Vulnerability index

Browse CVEs

800 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cleartext TransmissionCWE-319 × clear
MEDIUM 5.9 CVE-2019-14954 JetBrains IntelliJ IDEA before 2019.2 was resolving the markdown plantuml artifact download link via a cleartext http connection. Intellij Idea 2019.2+ Fix from $1,6002019-10-01 HIGH 7.5 CVE-2019-10435 Jenkins SourceGear Vault Plugin transmits configured credentials in plain text as part of job configuration forms, potentially resulting in their exp… Sourcegear Vault after 1.1.1 Fix from $1,9502019-10-01 HIGH 7.5 CVE-2019-10434 Jenkins LDAP Email Plugin transmits configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in t… Ldap Email after 0.8 Fix from $1,9502019-10-01 MEDIUM 5.3 CVE-2019-4280 IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 displays sensitive information in HTTP requests which could be used in further attacks against the … Sterling File Gateway after 6.0.1.0 Fix from $1,6002019-09-30 HIGH 8.8 CVE-2019-16924 The Nulock application 1.5.0 for mobile devices sends a cleartext password over Bluetooth, which allows remote attackers (after sniffing the network)… Nulock No fix yet Fix from $1,9502019-09-27 MEDIUM 6.5 CVE-2019-11739 Encrypted S/MIME parts in a crafted multipart/alternative message can leak plaintext when included in a a HTML reply/forward. This vulnerability affe… Thunderbird 60.9.0 / 68.1.0+ Fix from $1,6002019-09-27 MEDIUM 6.5 CVE-2019-6652 In BIG-IQ 6.0.0-6.1.0, services for stats do not require authentication nor do they implement any form of Transport Layer Security (TLS). Big Iq Centralized Management after 6.1.0 Fix from $1,6002019-09-25 MEDIUM 5.3 CVE-2019-10427 Jenkins Aqua MicroScanner Plugin 1.0.7 and earlier transmitted configured credentials in plain text as part of the global Jenkins configuration form,… Aqua Microscanner after 1.0.7 Fix from $1,6002019-09-25 HIGH 7.5 CVE-2019-10428 Jenkins Aqua Security Scanner Plugin 3.0.17 and earlier transmitted configured credentials in plain text as part of the global Jenkins configuration … Aqua Security Scanner after 3.0.17 Fix from $1,9502019-09-25 HIGH 7.5 CVE-2019-10411 Jenkins Inedo BuildMaster Plugin 2.4.0 and earlier transmitted configured credentials in plain text as part of the global Jenkins configuration form,… Inedo Buildmaster after 2.4.0 Fix from $1,9502019-09-25 HIGH 7.5 CVE-2019-10412 Jenkins Inedo ProGet Plugin 1.2 and earlier transmitted configured credentials in plain text as part of the global Jenkins configuration form, potent… Inedo Proget after 1.2 Fix from $1,9502019-09-25 CRITICAL 9.8 CVE-2019-5505 ONTAP Select Deploy administration utility versions 2.2 through 2.12.1 transmit credentials in plaintext. Ontap Select Deploy Administration Utility after 2.12.1 Fix from $2,3002019-09-24 MEDIUM 5.3 CVE-2019-5503 OnCommand Workflow Automation versions prior to 5.0 shipped without certain HTTP Security headers configured which could allow an attacker to obtain … Oncommand Workflow Automation Mitigation only Fix from $1,6002019-09-10 MEDIUM 6.5 CVE-2019-14319 The TikTok (formerly Musical.ly) application 12.2.0 for Android and iOS performs unencrypted transmission of images, videos, and likes. This allows a… Tiktok Mitigation only Fix from $1,6002019-09-04 MEDIUM 6.5 CVE-2019-10391 Jenkins IBM Application Security on Cloud Plugin 1.2.4 and earlier transmitted configured passwords in plain text as part of job configuration forms,… Ibm Application Security On Cloud after 1.2.4 Fix from $1,6002019-08-28 HIGH 7.5 CVE-2019-5635 A cleartext transmission of sensitive information vulnerability is present in Hickory Smart Ethernet Bridge from Belwith Products, LLC. Captured data… Hickory Smart Ethernet Bridge Firmware Mitigation only Fix from $1,9502019-08-22 MEDIUM 5.4 CVE-2019-11276 Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.16, 2.4.x prior to 2.4.12, 2.5.x prior to 2.5.8, and 2.6.x … Application Service 2.3.16 / 2.4.12+ Fix from $1,6002019-08-19 HIGH 7.5 CVE-2019-15135 The handshake protocol in Object Management Group (OMG) DDS Security 1.1 sends cleartext information about all of the capabilities of a participant (… Dds Security Mitigation only Fix from $1,9502019-08-18 MEDIUM 6.5 CVE-2019-0346 Unencrypted communication error in SAP Business Objects Business Intelligence Platform (Central Management Console), version 4.2, leads to disclosure… Businessobjects Business Intelligence Mitigation only Fix from $1,6002019-08-14 MEDIUM 6.5 CVE-2019-0348 SAP BusinessObjects Business Intelligence Platform (Web Intelligence), versions 4.1, 4.2, can access database with unencrypted connection, even if th… Businessobjects Business Intelligence Mitigation only Fix from $1,6002019-08-14 MEDIUM 6.5 CVE-2019-14664 In Enigmail below 2.1, an attacker in possession of PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted p… Fedora 2.1+ Fix from $1,6002019-08-05 HIGH 8.1 CVE-2019-5448 Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be s… Yarn 1.17.3+ Fix from $1,9502019-07-30 HIGH 7.4 CVE-2019-13498 One Identity Cloud Access Manager 8.1.3 does not use HTTP Strict Transport Security (HSTS), which may allow man-in-the-middle (MITM) attacks. This is… Cloud Access Manager No fix yet Fix from $1,9502019-07-29 MEDIUM 5.6 CVE-2019-12820 A vulnerability was found in the app 2.0 of the Shenzhen Jisiwei i3 robot vacuum cleaner. Actions performed on the app such as changing a password, a… I3 Firmware Mitigation only Fix from $1,6002019-07-19 HIGH 8.1 CVE-2019-10101 JetBrains Kotlin versions before 1.3.30 were resolving artifacts using an http connection during the build process, potentially allowing an MITM atta… Kotlin 1.3.30+ Fix from $1,9502019-07-03 HIGH 8.1 CVE-2019-10102 JetBrains Ktor framework (created using the Kotlin IDE template) versions before 1.1.0 were resolving artifacts using an http connection during the b… Kotlin 1.1.0 / 1.3.30+ Fix from $1,9502019-07-03 MEDIUM 5.3 CVE-2019-6640 On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.1-11.5.8, SNMP exposes sensitive configuration … Big Ip Local Traffic Manager 11.5.9 / 11.6.3+ Fix from $1,6002019-07-03 CRITICAL 9.8 CVE-2018-11421 Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior use a proprietary monitoring protocol that does not provide confidentiality, integ… Oncell G3150 Hspa Firmware after 1.6 Fix from $2,3002019-07-03 CRITICAL 9.8 CVE-2018-11422 Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior use a proprietary configuration protocol that does not provide confidentiality, in… Oncell G3150 Hspa Firmware after 1.6 Fix from $2,3002019-07-03 MEDIUM 5.3 CVE-2019-12781 An issue was discovered in Django 1.11 before 1.11.22, 2.1 before 2.1.10, and 2.2 before 2.2.3. An HTTP request is not redirected to HTTPS when the S… Django 1.11.22 / 2.1.10+ Fix from $1,6002019-07-01