Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.9
CVE-2024-41757
IBM Concert Software 1.0.0 and 1.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Str…
Concert
Mitigation only
HIGH 8.6
CVE-2024-26155
All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0
expose clear text credentials in the web portal. An attacker can access
the …
Remote Access Server Firmware
4.5.0+
MEDIUM 6.5
CVE-2024-48121
The HI-SCAN 6040i Hitrax HX-03-19-I was discovered to transmit user credentials in cleartext over the GIOP protocol. This allows attackers to possibl…
Mitigation only
MEDIUM 6.8
CVE-2024-45102
A privilege escalation vulnerability was discovered that could allow a valid, authenticated LXCA user to escalate their permissions for a connected X…
No fix yet
HIGH 7.5
CVE-2024-42181
HCL MyXalytics is affected by a cleartext transmission of sensitive information vulnerability. The application transmits sensitive or security-criti…
Dryice Myxalytics
Mitigation only
CRITICAL 9.1
CVE-2024-46505
Infoblox BloxOne v2.4 was discovered to contain a business logic flaw due to thick client vulnerabilities.
Mitigation only
MEDIUM 6.5
CVE-2024-11946
iXsystems TrueNAS CORE fetch_plugin_packagesites tar Cleartext Transmission of Sensitive Information Vulnerability. This vulnerability allows network…
Truenas Firmware
Mitigation only
HIGH 7.5
CVE-2021-39081
IBM Cognos Analytics Mobile for Android 1.1.14 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sens…
Cognos Analytics Mobile
Mitigation only
MEDIUM 5.7
CVE-2024-10973
A vulnerability was found in Keycloak. The environment option `KC_CACHE_EMBEDDED_MTLS_ENABLED` does not work and the JGroups replication configuratio…
Mitigation only
HIGH 7.5
CVE-2024-49819
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information in cleartext i…
Security Guardium Key Lifecycle Manager
Mitigation only
HIGH 7.5
CVE-2024-53246
In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions below 9.3.2408.101, 9.2.2406.106, 9.2.2403.111, and 9.…
Splunk
9.1.7 / 9.1.2312.206+
HIGH 8.1
CVE-2024-6515
Web browser interface may manipulate application username/password in clear text or Base64 encoding providing a higher probability of unintended cre…
Aspect Ent 2 Firmware
3.08.03+
MEDIUM 5.9
CVE-2021-29892
IBM Cognos Controller 11.0.0 and 11.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP …
Cognos Controller
Mitigation only
CRITICAL 9.3
CVE-2024-9834
Improper data protection on the ventilator's serial interface could allow an attacker to send and receive messages that result in unauthorized disclo…
Mitigation only
MEDIUM 5.4
CVE-2024-28169
Cleartext transmission of sensitive information for some BigDL software maintained by Intel(R) before version 2.5.0 may allow an authenticated user t…
Mitigation only
MEDIUM 5.3
CVE-2024-43432
A flaw was found in moodle. The cURL wrapper in Moodle strips HTTPAUTH and USERPWD headers during emulated redirects, but retains other original requ…
Moodle
4.1.12 / 4.2.9+
HIGH 8.8
CVE-2024-50634
A vulnerability in a weak JWT token in Watcharr v1.43.0 and below allows attackers to perform privilege escalation using a crafted JWT token. This vu…
Watcharr
after 1.43.0
MEDIUM 5.9
CVE-2024-32946
A vulnerability in the LevelOne WBR-6012 router's firmware version R0.40e6 allows sensitive information to be transmitted in cleartext via Web and FT…
Wbr 6012 Firmware
Mitigation only
MEDIUM 5.9
CVE-2024-50624
ispdbservice.cpp in KDE Kmail before 6.2.0 allows man-in-the-middle attackers to trigger use of an attacker-controlled mail server because cleartext …
Mitigation only
MEDIUM 5.3
CVE-2024-40595
An authentication-bypass issue in the RDP component of One Identity Safeguard for Privileged Sessions (SPS) On Premise before 7.5.1 (and LTS before 7…
Mitigation only
HIGH 7.5
CVE-2024-49387
Cleartext transmission of sensitive information in acep-collector service. The following products are affected: Acronis Cyber Protect 16 (Linux, Wind…
Cyber Protect
after 15
HIGH 7.5
CVE-2024-48788
An issue in YESCAM (com.yescom.YesCam.zwave) 1.0.2 allows a remote attacker to obtain sensitive information via the firmware update process.
Mitigation only
MEDIUM 6.5
CVE-2024-47833
Taipy is an open-source Python library for easy, end-to-end application development for data scientists and machine learning engineers. In affected v…
Taipy
4.0.0+
MEDIUM 5.3
CVE-2024-9620
A flaw was found in Event-Driven Automation (EDA) in Ansible Automation Platform (AAP), which lacks encryption of sensitive information. An attacker …
Mitigation only
HIGH 8.7
CVE-2024-47789
** UNSUPPORTED WHEN ASSIGNED ** This vulnerability exists in D3D Security IP Camera D8801 due to usage of weak authentication scheme of the HTTP head…
Mitigation only
HIGH 7.5
CVE-2024-7713
The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 discloses the Open AI API Key, allowing unauthenticated users …
Chatgpt Assistant
2.1.0+
MEDIUM 6.5
CVE-2024-47124
The goTenna Pro App does not encrypt callsigns in messages. It is
recommended to not use sensitive information in callsigns when using
this and pre…
Gotenna Pro
2.0.3+
MEDIUM 6.8
CVE-2024-45101
A privilege escalation vulnerability was discovered when Single Sign On (SSO) is enabled that could allow an attacker to intercept a valid, authentic…
Mitigation only
HIGH 7.8
CVE-2024-44105
Cleartext transmission of sensitive information in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a loc…
Workspace Control
10.18.99.0+
MEDIUM 5.9
CVE-2024-39746
IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 could allow a remote attacker to obtain sensitive information, caused by the failure …
Sterling Connect Direct Web Services
Mitigation only