Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.9
CVE-2024-31905
IBM QRadar Network Packet Capture 7.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP St…
Qradar Network Packet Capture
Mitigation only
MEDIUM 6.5
CVE-2024-38167
.NET and Visual Studio Information Disclosure Vulnerability
.net
8.0.8 / 17.6.18+
MEDIUM 6.5
CVE-2024-7408
This vulnerability exists in Airveda Air Quality Monitor PM2.5 PM10 due to transmission of sensitive information in plain text during AP pairing mode…
Pm2.5 Pm10 Monitor Firmware
7.4.4.39+
HIGH 7.5
CVE-2024-38891
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform…
Caterease
after 24.0.1.2405
HIGH 8.1
CVE-2024-32864
Under certain circumstances exacqVision Web Services will not enforce secure web communications (HTTPS)
Exacqvision Web Service
after 24.03
HIGH 7.4
CVE-2024-41262
mmudb v1.9.3 was discovered to use the HTTP protocol in the ShowMetricsRaw and ShowMetricsAsText functions, possibly allowing attackers to intercept …
Immudb
Mitigation only
HIGH 7.5
CVE-2024-41687
This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to transmission of password in plain text. A remote attacker could exploit this v…
Sy Gpon 1110 Wdont Firmware
Mitigation only
MEDIUM 6.5
CVE-2024-6972
In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the task log in clear-text.
Octopus Server
2024.1.12759 / 2024.2.9193+
MEDIUM 6.3
CVE-2024-41124
Puncia is the Official CLI utility for Subdomain Center & Exploit Observer. `API_URLS` is utilizing HTTP instead of HTTPS for communication that can …
Patch available
MEDIUM 6.0
CVE-2024-5631
Longse NVR (Network Video Recorder) model NVR3608PGE2W, as well as products based on this device, are transmitting user's login and password to a rem…
Mitigation only
MEDIUM 5.5
CVE-2024-6388
Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivileged users by passing the tok…
Ubuntu Advantage Desktop Daemon
1.12+
HIGH 7.5
CVE-2024-37183
Plain text credentials and session ID can be captured with a network sniffer.
L210 F2g Firmware
Mitigation only
MEDIUM 5.3
CVE-2024-0066
Johan Fagerström, member of the AXIS OS Bug Bounty Program, has found that a O3C feature may expose sensitive traffic between the client (Axis device…
No fix yet
HIGH 7.4
CVE-2024-27166
Coredump binaries in Toshiba printers have incorrect permissions. A local attacker can steal confidential information. As for the affected products/m…
No fix yet
MEDIUM 6.5
CVE-2024-27163
Toshiba printers will display the password of the admin user in clear-text and additional passwords when sending 2 specific HTTP requests to the inte…
Mitigation only
MEDIUM 5.1
CVE-2024-35210
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server is not enforcing HS…
Sinec Traffic Analyzer
1.2+
HIGH 7.5
CVE-2024-37393
Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-supplied input. An unauthenticated…
Multi Factor Authentication Solutions
9.4.514+
HIGH 7.5
CVE-2024-37163
SkyScrape is a GUI Dashboard for AWS Infrastructure and Managing Resources and Usage Costs. SkyScrape's API requests are currently unsecured HTTP re…
Skyscraper
Mitigation only
HIGH 7.5
CVE-2024-36426
In TARGIT Decision Suite 23.2.15007.0 before Autumn 2023, the session token is part of the URL and may be sent in a cleartext HTTP session.
Mitigation only
HIGH 7.5
CVE-2024-35059
An issue in the Pickle Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands.
Ait Core
after 2.5.2
HIGH 7.5
CVE-2024-35060
An issue in the YAML Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands via supplying a crafted YAML file.
Ait Core
after 2.5.2
HIGH 7.5
CVE-2024-35057
An issue in NASA AIT-Core v2.5.2 allows attackers to execute arbitrary code via a crafted packet.
Ait Core
after 2.5.2
HIGH 7.5
CVE-2024-35058
An issue in the API wait function of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary code via supplying a crafted string.
Ait Core
after 2.5.2
MEDIUM 6.5
CVE-2024-31840
An issue was discovered in Italtel Embrace 1.6.4. The web application inserts cleartext passwords in the HTML source code. An authenticated user is a…
Embrace
No fix yet
CRITICAL 9.6
CVE-2024-30209
A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT278…
Mitigation only
HIGH 7.0
CVE-2024-28134
An unauthenticated remote attacker can extract a session token with a MitM attack and gain web-based
management access with the privileges of the cur…
Charx Sec 3000 Firmware
after 1.5.1
MEDIUM 5.5
CVE-2024-0098
NVIDIA ChatRTX for Windows contains a vulnerability in the ChatRTX UI and backend, where a user can cause a clear-text transmission of sensitive info…
Chatrtx
0.3+
HIGH 7.1
CVE-2022-32510
An issue was discovered on certain Nuki Home Solutions devices. The HTTP API exposed by a Bridge used an unencrypted channel to provide an administra…
Mitigation only
HIGH 8.1
CVE-2024-1657
A flaw was found in the ansible automation platform. An insecure WebSocket connection was being used in installation from the Ansible rulebook EDA se…
Mitigation only
HIGH 7.5
CVE-2024-4161
In Brocade SANnav, before Brocade SANnav v2.3.0, syslog traffic received
clear text. This could allow an unauthenticated, remote attacker to
captur…
Brocade Sannav
2.3.0+