
5.0r14+
CRITICAL 9.8
CVE-2019-18852
Certain D-Link devices have a hardcoded Alphanetworks user account with TELNET access because of /etc/config/image_sign or /etc/alpha_config/image_si…
Dir 600 B1 Firmware
No fix yet
HIGH 8.8
CVE-2019-18800
Viber through 11.7.0.5 allows a remote attacker who can capture a victim's internet traffic to steal their Viber account, because not all Viber proto…
Viber
after 11.7.0.5
HIGH 7.5
CVE-2019-6845
A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists in Modicon M580, Modicon M340, Modicon Premium , Modicon Quantum (all…
Modicon M580 Firmware
Mitigation only
MEDIUM 6.5
CVE-2019-6846
A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modules (all…
Modicon M580 Firmware
Mitigation only
HIGH 7.5
CVE-2019-18201
An issue was discovered on Fujitsu Wireless Keyboard Set LX390 GK381 devices. Because of the lack of proper encryption of 2.4 GHz communication, an a…
Lx390 Firmware
No fix yet
MEDIUM 6.6
CVE-2019-18199
An issue was discovered on Fujitsu Wireless Keyboard Set LX390 GK381 devices. Because of the lack of proper encryption of 2.4 GHz communication, and …
Lx390 Firmware
No fix yet
MEDIUM 6.5
CVE-2019-12967
Stephan Mooltipass Moolticute through 0.42.1 (and possibly earlier versions) has Incorrect Access Control.
Moolticute
after 0.42.1
CRITICAL 9.8
CVE-2019-17393
The Customer's Tomedo Server in Version 1.7.3 communicates to the Vendor Tomedo Server via HTTP (in cleartext) that can be sniffed by unauthorized ac…
Server
No fix yet
HIGH 7.5
CVE-2019-15626
The Deep Security Manager application (Versions 10.0, 11.0 and 12.0), when configured in a certain way, may transmit initial LDAP communication in cl…
Deep Security
Patch available
MEDIUM 6.5
CVE-2019-17356
The Infinite Design application 3.4.12 for Android sends a username and password via TCP without any encryption during login, as demonstrated by snif…
Infinite Design
No fix yet
HIGH 7.8
CVE-2019-9532
The web application portal of the Cobham EXPLORER 710, firmware version 1.07, sends the login password in cleartext. This could allow an unauthentica…
Explorer 710 Firmware
Mitigation only
MEDIUM 5.5
CVE-2019-0069
On EX4600, QFX5100 Series, NFX Series, QFX10K Series, QFX5110, QFX5200 Series, QFX5110, QFX5200, QFX10K Series, vSRX, SRX1500, SRX4000 Series, vSRX, …
Junos
Mitigation only
MEDIUM 6.8
CVE-2019-14808
An issue was discovered in the RENPHO application 3.0.0 for iOS. It transmits JSON data unencrypted to a server without an integrity check, if a user…
Renpho
No fix yet
CRITICAL 9.1
CVE-2019-17218
An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. By default, the communication to the web service i…
Combi Stream Mslq Firmware
Mitigation only
MEDIUM 5.9
CVE-2019-14959
JetBrains Toolbox before 1.15.5605 was resolving an internal URL via a cleartext http connection.
Toolbox
1.15.5605+
HIGH 7.5
CVE-2019-0231
Handling of the close_notify SSL/TLS message does not lead to a connection closure, leading the server to retain the socket opened and to have the cl…
Mina
Mitigation only