Skip to main content

CWE archive

CWE-319 CVEs

Programmatic archive

898 CVEs tagged with CWE-31982 Critical, 359 High, 403 Medium, 54 Low, 0 Unrated.

CVE-2026-3182

Published Jul 21, 2026

Zohocorp ManageEngine Endpoint Central versions before 11.4.2528.34 are affected by cleartext transmission of sensitive information vulnerability.

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-47255

Published Jul 20, 2026

AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0.9.10 had weakness related to…

CVSS 8.2 · High
evidence mentions
7
Buzz score
25.8

CVE-2026-48022

Published Jul 17, 2026

@hapi/wreck is an HTTP client utility. Prior to 18.1.2, Wreck strips credential headers including Authorization, Cookie, and Proxy-Authorization before following a cross-origin re…

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-48978

Published Jul 17, 2026

oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, auth.Client follows the realm URL from a registry's WWW-Authenticate: Bearer challenge without validating the s…

CVSS 2.1 · Low
evidence mentions
3
Buzz score
18.9

CVE-2026-34346

Published Jul 14, 2026

Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
29.1

CVE-2026-53624

Published Jul 8, 2026

Fiber is an Express inspired web framework written in Go. Prior to 3.4.0, the helmet middleware in middleware/helmet/helmet.go never sets the Strict-Transport-Security response he…

CVSS 4.8 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2025-12530

Published Jun 30, 2026

IBM watsonx.data intelligence 5.2.2, 5.3.0, 5.3.1, 5.3.1 through patch-1 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-55844

Published Jun 29, 2026

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2025.5.0, The iOS companion app ignores the SSID allowlist for internal…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-49486

Published Jun 26, 2026

The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p()`, so although the control channel was TLS-protected the d…

CVSS 7.5 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-44726

Published Jun 23, 2026

Deno is a JavaScript, TypeScript, and WebAssembly runtime. From 2.0.0 until 2.7.8, a flaw in Deno's Node.js tls compatibility layer could cause a TLS client to transmit applicatio…

CVSS 7.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-55568

Published Jun 23, 2026

Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, in certain configurations, traffic expected to be protected by TLS on the hop to the proxy is transmitted in cleartext. P…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-15619

Published Jun 23, 2026

HCL Connections contains a broken access control vulnerability that may allow an unauthorized user to view data in a single specific scenario.

CVSS 3.5 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-11833

Published Jun 23, 2026

Overview: A vulnerability has been found in FAST/TOOLS and CI Server. The web server may return a response containing the CI Server setting information. This information could b…

CVSS 8.2 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-50034

Published Jun 19, 2026

An attacker within BLE communication range can passively intercept wireless traffic and obtain sensitive health-related information, including glucose measurement values.

CVSS 7.1 · High
evidence mentions
4
Buzz score
31.1

CVE-2026-50200

Published Jun 17, 2026

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Management.Endpoint prior to version 4.2.0…

CVSS 7.5 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-9741

Published Jun 9, 2026

A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (QE) or Client-Side Field Level Encryption (CSFLE) results in literal values fo…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-45432

Published Jun 4, 2026

This vulnerability exists in GX Earth ONT models due to the transmission of user credentials in plaintext over HTTP in its web management interface. A remote attacker could exploi…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-8874

Published Jun 3, 2026

Version 3.0.7 of the Securly Chrome Extension downloads JSON files containing crisis alert keywords and filtering rules over unencrypted HTTP via the Fetch API. Other endpoints in…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-36610

Published Jun 3, 2026

Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 transmits DDNS credentials over plaintext HTTP with only Base64 encoding. The firmware contains no TLS implementation, all…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-7666

Published Jun 3, 2026

An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.core.mail.backends.smtp.EmailBackend` in Django fails to prevent reuse of a partially-initialized…

CVSS 2.3 · Low
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2023-52951

Published Jun 3, 2026

A cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703 allows man-in-the-middle attackers to obtain user credential.

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-10584

Published Jun 2, 2026

Proxy server in Graph Explorer before 3.0.1 falls back to HTTP when certificate files are missing, which might allow remote threat actors to obtain sensitive information via inter…

CVSS 8.2 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-43625

Published Jun 1, 2026

CodexBar prior to 0.32.0 contains a session cookie leakage vulnerability that allows network attackers to intercept imported browser session cookies by exploiting improper redirec…

CVSS 8.2 · High
evidence mentions
4
Buzz score
22.6
Showing 1-25 of 898 CVEsPage 1 of 36