Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.9
CVE-2017-8851
An issue was discovered on OnePlus One and X devices. Due to a lenient updater-script on the OnePlus One and X OTA images, the fact that both product…
Oxygenos
No fix yet
MEDIUM 5.3
CVE-2017-3305
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: C API). Supported versions that are affected are 5.5.55 and earlie…
MySQL
after 5.6.35
MEDIUM 5.9
CVE-2017-2412
An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "iTunes Store" component. It allows man-in-the…
Iphone Os
after 10.2.1
MEDIUM 5.3
CVE-2017-3815
An API Privilege vulnerability in Cisco TelePresence Server Software could allow an unauthenticated, remote attacker to emulate Cisco TelePresence Se…
Telepresence Server Software
Mitigation only
MEDIUM 5.3
CVE-2017-6370
TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer, which allows remote attackers to obtain sensitiv…
TYPO3
No fix yet
HIGH 8.1
CVE-2017-6432
An issue was discovered on Dahua DHI-HCVR7216A-S3 3.210.0001.10 build 2016-06-06 devices. The Dahua DVR Protocol, which operates on TCP Port 37777, i…
Nvr Firmware
No fix yet
MEDIUM 5.5
CVE-2017-6410
kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full https URL (potentially including…
Kdelibs
after 5.31
MEDIUM 5.9
CVE-2017-6341EPSS 9%
Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and SmartPSS Software 1.16.1 2…
Camera Firmware
Mitigation only
CRITICAL 10.0
CVE-2015-0987
Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 rely on cleartext password transmission, which al…
Cx Programmer
after 9.5
MEDIUM 5.0
CVE-2011-3022
translate/translate_manager.cc in Google Chrome before 17.0.963.56 and 19.x before 19.0.1036.7 uses an HTTP session to exchange data for translation,…
Chrome
17.0.963.56 / 19.0.1036.7+
HIGH 7.5
CVE-2008-4122
Joomla! 1.5.8 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this coo…
Joomla\!
Mitigation only
HIGH 7.5
CVE-2008-4390
The Cisco Linksys WVC54GC wireless video camera before firmware 1.25 sends cleartext configuration data in response to a Setup Wizard remote-manageme…
Linksys Wvc54gc Firmware
1.25+
HIGH 7.5
CVE-2008-3289EPSS 5%
EMC Dantz Retrospect Backup Client 7.5.116 sends the password hash in cleartext at an unspecified point, which allows remote attackers to obtain sens…
Retrospect Backup Client
Patch available
HIGH 7.5
CVE-2008-0374
OKI C5510MFP Printer CU H2.15, PU 01.03.01, System F/W 1.01, and Web Page 1.00 sends the configuration of the printer in cleartext, which allows remo…
C5510mfp Firmware
Mitigation only
MEDIUM 5.5
CVE-2007-5626
make_catalog_backup in Bacula 2.2.5, and probably earlier, sends a MySQL password as a command line argument, and sometimes transmits cleartext e-mai…
Bacula
after 2.2.5
MEDIUM 5.3
CVE-2007-4786
Cisco Adaptive Security Appliance (ASA) running PIX 7.0 before 7.0.7.1, 7.1 before 7.1.2.61, 7.2 before 7.2.2.34, and 8.0 before 8.0.2.11, when AAA i…
Adaptive Security Appliance Software
7.0.7.1 / 7.1.2.61+
HIGH 7.5
CVE-2005-3140
Procom NetFORCE 800 4.02 M10 Build 20 and possibly other versions sends the NIS password map (passwd.nis) as a file attachment in diagnostic e-mail m…
Netforce 800 Firmware
Mitigation only
MEDIUM 5.0
CVE-2005-2069
pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is r…
Nss Ldap
Patch available
MEDIUM 5.0
CVE-2004-1852
DameWare Mini Remote Control 3.x before 3.74 and 4.x before 4.2 transmits the Blowfish encryption key in plaintext, which allows remote attackers to …
Dameware Mini Remote Control
3.74 / 4.2+
HIGH 7.5
CVE-2002-1949
The Network Attached Storage (NAS) Administration Web Page for Iomega NAS A300U transmits passwords in cleartext, which allows remote attackers to sn…
Nas A300u Firmware
Mitigation only