CWE-319
898 CVEs • Abstraction: Base • Likelihood of Exploit: High
Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
CVEs (898)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ibm 1Qradar Security Information And Event Manager Jun 17, 2026 Jul 16, 2021 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 IBM QRadar SIEM 7.3 and 7.4 uses less secure methods for protecting data in transit between hosts when encrypt host connections is not enabled as well as data at rest. IBM X-Force ID: 192539. |
1Magicsmotion 1Flamingo 2 Firmware Jun 17, 2026 Jul 15, 2021 N/A· v4 5.3 MEDIUM· v3 2.9 LOW· v2 MagicMotion Flamingo 2 lacks BLE encryption, enabling data sniffing and packet forgery. |
1Qualcomm 22Aqt1000 Firmware Qca6164 FirmwareQca6174 Firmware+19 moreJun 17, 2026 Jul 13, 2021 N/A· v4 4.3 MEDIUM· v3 3.3 LOW· v2 Weak configuration in WLAN could cause forwarding of unencrypted packets from one client to another in Snapdragon Compute, Snapdragon Connectivity |
1Devolutions 1Devolutions Server Jun 17, 2026 Jul 12, 2021 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 Devolutions Server before 2021.1.18, and LTS before 2020.3.20, allows attackers to intercept private keys via a man-in-the-middle attack against the connections/partial endpoint (which accepts cleartext). |
There is a Cleartext Transmission of Sensitive Information Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect service confidentiality and availability. |
When using http protocol, the user password is transmitted as a clear text parameter for which it is possible to be obtained by an attacker through a MITM attack. This will be fixed starting from Firmware version 3.11.5,...Show more |
2Fedoraproject Quassel Irc2Fedora QuasselJun 17, 2026 Jun 17, 2021 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 Quassel through 0.13.1, when --require-ssl is enabled, launches without SSL or TLS support if a usable X.509 certificate is not found on the local system. |
The VeryFitPro (com.veryfit2hr.second) application 3.2.8 for Android does all communication with the backend API over cleartext HTTP. This includes logins, registrations, and password change requests. This allows informa...Show more |
There is an Information Disclosure vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may result in video streams being intercepted during transmission. |
Cleartext Transmission of Sensitive Information vulnerability in the administrator interface of McAfee Database Security (DBSec) prior to 4.8.2 allows an administrator to view the unencrypted password of the McAfee Insig...Show more |
Intra-cluster communication does not use TLS. The services within the NGINX Controller 3.x before 3.4.0 namespace are using cleartext protocols inside the cluster. |
Local File Inclusion vulnerability in Ab Initio Control>Center before 4.0.2.6 allows remote attackers to retrieve arbitrary files. Fixed in v4.0.2.6 and v4.0.3.1. |
1Couchbase 1Couchbase Server Jun 17, 2026 May 26, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in Couchbase Server 5.x and 6.x before 6.5.2 and 6.6.x before 6.6.2. Internal users with administrator privileges, @cbq-engine-cbauth and @index-cbauth, leak credentials in cleartext in the indexe...Show more |
1Couchbase 1Couchbase Server Jun 17, 2026 May 19, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Couchbase Server 6.x through 6.6.1. The Couchbase Server UI is insecurely logging session cookies in the logs. This allows for the impersonation of a user if the log files are obtained by an at...Show more |
1Sitel Sa 1Remote Cap/prx Firmware Jun 17, 2026 May 17, 2021 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 SITEL CAP/PRX firmware version 5.2.01 allows an attacker with access to the local network of the device to obtain the authentication passwords by analysing the network traffic. |
1Ibm 1Cloud Pak For Security Jun 17, 2026 May 14, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 IBM Cloud Pak for Security (CP4S) 1.4.0.0, 1.5.0.0, 1.5.0.1, 1.6.0.0, and 1.6.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An...Show more |
1Moxa 3Nport Ia5150a Firmware Nport Ia5250a FirmwareNport Ia5450a FirmwareJun 17, 2026 May 14, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Cleartext transmission of sensitive information via Moxa Service in NPort IA5000A series serial devices. Successfully exploiting the vulnerability could enable attackers to read authentication data, device configuration,...Show more |
1Moxa 3Nport Ia5150a Firmware Nport Ia5250a FirmwareNport Ia5450a FirmwareJun 17, 2026 May 14, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The NPort IA5000A Series devices use Telnet as one of the network device management services. Telnet does not support the encryption of client-server communications, making it vulnerable to Man-in-the-Middle attacks. |
In JetBrains WebStorm before 2021.1, HTTP requests were used instead of HTTPS. |
1Agenziaentrate 1Desktop Telematico Jun 17, 2026 May 10, 2021 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 Agenzia delle Entrate Desktop Telematico 1.0.0 contacts the jws.agenziaentrate.it server over cleartext HTTP, which allows man-in-the-middle attackers to spoof product updates. |