CWE-319
925 CVEs • Abstraction: Base • Likelihood of Exploit: High
Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
CVEs (925)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
It was discovered that Kibana’s JIRA connector & IBM Resilient connector could be used to return HTTP response data on internal hosts, which may be intentionally hidden from public view. Using this vulnerability, a malic...Show more |
1Ibm 2Security Guardium Key Lifecycle Manager Security Key Lifecycle ManagerJun 17, 2026 Nov 15, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit...Show more |
1Binatoneglobal 21Cn28 Firmware Cn40 FirmwareCn50 Firmware+18 moreJun 17, 2026 Nov 12, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Some device communications in some Motorola-branded Binatone Hubble Cameras with backend Hubble services are not encrypted which could lead to the communication channel being accessible by an attacker. |
1Siemens 1Climatix Pol909 Firmware Jun 17, 2026 Nov 9, 2021 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.42), Climatix POL909 (AWM module) (All versions < V11.34). The web server of affected devices transmits data without TLS encryption....Show more |
IBM QRadar Network Security 5.4.0 and 5.5.0 transmits sensitive or security-critical data in cleartext in a communication channel that can be obtained using man in the middle techniques. IBM X-Force ID: 17467. |
Meross Smart Wi-Fi 2 Way Wall Switch (MSS550X), on its 3.1.3 version and before, creates an open Wi-Fi Access Point without the required security measures in its initial setup. This could allow a remote attacker to obtai...Show more |
1Ibm 2Business Automation Workflow Business Process ManagerJun 17, 2026 Nov 5, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 IBM Business Automation Workflow 18. 19, 20, 21, and IBM Business Process Manager 8.5 and d8.6 transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized intercepti...Show more |
The affected product is vulnerable to cookie information being transmitted as cleartext over HTTP. An attacker can capture network traffic, obtain the user’s cookie and take over the account. |
Delta Electronics DIALink versions 1.2.4.0 and prior runs by default on HTTP, which may allow an attacker to be positioned between the traffic and perform a machine-in-the-middle attack to access information without auth...Show more |
Datalust Seq.App.EmailPlus (aka seq-app-htmlemail) 3.1.0-dev-00148, 3.1.0-dev-00170, and 3.1.0-dev-00176 can use cleartext SMTP on port 25 in some cases where encryption on port 465 was intended. |
The OptinMonster WordPress plugin is vulnerable to sensitive information disclosure and unauthorized setting updates due to insufficient authorization validation via the logged_in_or_has_api_key function in the ~/OMAPI/R...Show more |
The Juniper Networks CTPView server is not enforcing HTTP Strict Transport Security (HSTS). HSTS is an optional response header which allows servers to indicate that content from the requested domain will only be served...Show more |
1Mitsubishielectric 8R08psfcpu Firmware R08sfcpu FirmwareR120psfcpu Firmware+5 moreJun 17, 2026 Oct 14, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Cleartext Transmission of Sensitive InformationCleartext transmission of sensitive information vulnerability in MELSEC iQ-R series Safety CPU R08/16/32/120SFCPU firmware versions "26" and prior and MELSEC iQ-R series SIL...Show more |
In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user. |
LaraCMS v1.0.1 transmits sensitive information in cleartext which can be intercepted by attackers. |
The Credova_Financial WordPress plugin discloses a site's associated Credova API account username and password in plaintext via an AJAX action whenever a site user goes to checkout on a page that has the Credova Financin...Show more |
8Apple DebianFedoraproject+5 more29Cloud Backup Clustered Data OntapCommerce Guided Search+26 moreJun 17, 2026 Sep 29, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLU...Show more |
1Riconmobile 1S9922l Firmware Jun 17, 2026 Sep 28, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 RICON Industrial Cellular Router S9922L 16.10.3(3794) is affected by cleartext storage of sensitive information and sends username and password as base64. |
1Netgear 11R6400v2 Firmware R6700 FirmwareR6700v3 Firmware+8 moreJun 17, 2026 Sep 21, 2021 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 The update process of the Circle Parental Control Service on various NETGEAR routers allows remote attackers to achieve remote code execution as root via a MitM attack. While the parental controls themselves are not enab...Show more |
Barco MirrorOp Windows Sender before 2.5.3.65 uses cleartext HTTP and thus allows rogue software upgrades. An attacker on the local network can achieve remote code execution on any computer that tries to update Windows S...Show more |