Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2017-12310
A vulnerability in the auto discovery phase of Cisco Spark Hybrid Calendar Service could allow an unauthenticated, remote attacker to view sensitive …
Spark Hybrid Calendar Service
Mitigation only
HIGH 7.2
CVE-2017-0925
Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration API endpoin…
GitLab
after 10.3.3
CRITICAL 9.8
CVE-2018-6295
Unencrypted way of remote control and communications in Hanwha Techwin Smartcams
Snh V6410pn Firmware
Mitigation only
MEDIUM 5.9
CVE-2018-5471
A Cleartext Transmission of Sensitive Information issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPU…
Hirschmann Rs20 0900mmm2tdau
Mitigation only
MEDIUM 5.9
CVE-2018-6019
Samsung Display Solutions App before 3.02 for Android allows man-in-the-middle attackers to spoof B2B content by leveraging failure to use encryption…
Display Solutions
after 3.01
HIGH 8.1
CVE-2018-7298
In /usr/local/etc/config/addons/mh/loopupd.sh on eQ-3 AG HomeMatic CCU2 2.29.22 devices, software update packages are downloaded via the HTTP protoco…
Homematic Central Control Unit Ccu2 Firmware
Mitigation only
CRITICAL 9.8
CVE-2018-7259
The FSX / P3Dv4 installer 2.0.1.231 for Flight Sim Labs A320-X sends a user's Google account credentials to http://installLog.flightsimlabs.com/LogHa…
A320 X
Mitigation only
CRITICAL 9.8
CVE-2018-1297EPSS 10%
When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection. This could allow an attacker to get Access …
Jmeter
Mitigation only
CRITICAL 9.1
CVE-2018-6017
Unencrypted transmission of images in Tinder iOS app and Tinder Android app allows an attacker to extract private sensitive information by sniffing n…
Tinder
Mitigation only
CRITICAL 9.1
CVE-2018-6018
Fixed sizes of HTTPS responses in Tinder iOS app and Tinder Android app allow an attacker to extract private sensitive information by sniffing networ…
Tinder
Mitigation only
MEDIUM 6.5
CVE-2017-17844
An issue was discovered in Enigmail before 1.9.9. A remote attacker can obtain cleartext content by sending an encrypted data block (that the attacke…
Debian Linux
1.9.9+
HIGH 8.8
CVE-2017-5259EPSS 39%
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, an undocumented, root-privilege administration web shell is available using the …
Cnpilot R190v Firmware
after 4.3.2-r4
HIGH 8.1
CVE-2017-1694
IBM Integration Bus 9.0 and 10.0 transmits user credentials in plain in clear text which can be read by an attacker using man in the middle technique…
Integration Bus
Mitigation only
HIGH 7.5
CVE-2017-14486
The Vibease Wireless Remote Vibrator app for Android and the Vibease Chat app for iOS use cleartext to exchange messages with other apps and the PLAI…
Chat
Mitigation only
CRITICAL 9.8
CVE-2017-15999
In the "NQ Contacts Backup & Restore" application 1.1 for Android, no HTTPS is used for transmitting login and synced user data. When logging in, the…
Contacts Backup \& Restore
Mitigation only
MEDIUM 5.9
CVE-2017-1232
IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) transmits sensitive or security-critical data in cleartext in a communication channel t…
Bigfix Platform
Patch available
MEDIUM 5.3
CVE-2017-7147
An issue was discovered in certain Apple products. The Apple Support app before 1.2 for iOS is affected. The issue involves the "Analytics" component…
Apple Support
after 1.1.1
HIGH 7.5
CVE-2017-7133
An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "MobileBackup" component. It allows remote attac…
Iphone Os
after 10.3.3
MEDIUM 5.5
CVE-2017-7143
An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the "Captive Network Assistant" component. It a…
Mac Os X
after 10.12.6
MEDIUM 5.3
CVE-2017-7078
An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. The issue involves the "Mail Drafts" co…
Iphone Os
after 10.12.6
MEDIUM 6.5
CVE-2017-14009
An Information Exposure issue was discovered in ProMinent MultiFLEX M10a Controller web interface. When an authenticated user uses the Change Passwor…
Multiflex M10a Controller Firmware
Mitigation only
HIGH 7.5
CVE-2017-15290
Mirasys Video Management System (VMS) 6.x before 6.4.6, 7.x before 7.5.15, and 8.x before 8.1.1 has a login process in which cleartext data is sent f…
Video Management System
Mitigation only
MEDIUM 5.9
CVE-2017-15042
An unintended cleartext issue exists in Go before 1.8.4 and 1.9.x before 1.9.1. RFC 4954 requires that, during SMTP, the PLAIN auth scheme must only …
Go
after 1.8.3
MEDIUM 5.9
CVE-2017-8444
The client-forwarder in Elastic Cloud Enterprise versions prior to 1.0.2 do not properly encrypt traffic to ZooKeeper. If an attacker is able to man …
Cloud Enterprise
Mitigation only
MEDIUM 6.5
CVE-2017-6665
A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker…
iOS
Mitigation only
HIGH 7.0
CVE-2017-1181
IBM Tivoli Monitoring Portal V6 client could allow a local attacker to gain elevated privileges for IBM Tivoli Monitoring, caused by the default cons…
Tivoli Monitoring
Mitigation only
HIGH 7.5
CVE-2017-1000024
Shotwell version 0.24.4 or earlier and 0.25.3 or earlier is vulnerable to an information disclosure in the web publishing plugins resulting in potent…
Shotwell
after 0.25.3
HIGH 7.5
CVE-2017-5652
During a routine security analysis, it was found that one of the ports in Apache Impala (incubating) 2.7.0 to 2.8.0 sent data in plaintext even when …
Impala
Mitigation only
HIGH 7.4
CVE-2017-9035
Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows attackers to eavesdrop and tamper with updates by leveraging unencrypted communications…
Serverprotect
Patch available
MEDIUM 5.9
CVE-2017-8850
An issue was discovered on OnePlus One, X, 2, 3, and 3T devices. Due to a lenient updater-script in the OnePlus OTA images, and the fact that both RO…
Oxygenos
No fix yet