CWE-319
923 CVEs • Abstraction: Base • Likelihood of Exploit: High
Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
CVEs (923)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ibm 1Cloud Pak For Security Jun 17, 2026 May 14, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 IBM Cloud Pak for Security (CP4S) 1.4.0.0, 1.5.0.0, 1.5.0.1, 1.6.0.0, and 1.6.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An...Show more |
1Moxa 3Nport Ia5150a Firmware Nport Ia5250a FirmwareNport Ia5450a FirmwareJun 17, 2026 May 14, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Cleartext transmission of sensitive information via Moxa Service in NPort IA5000A series serial devices. Successfully exploiting the vulnerability could enable attackers to read authentication data, device configuration,...Show more |
1Moxa 3Nport Ia5150a Firmware Nport Ia5250a FirmwareNport Ia5450a FirmwareJun 17, 2026 May 14, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The NPort IA5000A Series devices use Telnet as one of the network device management services. Telnet does not support the encryption of client-server communications, making it vulnerable to Man-in-the-Middle attacks. |
In JetBrains WebStorm before 2021.1, HTTP requests were used instead of HTTPS. |
1Agenziaentrate 1Desktop Telematico Jun 17, 2026 May 10, 2021 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 Agenzia delle Entrate Desktop Telematico 1.0.0 contacts the jws.agenziaentrate.it server over cleartext HTTP, which allows man-in-the-middle attackers to spoof product updates. |
1Remotemouse 1Emote Remote Mouse Jun 17, 2026 May 7, 2021 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in Emote Remote Mouse through 4.0.0.0. It uses cleartext HTTP to check, and request, updates. Thus, attackers can machine-in-the-middle a victim to download a malicious binary in place of the real...Show more |
1Remotemouse 1Emote Remote Mouse Jun 17, 2026 May 7, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in Emote Remote Mouse through 4.0.0.0. Attackers can maximize or minimize the window of a running process by sending the process name in a crafted packet. This information is sent in cleartext and...Show more |
1Google 1Google/apple Exposure Notifications Jun 17, 2026 Apr 28, 2021 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 GAEN (aka Google/Apple Exposure Notifications) through 2021-04-27 on Android allows attackers to obtain sensitive information, such as a user's location history, in-person social graph, and (sometimes) COVID-19 infection...Show more |
pgsync before 0.6.7 is affected by Information Disclosure of sensitive information. Syncing the schema with the --schema-first and --schema-only options is mishandled. For example, the sslmode connection parameter may be...Show more |
A smart proxy that provides a restful API to various sub-systems of the Foreman is affected by the flaw which can cause a Man-in-the-Middle attack. The FreeIPA module of Foreman smart proxy does not check the SSL certifi...Show more |
1Dell 1Emc Powerscale Onefs Jun 17, 2026 Apr 20, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Dell PowerScale OneFS 8.1.0 - 9.1.0 contains an LDAP Provider inability to connect over TLSv1.2 vulnerability. It may make it easier to eavesdrop and decrypt such traffic for a malicious actor. Note: This does not affect...Show more |
1Fibaro 2Home Center 2 Firmware Home Center Lite FirmwareJun 17, 2026 Apr 19, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Fibaro Home Center 2 and Lite devices in all versions provide a web based management interface over unencrypted HTTP protocol. Communication between the user and the device can be eavesdropped to hijack sessions, toke...Show more |
1Mcafee 1Content Security Reporter Jun 17, 2026 Apr 15, 2021 N/A· v4 4.3 MEDIUM· v3 2.7 LOW· v2 Cleartext Transmission of Sensitive Information vulnerability in the ePO Extension of McAfee Content Security Reporter (CSR) prior to 2.8.0 allows an ePO administrator to view the unencrypted password of the McAfee Web G...Show more |
Cleartext Transmission of Sensitive Information between McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update and McAfee Global Threat Intelligence (GTI) servers using DNS allows a remote attack...Show more |
1Netgear 43Br200 Firmware Br500 FirmwareD7800 Firmware+40 moreJun 17, 2026 Apr 14, 2021 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR Nighthawk R7800. Authentication is not required to exploit this vulnerability The specific flaw exists w...Show more |
An internal product security audit of Lenovo XClarity Controller (XCC) discovered that the XCC configuration backup/restore password may be written to an internal XCC log buffer if Lenovo XClarity Administrator (LXCA) is...Show more |
Cleartext transmission of sensitive information in Netop Vision Pro up to and including 9.7.1 allows a remote unauthenticated attacker to gather credentials including Windows login usernames and passwords. |
Wrongthink peer-to-peer, end-to-end encrypted messenger with PeerJS and Axolotl ratchet. In wrongthink from version 2.0.0 and before 2.3.0 there was a set of vulnerabilities causing inadequate encryption strength. Part o...Show more |
1Advantech 1Spectre Rt Ert351 Firmware Jun 17, 2026 Mar 17, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Advantech Spectre RT ERT351 Versions 5.1.3 and prior logins and passwords are transmitted in clear text form, which may allow an attacker to intercept the request. |
The Taidii Diibear Android application 2.4.0 and all its derivatives allow attackers to view private chat messages and media files via logcat because of excessive logging. |