Vulnerability index

Browse CVEs

798 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cleartext TransmissionCWE-319 × clear
MEDIUM 5.9 CVE-2024-41757 IBM Concert Software 1.0.0 and 1.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Str… Concert Mitigation only Fix from $1,6002025-01-24 HIGH 8.6 CVE-2024-26155 All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 expose clear text credentials in the web portal. An attacker can access the … Remote Access Server Firmware 4.5.0+ Fix from $1,9502025-01-17 MEDIUM 6.5 CVE-2024-48121 The HI-SCAN 6040i Hitrax HX-03-19-I was discovered to transmit user credentials in cleartext over the GIOP protocol. This allows attackers to possibl… Mitigation only Fix from $1,6002025-01-15 MEDIUM 6.8 CVE-2024-45102 A privilege escalation vulnerability was discovered that could allow a valid, authenticated LXCA user to escalate their permissions for a connected X… No fix yet Fix from $1,6002025-01-14 HIGH 7.5 CVE-2024-42181 HCL MyXalytics is affected by a cleartext transmission of sensitive information vulnerability. The application transmits sensitive or security-criti… Dryice Myxalytics Mitigation only Fix from $1,9502025-01-12 CRITICAL 9.1 CVE-2024-46505 Infoblox BloxOne v2.4 was discovered to contain a business logic flaw due to thick client vulnerabilities. Mitigation only Fix from $2,3002025-01-09 MEDIUM 6.5 CVE-2024-11946 iXsystems TrueNAS CORE fetch_plugin_packagesites tar Cleartext Transmission of Sensitive Information Vulnerability. This vulnerability allows network… Truenas Firmware Mitigation only Fix from $1,6002024-12-30 HIGH 7.5 CVE-2021-39081 IBM Cognos Analytics Mobile for Android 1.1.14 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sens… Cognos Analytics Mobile Mitigation only Fix from $1,9502024-12-19 MEDIUM 5.7 CVE-2024-10973 A vulnerability was found in Keycloak. The environment option `KC_CACHE_EMBEDDED_MTLS_ENABLED` does not work and the JGroups replication configuratio… Mitigation only Fix from $1,6002024-12-17 HIGH 7.5 CVE-2024-49819 IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information in cleartext i… Security Guardium Key Lifecycle Manager Mitigation only Fix from $1,9502024-12-17 HIGH 7.5 CVE-2024-53246 In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions below 9.3.2408.101, 9.2.2406.106, 9.2.2403.111, and 9.… Splunk 9.1.7 / 9.1.2312.206+ Fix from $1,9502024-12-10 HIGH 8.1 CVE-2024-6515 Web browser interface may manipulate application username/password in clear text or Base64 encoding providing a higher probability of unintended cre… Aspect Ent 2 Firmware 3.08.03+ Fix from $1,9502024-12-05 MEDIUM 5.9 CVE-2021-29892 IBM Cognos Controller 11.0.0 and 11.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP … Cognos Controller Mitigation only Fix from $1,6002024-12-03 CRITICAL 9.3 CVE-2024-9834 Improper data protection on the ventilator's serial interface could allow an attacker to send and receive messages that result in unauthorized disclo… Mitigation only Fix from $2,3002024-11-14 MEDIUM 5.4 CVE-2024-28169 Cleartext transmission of sensitive information for some BigDL software maintained by Intel(R) before version 2.5.0 may allow an authenticated user t… Mitigation only Fix from $1,6002024-11-13 MEDIUM 5.3 CVE-2024-43432 A flaw was found in moodle. The cURL wrapper in Moodle strips HTTPAUTH and USERPWD headers during emulated redirects, but retains other original requ… Moodle 4.1.12 / 4.2.9+ Fix from $1,6002024-11-11 HIGH 8.8 CVE-2024-50634 A vulnerability in a weak JWT token in Watcharr v1.43.0 and below allows attackers to perform privilege escalation using a crafted JWT token. This vu… Watcharr after 1.43.0 Fix from $1,9502024-11-08 MEDIUM 5.9 CVE-2024-32946 A vulnerability in the LevelOne WBR-6012 router's firmware version R0.40e6 allows sensitive information to be transmitted in cleartext via Web and FT… Wbr 6012 Firmware Mitigation only Fix from $1,6002024-10-30 MEDIUM 5.9 CVE-2024-50624 ispdbservice.cpp in KDE Kmail before 6.2.0 allows man-in-the-middle attackers to trigger use of an attacker-controlled mail server because cleartext … Mitigation only Fix from $1,6002024-10-28 MEDIUM 5.3 CVE-2024-40595 An authentication-bypass issue in the RDP component of One Identity Safeguard for Privileged Sessions (SPS) On Premise before 7.5.1 (and LTS before 7… Mitigation only Fix from $1,6002024-10-24 HIGH 7.5 CVE-2024-49387 Cleartext transmission of sensitive information in acep-collector service. The following products are affected: Acronis Cyber Protect 16 (Linux, Wind… Cyber Protect after 15 Fix from $1,9502024-10-15 HIGH 7.5 CVE-2024-48788 An issue in YESCAM (com.yescom.YesCam.zwave) 1.0.2 allows a remote attacker to obtain sensitive information via the firmware update process. Mitigation only Fix from $1,9502024-10-11 MEDIUM 6.5 CVE-2024-47833 Taipy is an open-source Python library for easy, end-to-end application development for data scientists and machine learning engineers. In affected v… Taipy 4.0.0+ Fix from $1,6002024-10-09 MEDIUM 5.3 CVE-2024-9620 A flaw was found in Event-Driven Automation (EDA) in Ansible Automation Platform (AAP), which lacks encryption of sensitive information. An attacker … Mitigation only Fix from $1,6002024-10-08 HIGH 8.7 CVE-2024-47789 ** UNSUPPORTED WHEN ASSIGNED ** This vulnerability exists in D3D Security IP Camera D8801 due to usage of weak authentication scheme of the HTTP head… Mitigation only Fix from $1,9502024-10-04 HIGH 7.5 CVE-2024-7713 The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 discloses the Open AI API Key, allowing unauthenticated users … Chatgpt Assistant 2.1.0+ Fix from $1,9502024-09-27 MEDIUM 6.5 CVE-2024-47124 The goTenna Pro App does not encrypt callsigns in messages. It is recommended to not use sensitive information in callsigns when using this and pre… Gotenna Pro 2.0.3+ Fix from $1,6002024-09-26 MEDIUM 6.8 CVE-2024-45101 A privilege escalation vulnerability was discovered when Single Sign On (SSO) is enabled that could allow an attacker to intercept a valid, authentic… Mitigation only Fix from $1,6002024-09-13 HIGH 7.8 CVE-2024-44105 Cleartext transmission of sensitive information in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a loc… Workspace Control 10.18.99.0+ Fix from $1,9502024-09-10 MEDIUM 5.9 CVE-2024-39746 IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 could allow a remote attacker to obtain sensitive information, caused by the failure … Sterling Connect Direct Web Services Mitigation only Fix from $1,6002024-08-22