Vulnerability index

Browse CVEs

800 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cleartext TransmissionCWE-319 × clear
HIGH 7.5 CVE-2018-18071 An issue was discovered in the Daimler Mercedes-Benz Me app 2.11.0-846 for iOS. The encrypted Connected Vehicle API data exchange between the app and… Mercedes Me No fix yet Fix from $1,9502018-10-09 MEDIUM 5.9 CVE-2018-5401 The Auto-Maskin DCU 210E, RP-210E, and Marine Pro Observer Android App transmit sensitive or security-critical data in cleartext in a communication c… Rp 210e Firmware Mitigation only Fix from $1,6002018-10-08 HIGH 8.8 CVE-2018-5402 The Auto-Maskin DCU 210E, RP-210E, and Marine Pro Observer Android App use an embedded webserver that uses unencrypted plaintext for the transmission… Rp 210e Firmware Mitigation only Fix from $1,9502018-10-08 HIGH 8.1 CVE-2018-15752 An issue was discovered in the MensaMax (aka com.breustedt.mensamax) application 4.3 for Android. Cleartext Transmission of Sensitive Information all… Mensamax No fix yet Fix from $1,9502018-10-02 HIGH 8.8 CVE-2018-8842 Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software transmits sensitive or security-critical data in cleartext in a commu… E Alert Firmware Mitigation only Fix from $1,9502018-09-26 HIGH 8.1 CVE-2018-13140EPSS 7% Druide Antidote through 9.5.1 on Windows and Linux allows remote code execution through the update mechanism by leveraging use of HTTP to download in… Antidote 9 after 5.1 Fix from $1,9502018-09-24 MEDIUM 6.5 CVE-2018-16225 The QBee MultiSensor Camera through 4.16.4 accepts unencrypted network traffic from clients (such as the QBee Cam application through 1.0.5 for Andro… Qbee Multi Sensor Camera Firmware after 10.7.2 Fix from $1,6002018-09-18 MEDIUM 5.9 CVE-2018-14627 The IIOP OpenJDK Subsystem in WildFly before version 14.0.0 does not honour configuration when SSL transport is required. Servers before this version… Wildfly 14.0.0+ Fix from $1,6002018-09-04 HIGH 8.0 CVE-2018-12710EPSS 77% An issue was discovered on D-Link DIR-601 2.02NA devices. Being local to the network and having only "User" account (which is a low privilege account… Dir 601 Firmware No fix yet Fix from $1,9502018-08-29 CRITICAL 9.8 CVE-2018-11749 When users are configured to use startTLS with RBAC LDAP, at login time, the user's credentials are sent via plaintext to the LDAP server. This affec… Puppet Enterprise after 2018.1.3 Fix from $2,3002018-08-24 HIGH 8.8 CVE-2018-11050 Dell EMC NetWorker versions between 9.0 and 9.1.1.8 through 9.2.1.3, and the version 18.1.0.1 contain a Clear-Text authentication over network vulner… Emc Networker after 9.2.1.3 Fix from $1,9502018-08-01 HIGH 7.5 CVE-2018-11338 Intuit Lacerte 2017 for Windows in a client/server environment transfers the entire customer list in cleartext over SMB, which allows attackers to (1… Lacerte after 2017 Fix from $1,9502018-07-31 CRITICAL 9.8 CVE-2018-8855 Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The dev… Smartserver 1 Firmware 4.11.007+ Fix from $2,3002018-07-24 HIGH 7.5 CVE-2016-5638 There are few web pages associated with the genie app on the Netgear WNDR4500 running firmware version V1.0.1.40_1.0.6877. Genie app adds some capabi… Wndr4500 Firmware No fix yet Fix from $1,9502018-07-24 CRITICAL 9.8 CVE-2016-5649EPSS 27% A vulnerability is in the 'BSW_cxttongr.htm' page of the Netgear DGN2200, version DGN2200-V1.0.0.50_7.0.50, and DGND3700, version DGND3700-V1.0.0.17_… Dgn2200 Firmware No fix yet Fix from $2,3002018-07-24 HIGH 8.1 CVE-2018-0025 When an SRX Series device is configured to use HTTP/HTTPS pass-through authentication services, a client sending authentication credentials in the in… Junos Mitigation only Fix from $1,9502018-07-11 HIGH 8.1 CVE-2018-8929 Improper restriction of communication channel to intended endpoints vulnerability in HTTP daemon in Synology SSL VPN Client before 1.2.4-0224 allows … Ssl Vpn Client 1.2.4-0224+ Fix from $1,9502018-07-06 HIGH 7.5 CVE-2018-4227 An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. The issue involves the "Mail" compo… Iphone Os 10.13.5 / 11.4+ Fix from $1,9502018-06-08 MEDIUM 5.9 CVE-2018-1454 IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to obtain sensitive information, caused by the failure to proper… Infosphere Information Server Mitigation only Fix from $1,6002018-06-05 HIGH 8.1 CVE-2017-16040 gfe-sass is a library for promises (CommonJS/Promises/A,B,D) gfe-sass downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It m… Gfe Sass after 1.0.19 Fix from $1,9502018-06-04 MEDIUM 5.9 CVE-2017-16041 ikst versions before 1.1.2 download resources over HTTP, which leaves it vulnerable to MITM attacks. Ikst 1.1.2+ Fix from $1,6002018-06-04 HIGH 8.1 CVE-2017-16035 The hubl-server module is a wrapper for the HubL Development Server. During installation hubl-server downloads a set of dependencies from api.hubapi.… Hubl Server after 1.1.5 Fix from $1,9502018-06-04 HIGH 7.5 CVE-2018-1600 IBM BigFix Platform 9.2 and 9.5 transmits sensitive or security-critical data in clear text in a communication channel that can be sniffed by unautho… Bigfix Platform after 9.5.8 Fix from $1,9502018-06-04 MEDIUM 6.5 CVE-2018-11477 An issue was discovered on Vgate iCar 2 Wi-Fi OBD2 Dongle devices. The data packets that are sent between the iOS or Android application and the OBD … Icar 2 Wi Fi Obd2 Firmware Mitigation only Fix from $1,6002018-05-30 MEDIUM 6.6 CVE-2018-11402 SimpliSafe Original has Unencrypted Keypad Transmissions, which allows physically proximate attackers to discover the PIN. U9k Kp1000 Firmware Mitigation only Fix from $1,6002018-05-24 MEDIUM 5.8 CVE-2018-0281 A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to restart an instance of … Secure Firewall Management Center Mitigation only Fix from $1,6002018-05-02 MEDIUM 5.8 CVE-2018-0283 A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to restart an instance of … Secure Firewall Management Center Mitigation only Fix from $1,6002018-05-02 MEDIUM 6.5 CVE-2017-12716 Abbott Laboratories Accent and Anthem pacemakers manufactured prior to Aug 28, 2017 transmit unencrypted patient information via RF communications to… Accent Firmware Mitigation only Fix from $1,6002018-04-25 CRITICAL 9.8 CVE-2018-7246 A cleartext transmission of sensitive information vulnerability exists in Schneider Electric's 66074 MGE Network Management Card Transverse installed… 66074 Mge Network Management Card Transverse Mitigation only Fix from $2,3002018-04-18 MEDIUM 5.3 CVE-2017-8154 The Themes App Honor 8 Lite Huawei mobile phones with software of versions before Prague-L31C576B172, versions before Prague-L31C530B160, versions be… Honor 8 Lite Firmware Mitigation only Fix from $1,6002018-04-11