Skip to main content

CWE archive

CWE-319 CVEs

Programmatic archive

897 CVEs tagged with CWE-31982 Critical, 359 High, 402 Medium, 54 Low, 0 Unrated.

CVE-2024-4161

Published Apr 25, 2024

In Brocade SANnav, before Brocade SANnav v2.3.0, syslog traffic received clear text. This could allow an unauthenticated, remote attacker to capture sensitive information.

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-28275

Published Apr 3, 2024

Puwell Cloud Tech Co, Ltd 360Eyes Pro v3.9.5.16(3090516) was discovered to transmit sensitive information in cleartext. This vulnerability allows attackers to intercept and access…

CVSS 6.5 · Medium

CVE-2024-25960

Published Mar 28, 2024

Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains a cleartext transmission of sensitive information vulnerability. A local low privileged attacker could potentially…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-28250

Published Mar 18, 2024

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.14.0 and prior to versions 1.14.8 and 1.15.2, In Cilium clusters w…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-28249

Published Mar 18, 2024

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.13.13, 1.14.8, and 1.15.2, in Cilium clusters with IPsec enabled and…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-26288

Published Mar 12, 2024

An unauthenticated remote attacker can influence the communication due to the lack of encryption of sensitive data via a MITM. Charging is not affected.

CVSS 8.7 · High

CVE-2023-27291

Published Mar 3, 2024

IBM Watson CP4D Data Stores 4.6.0, 4.6.1, 4.6.2, and 4.6.3 does not encrypt sensitive or critical information before storage or transmission which could allow an attacker to obtai…

CVSS 4.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-47745

Published Mar 3, 2024

IBM MQ Operator 2.0.0 LTS, 2.0.18 LTS, 3.0.0 CD, 3.0.1 CD, 2.4.0 through 2.4.7, 2.3.0 through 2.3.3, 2.2.0 through 2.2.2, and 2.3.0 through 2.3.3 stores or transmits user credenti…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-25631

Published Feb 20, 2024

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who have enabled an external kvstore and Wireguard transparent encrypti…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-25630

Published Feb 20, 2024

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who are using CRDs to store Cilium state (the default configuration) an…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-42016

Published Feb 9, 2024

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.3 does not set the secure attribute on authorization tokens or session cookies. Atta…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32328

Published Feb 7, 2024

IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure protocols in some instances that could allow an attacker on the network to take control of the server. IBM X-Fo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-50962

Published Feb 2, 2024

IBM PowerSC 1.3, 2.0, and 2.1 MFA does not implement the "HTTP Strict Transport Security" (HSTS) web security policy mechanism. IBM X-Force ID: 276004.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-46889

Published Jan 23, 2024

Meross MSH30Q 4.5.23 is vulnerable to Cleartext Transmission of Sensitive Information. During the device setup phase, the MSH30Q creates an unprotected Wi-Fi access point. In this…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort
Showing 276-300 of 897 CVEsPage 12 of 36