Vulnerability index

Browse CVEs

798 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cleartext TransmissionCWE-319 × clear
MEDIUM 5.9 CVE-2024-31905 IBM QRadar Network Packet Capture 7.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP St… Qradar Network Packet Capture Mitigation only Fix from $1,6002024-08-15 MEDIUM 6.5 CVE-2024-38167 .NET and Visual Studio Information Disclosure Vulnerability .net 8.0.8 / 17.6.18+ Fix from $1,6002024-08-13 MEDIUM 6.5 CVE-2024-7408 This vulnerability exists in Airveda Air Quality Monitor PM2.5 PM10 due to transmission of sensitive information in plain text during AP pairing mode… Pm2.5 Pm10 Monitor Firmware 7.4.4.39+ Fix from $1,6002024-08-12 HIGH 7.5 CVE-2024-38891 An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform… Caterease after 24.0.1.2405 Fix from $1,9502024-08-02 HIGH 8.1 CVE-2024-32864 Under certain circumstances exacqVision Web Services will not enforce secure web communications (HTTPS) Exacqvision Web Service after 24.03 Fix from $1,9502024-08-01 HIGH 7.4 CVE-2024-41262 mmudb v1.9.3 was discovered to use the HTTP protocol in the ShowMetricsRaw and ShowMetricsAsText functions, possibly allowing attackers to intercept … Immudb Mitigation only Fix from $1,9502024-07-31 HIGH 7.5 CVE-2024-41687 This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to transmission of password in plain text. A remote attacker could exploit this v… Sy Gpon 1110 Wdont Firmware Mitigation only Fix from $1,9502024-07-26 MEDIUM 6.5 CVE-2024-6972 In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the task log in clear-text. Octopus Server 2024.1.12759 / 2024.2.9193+ Fix from $1,6002024-07-25 MEDIUM 6.3 CVE-2024-41124 Puncia is the Official CLI utility for Subdomain Center & Exploit Observer. `API_URLS` is utilizing HTTP instead of HTTPS for communication that can … Patch available Fix from $1,6002024-07-19 MEDIUM 6.0 CVE-2024-5631 Longse NVR (Network Video Recorder) model NVR3608PGE2W, as well as products based on this device, are transmitting user's login and password to a rem… Mitigation only Fix from $1,6002024-07-09 MEDIUM 5.5 CVE-2024-6388 Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivileged users by passing the tok… Ubuntu Advantage Desktop Daemon 1.12+ Fix from $1,6002024-06-27 HIGH 7.5 CVE-2024-37183 Plain text credentials and session ID can be captured with a network sniffer. L210 F2g Firmware Mitigation only Fix from $1,9502024-06-20 MEDIUM 5.3 CVE-2024-0066 Johan Fagerström, member of the AXIS OS Bug Bounty Program, has found that a O3C feature may expose sensitive traffic between the client (Axis device… No fix yet Fix from $1,6002024-06-18 HIGH 7.4 CVE-2024-27166 Coredump binaries in Toshiba printers have incorrect permissions. A local attacker can steal confidential information. As for the affected products/m… No fix yet Fix from $1,9502024-06-14 MEDIUM 6.5 CVE-2024-27163 Toshiba printers will display the password of the admin user in clear-text and additional passwords when sending 2 specific HTTP requests to the inte… Mitigation only Fix from $1,6002024-06-14 MEDIUM 5.1 CVE-2024-35210 A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server is not enforcing HS… Sinec Traffic Analyzer 1.2+ Fix from $1,6002024-06-11 HIGH 7.5 CVE-2024-37393 Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-supplied input. An unauthenticated… Multi Factor Authentication Solutions 9.4.514+ Fix from $1,9502024-06-10 HIGH 7.5 CVE-2024-37163 SkyScrape is a GUI Dashboard for AWS Infrastructure and Managing Resources and Usage Costs. SkyScrape's API requests are currently unsecured HTTP re… Skyscraper Mitigation only Fix from $1,9502024-06-07 HIGH 7.5 CVE-2024-36426 In TARGIT Decision Suite 23.2.15007.0 before Autumn 2023, the session token is part of the URL and may be sent in a cleartext HTTP session. Mitigation only Fix from $1,9502024-05-27 HIGH 7.5 CVE-2024-35059 An issue in the Pickle Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands. Ait Core after 2.5.2 Fix from $1,9502024-05-21 HIGH 7.5 CVE-2024-35060 An issue in the YAML Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands via supplying a crafted YAML file. Ait Core after 2.5.2 Fix from $1,9502024-05-21 HIGH 7.5 CVE-2024-35057 An issue in NASA AIT-Core v2.5.2 allows attackers to execute arbitrary code via a crafted packet. Ait Core after 2.5.2 Fix from $1,9502024-05-21 HIGH 7.5 CVE-2024-35058 An issue in the API wait function of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary code via supplying a crafted string. Ait Core after 2.5.2 Fix from $1,9502024-05-21 MEDIUM 6.5 CVE-2024-31840 An issue was discovered in Italtel Embrace 1.6.4. The web application inserts cleartext passwords in the HTML source code. An authenticated user is a… Embrace No fix yet Fix from $1,6002024-05-21 CRITICAL 9.6 CVE-2024-30209 A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT278… Mitigation only Fix from $2,3002024-05-14 HIGH 7.0 CVE-2024-28134 An unauthenticated remote attacker can extract a session token with a MitM attack and gain web-based management access with the privileges of the cur… Charx Sec 3000 Firmware after 1.5.1 Fix from $1,9502024-05-14 MEDIUM 5.5 CVE-2024-0098 NVIDIA ChatRTX for Windows contains a vulnerability in the ChatRTX UI and backend, where a user can cause a clear-text transmission of sensitive info… Chatrtx 0.3+ Fix from $1,6002024-05-14 HIGH 7.1 CVE-2022-32510 An issue was discovered on certain Nuki Home Solutions devices. The HTTP API exposed by a Bridge used an unencrypted channel to provide an administra… Mitigation only Fix from $1,9502024-05-14 HIGH 8.1 CVE-2024-1657 A flaw was found in the ansible automation platform. An insecure WebSocket connection was being used in installation from the Ansible rulebook EDA se… Mitigation only Fix from $1,9502024-04-25 HIGH 7.5 CVE-2024-4161 In Brocade SANnav, before Brocade SANnav v2.3.0, syslog traffic received clear text. This could allow an unauthenticated, remote attacker to captur… Brocade Sannav 2.3.0+ Fix from $1,9502024-04-25