Skip to main content

CWE archive

CWE-319 CVEs

Programmatic archive

897 CVEs tagged with CWE-31982 Critical, 359 High, 402 Medium, 54 Low, 0 Unrated.

CVE-2024-41262

Published Jul 31, 2024

mmudb v1.9.3 was discovered to use the HTTP protocol in the ShowMetricsRaw and ShowMetricsAsText functions, possibly allowing attackers to intercept communications via a man-in-th…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-41124

Published Jul 19, 2024

Puncia is the Official CLI utility for Subdomain Center & Exploit Observer. `API_URLS` is utilizing HTTP instead of HTTPS for communication that can lead to issues like Eavesdropp…

CVSS 6.3 · Medium

CVE-2024-5631

Published Jul 9, 2024

Longse NVR (Network Video Recorder) model NVR3608PGE2W, as well as products based on this device, are transmitting user's login and password to a remote control service without us…

CVSS 6.0 · Medium

CVE-2024-0066

Published Jun 18, 2024

Johan Fagerström, member of the AXIS OS Bug Bounty Program, has found that a O3C feature may expose sensitive traffic between the client (Axis device) and (O3C) server. If O3C is…

CVSS 5.3 · Medium

CVE-2024-27166

Published Jun 14, 2024

Coredump binaries in Toshiba printers have incorrect permissions. A local attacker can steal confidential information. As for the affected products/models/versions, see the refere…

CVSS 7.4 · High

CVE-2024-27163

Published Jun 14, 2024

Toshiba printers will display the password of the admin user in clear-text and additional passwords when sending 2 specific HTTP requests to the internal API. An attacker stealing…

CVSS 6.5 · Medium

CVE-2024-35210

Published Jun 11, 2024

A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server is not enforcing HSTS. This could allow an attack…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37163

Published Jun 7, 2024

SkyScrape is a GUI Dashboard for AWS Infrastructure and Managing Resources and Usage Costs. SkyScrape's API requests are currently unsecured HTTP requests, leading to potential v…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-36426

Published May 27, 2024

In TARGIT Decision Suite 23.2.15007.0 before Autumn 2023, the session token is part of the URL and may be sent in a cleartext HTTP session.

CVSS 7.5 · High

CVE-2024-35060

Published May 21, 2024

An issue in the YAML Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands via supplying a crafted YAML file.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-35059

Published May 21, 2024

An issue in the Pickle Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-35058

Published May 21, 2024

An issue in the API wait function of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary code via supplying a crafted string.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-35057

Published May 21, 2024

An issue in NASA AIT-Core v2.5.2 allows attackers to execute arbitrary code via a crafted packet.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-31840

Published May 21, 2024

An issue was discovered in Italtel Embrace 1.6.4. The web application inserts cleartext passwords in the HTML source code. An authenticated user is able to edit the configuration…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30209

Published May 14, 2024

A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions < V3.0.…

CVSS 9.0 · Critical

CVE-2024-28134

Published May 14, 2024

An unauthenticated remote attacker can extract a session token with a MitM attack and gain web-based management access with the privileges of the currently logged in user due to c…

CVSS 7.0 · High

CVE-2024-0098

Published May 14, 2024

NVIDIA ChatRTX for Windows contains a vulnerability in the ChatRTX UI and backend, where a user can cause a clear-text transmission of sensitive information issue by data sniffing…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-32510

Published May 14, 2024

An issue was discovered on certain Nuki Home Solutions devices. The HTTP API exposed by a Bridge used an unencrypted channel to provide an administrative interface. A token can be…

CVSS 7.1 · High

CVE-2024-1657

Published Apr 25, 2024

A flaw was found in the ansible automation platform. An insecure WebSocket connection was being used in installation from the Ansible rulebook EDA server. An attacker that has acc…

CVSS 8.1 · High
Showing 251-275 of 897 CVEsPage 11 of 36