Vulnerability index

Browse CVEs

798 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cleartext TransmissionCWE-319 × clear
CRITICAL 10.0 CVE-2025-47419 Cleartext Transmission of Sensitive Information vulnerability in Crestron Automate VX allows Sniffing Network Traffic. The device allows Web UI and … Mitigation only Fix from $2,3002025-05-06 MEDIUM 6.5 CVE-2025-32884 An issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. By default, a GID is the user's phone number unless they specific… Mesh Firmware Mitigation only Fix from $1,6002025-05-01 MEDIUM 6.5 CVE-2025-32887 An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. A command channel includes the next hop. which can be intercepted a… Mesh Firmware Mitigation only Fix from $1,6002025-05-01 MEDIUM 6.5 CVE-2025-32881 An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. By default, the GID is the user's phone number unless they specific… Mesh Firmware Mitigation only Fix from $1,6002025-05-01 HIGH 8.7 CVE-2025-42603 This vulnerability exists in the Meon KYC solutions due to transmission of sensitive data in plain text within the response payloads of certain API e… Mitigation only Fix from $1,9502025-04-23 HIGH 7.5 CVE-2025-43013 In JetBrains Toolbox App before 2.6 unencrypted credential transmission during SSH authentication was possible Toolbox 2.6+ Fix from $1,9502025-04-17 MEDIUM 5.9 CVE-2025-27722 Cleartext transmission of sensitive information issue exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, a man-in-the-middle attack may allo… Mitigation only Fix from $1,6002025-04-09 MEDIUM 6.8 CVE-2025-26654 SAP Commerce Cloud (Public Cloud) does not allow to disable unencrypted HTTP (port 80) entirely, but instead allows a redirect from port 80 to 443 (H… Mitigation only Fix from $1,6002025-04-08 HIGH 7.5 CVE-2025-2861 SaTECH BCU in its firmware version 2.1.3 uses the HTTP protocol. The use of the HTTP protocol for web browsing has the problem that information is ex… Satech Bcu Firmware Mitigation only Fix from $1,9502025-03-28 MEDIUM 6.5 CVE-2024-45361 A protocol flaw vulnerability exists in the Xiaomi Mi Connect Service APP. The vulnerability is caused by the validation logic is flawed and can be e… Mitigation only Fix from $1,6002025-03-27 CRITICAL 9.0 CVE-2025-2311 Incorrect Use of Privileged APIs, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in Sechard Info… Mitigation only Fix from $2,3002025-03-20 HIGH 7.5 CVE-2024-10718 In phpipam/phpipam version 1.5.1, the Secure attribute for sensitive cookies in HTTPS sessions is not set. This could cause the user agent to send th… Phpipam 1.7.0+ Fix from $1,9502025-03-20 HIGH 7.3 CVE-2024-44276 This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in iOS 18.2 and iPadOS 18.2. A user in a privi… Ipados 18.2+ Fix from $1,9502025-03-17 HIGH 7.5 CVE-2025-27594 The device uses an unencrypted, proprietary protocol for communication. Through this protocol, configuration data is transmitted and device authentic… Mitigation only Fix from $1,9502025-03-14 HIGH 7.5 CVE-2024-13872 Bitdefender Box, versions 1.3.11.490 through 1.3.11.505, uses the insecure HTTP protocol to download assets over the Internet to update and restart d… Box Firmware after 1.3.11.505 Fix from $1,9502025-03-12 MEDIUM 5.6 CVE-2025-22493 Secure flag not set and SameSIte was set to Lax in the Foreseer Reporting Software (FRS). Absence of this secure flag could lead into the session coo… Mitigation only Fix from $1,6002025-03-05 HIGH 7.1 CVE-2025-24849 Lack of encryption in transit for cloud infrastructure facilitating potential for sensitive data manipulation or exposure. No fix yet Fix from $1,9502025-02-28 MEDIUM 6.5 CVE-2025-25728 Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 were discovered to send communications to the update API i… Mitigation only Fix from $1,6002025-02-28 MEDIUM 6.4 CVE-2022-41545 The administrative web interface of a Netgear C7800 Router running firmware version 6.01.07 (and possibly others) authenticates users via basic authe… C7800 Firmware Mitigation only Fix from $1,6002025-02-18 HIGH 7.5 CVE-2024-5462 If Brocade Fabric OS before Fabric OS 9.2.0 configuration settings are not set to encrypt SNMP passwords, then the SNMP privsecret / authsecret field… Fabric Operating System 9.2.0+ Fix from $1,9502025-02-15 HIGH 7.5 CVE-2025-1060 CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists that could result in the exposure of data when network traffic is being… Mitigation only Fix from $1,9502025-02-13 MEDIUM 6.5 CVE-2025-0556 In Progress® Telerik® Report Server, versions prior to 2025 Q1 (11.0.25.211) when using the older .NET Framework implementation, communication of non… Telerik Report Server 11.0.25.211+ Fix from $1,6002025-02-12 HIGH 7.5 CVE-2024-36558 Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h suffers from Cleartext Transmission of Sensitive Information due to … Mitigation only Fix from $1,9502025-02-06 HIGH 7.5 CVE-2024-43187 IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 transmits sensitive or security-critical data in cleartext in a communicatio… Security Verify Access 10.0.9.0+ Fix from $1,9502025-02-04 HIGH 8.1 CVE-2025-23060 A vulnerability in HPE Aruba Networking ClearPass Policy Manager may, under certain circumstances, expose sensitive unencrypted information. Exploiti… Clearpass Policy Manager 6.11.10 / 6.12.4+ Fix from $1,9502025-02-04 MEDIUM 5.9 CVE-2023-35017 IBM Security Verify Governance 10.0.2 Identity Manager can transmit user credentials in clear text that could be obtained by an attacker using man in… Security Verify Governance Mitigation only Fix from $1,6002025-01-29 MEDIUM 5.9 CVE-2025-0784 A vulnerability has been found in Intelbras InControl up to 2.21.58 and classified as problematic. This vulnerability affects unknown code of the fil… Incontrol Web 2.21.59+ Fix from $1,6002025-01-28 HIGH 8.7 CVE-2025-0631 A Credential Exposure Vulnerability exists in the above-mentioned product and version. The vulnerability is due to using HTTP resulting in credential… Mitigation only Fix from $1,9502025-01-28 MEDIUM 5.7 CVE-2025-0432 EWON Flexy 202 transmits user credentials in clear text with no encryption when a user is added, or user credentials are changed via its webpage. Mitigation only Fix from $1,6002025-01-28 MEDIUM 6.5 CVE-2024-28786 IBM QRadar SIEM 7.5 transmits sensitive or security-critical data in cleartext in a communication channel that could be obtained by an unauthorized a… Qradar Security Information And Event Manager Mitigation only Fix from $1,6002025-01-28