Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2018-18071
An issue was discovered in the Daimler Mercedes-Benz Me app 2.11.0-846 for iOS. The encrypted Connected Vehicle API data exchange between the app and…
Mercedes Me
No fix yet
MEDIUM 5.9
CVE-2018-5401
The Auto-Maskin DCU 210E, RP-210E, and Marine Pro Observer Android App transmit sensitive or security-critical data in cleartext in a communication c…
Rp 210e Firmware
Mitigation only
HIGH 8.8
CVE-2018-5402
The Auto-Maskin DCU 210E, RP-210E, and Marine Pro Observer Android App use an embedded webserver that uses unencrypted plaintext for the transmission…
Rp 210e Firmware
Mitigation only
HIGH 8.1
CVE-2018-15752
An issue was discovered in the MensaMax (aka com.breustedt.mensamax) application 4.3 for Android. Cleartext Transmission of Sensitive Information all…
Mensamax
No fix yet
HIGH 8.8
CVE-2018-8842
Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software transmits sensitive or security-critical data in cleartext in a commu…
E Alert Firmware
Mitigation only
HIGH 8.1
CVE-2018-13140EPSS 7%
Druide Antidote through 9.5.1 on Windows and Linux allows remote code execution through the update mechanism by leveraging use of HTTP to download in…
Antidote 9
after 5.1
MEDIUM 6.5
CVE-2018-16225
The QBee MultiSensor Camera through 4.16.4 accepts unencrypted network traffic from clients (such as the QBee Cam application through 1.0.5 for Andro…
Qbee Multi Sensor Camera Firmware
after 10.7.2
MEDIUM 5.9
CVE-2018-14627
The IIOP OpenJDK Subsystem in WildFly before version 14.0.0 does not honour configuration when SSL transport is required. Servers before this version…
Wildfly
14.0.0+
HIGH 8.0
CVE-2018-12710EPSS 77%
An issue was discovered on D-Link DIR-601 2.02NA devices. Being local to the network and having only "User" account (which is a low privilege account…
Dir 601 Firmware
No fix yet
CRITICAL 9.8
CVE-2018-11749
When users are configured to use startTLS with RBAC LDAP, at login time, the user's credentials are sent via plaintext to the LDAP server. This affec…
Puppet Enterprise
after 2018.1.3
HIGH 8.8
CVE-2018-11050
Dell EMC NetWorker versions between 9.0 and 9.1.1.8 through 9.2.1.3, and the version 18.1.0.1 contain a Clear-Text authentication over network vulner…
Emc Networker
after 9.2.1.3
HIGH 7.5
CVE-2018-11338
Intuit Lacerte 2017 for Windows in a client/server environment transfers the entire customer list in cleartext over SMB, which allows attackers to (1…
Lacerte
after 2017
CRITICAL 9.8
CVE-2018-8855
Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The dev…
Smartserver 1 Firmware
4.11.007+
HIGH 7.5
CVE-2016-5638
There are few web pages associated with the genie app on the Netgear WNDR4500 running firmware version V1.0.1.40_1.0.6877. Genie app adds some capabi…
Wndr4500 Firmware
No fix yet
CRITICAL 9.8
CVE-2016-5649EPSS 27%
A vulnerability is in the 'BSW_cxttongr.htm' page of the Netgear DGN2200, version DGN2200-V1.0.0.50_7.0.50, and DGND3700, version DGND3700-V1.0.0.17_…
Dgn2200 Firmware
No fix yet
HIGH 8.1
CVE-2018-0025
When an SRX Series device is configured to use HTTP/HTTPS pass-through authentication services, a client sending authentication credentials in the in…
Junos
Mitigation only
HIGH 8.1
CVE-2018-8929
Improper restriction of communication channel to intended endpoints vulnerability in HTTP daemon in Synology SSL VPN Client before 1.2.4-0224 allows …
Ssl Vpn Client
1.2.4-0224+
HIGH 7.5
CVE-2018-4227
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. The issue involves the "Mail" compo…
Iphone Os
10.13.5 / 11.4+
MEDIUM 5.9
CVE-2018-1454
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to obtain sensitive information, caused by the failure to proper…
Infosphere Information Server
Mitigation only
HIGH 8.1
CVE-2017-16040
gfe-sass is a library for promises (CommonJS/Promises/A,B,D) gfe-sass downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It m…
Gfe Sass
after 1.0.19
MEDIUM 5.9
CVE-2017-16041
ikst versions before 1.1.2 download resources over HTTP, which leaves it vulnerable to MITM attacks.
Ikst
1.1.2+
HIGH 8.1
CVE-2017-16035
The hubl-server module is a wrapper for the HubL Development Server. During installation hubl-server downloads a set of dependencies from api.hubapi.…
Hubl Server
after 1.1.5
HIGH 7.5
CVE-2018-1600
IBM BigFix Platform 9.2 and 9.5 transmits sensitive or security-critical data in clear text in a communication channel that can be sniffed by unautho…
Bigfix Platform
after 9.5.8
MEDIUM 6.5
CVE-2018-11477
An issue was discovered on Vgate iCar 2 Wi-Fi OBD2 Dongle devices. The data packets that are sent between the iOS or Android application and the OBD …
Icar 2 Wi Fi Obd2 Firmware
Mitigation only
MEDIUM 6.6
CVE-2018-11402
SimpliSafe Original has Unencrypted Keypad Transmissions, which allows physically proximate attackers to discover the PIN.
U9k Kp1000 Firmware
Mitigation only
MEDIUM 5.8
CVE-2018-0281
A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to restart an instance of …
Secure Firewall Management Center
Mitigation only
MEDIUM 5.8
CVE-2018-0283
A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to restart an instance of …
Secure Firewall Management Center
Mitigation only
MEDIUM 6.5
CVE-2017-12716
Abbott Laboratories Accent and Anthem pacemakers manufactured prior to Aug 28, 2017 transmit unencrypted patient information via RF communications to…
Accent Firmware
Mitigation only
CRITICAL 9.8
CVE-2018-7246
A cleartext transmission of sensitive information vulnerability exists in Schneider Electric's 66074 MGE Network Management Card Transverse installed…
66074 Mge Network Management Card Transverse
Mitigation only
MEDIUM 5.3
CVE-2017-8154
The Themes App Honor 8 Lite Huawei mobile phones with software of versions before Prague-L31C576B172, versions before Prague-L31C530B160, versions be…
Honor 8 Lite Firmware
Mitigation only