Skip to main content

CWE archive

CWE-319 CVEs

Programmatic archive

901 CVEs tagged with CWE-31982 Critical, 360 High, 405 Medium, 54 Low, 0 Unrated.

CVE-2021-39026

Published Feb 18, 2022

IBM Guardium Data Encryption (GDE) 5.0.0.2 and 5.0.0.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transpor…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-25180

Published Feb 15, 2022

Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier includes password parameters from the original build in replayed builds, allowing attackers with Run/Replay permissi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-29397

Published Feb 4, 2022

Cleartext Transmission of Sensitive Information in /northstar/Admin/login.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote local user to intercept use…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-45735

Published Feb 4, 2022

TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to use the HTTP protocol for authentication into the admin interface, allowing attackers to intercept user credentials via pa…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-41835

Published Jan 21, 2022

Fresenius Kabi Agilia Link + version 3.0 does not enforce transport layer encryption. Therefore, transmitted data may be sent in cleartext. Transport layer encryption is offered o…

CVSS 7.3 · High

CVE-2022-23105

Published Jan 12, 2022

Jenkins Active Directory Plugin 2.25 and earlier does not encrypt the transmission of data between the Jenkins controller and Active Directory servers in most configurations.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20175

Published Dec 30, 2021

Netgear Nighthawk R6700 version 1.0.4.120 does not utilize secure communication methods to the SOAP interface. By default, all communication to/from the device's SOAP Interface (p…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2021-20174

Published Dec 30, 2021

Netgear Nighthawk R6700 version 1.0.4.120 does not utilize secure communication methods to the web interface. By default, all communication to/from the device's web interface is s…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2021-20169

Published Dec 30, 2021

Netgear RAX43 version 1.0.3.96 does not utilize secure communications to the web interface. By default, all communication to/from the device is sent via HTTP, which causes potenti…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-45100

Published Dec 16, 2021

The ksmbd server through 3.4.2, as used in the Linux kernel through 5.15.8, sometimes communicates in cleartext even though encryption has been enabled. This occurs because it set…

CVSS 7.5 · High

CVE-2021-44518

Published Dec 2, 2021

An issue was discovered in the eGeeTouch 3rd Generation Travel Padlock application for Android. The lock sends a pairing code before each operation (lock or unlock) activated via…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-37939

Published Nov 18, 2021

It was discovered that Kibana’s JIRA connector & IBM Resilient connector could be used to return HTTP response data on internal hosts, which may be intentionally hidden from publi…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-4152

Published Nov 8, 2021

IBM QRadar Network Security 5.4.0 and 5.5.0 transmits sensitive or security-critical data in cleartext in a communication channel that can be obtained using man in the middle tech…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3774

Published Nov 5, 2021

Meross Smart Wi-Fi 2 Way Wall Switch (MSS550X), on its 3.1.3 version and before, creates an open Wi-Fi Access Point without the required security measures in its initial setup. Th…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2021-42699

Published Nov 5, 2021

The affected product is vulnerable to cookie information being transmitted as cleartext over HTTP. An attacker can capture network traffic, obtain the user’s cookie and take over…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-38418

Published Nov 3, 2021

Delta Electronics DIALink versions 1.2.4.0 and prior runs by default on HTTP, which may allow an attacker to be positioned between the traffic and perform a machine-in-the-middle…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 501-525 of 901 CVEsPage 21 of 37