Skip to main content

CWE archive

CWE-319 CVEs

Programmatic archive

897 CVEs tagged with CWE-31982 Critical, 359 High, 402 Medium, 54 Low, 0 Unrated.

CVE-2021-39882

Published Oct 5, 2021

In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-39342

Published Sep 29, 2021

The Credova_Financial WordPress plugin discloses a site's associated Credova API account username and password in plaintext via an AJAX action whenever a site user goes to checkou…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-38142

Published Sep 7, 2021

Barco MirrorOp Windows Sender before 2.5.3.65 uses cleartext HTTP and thus allows rogue software upgrades. An attacker on the local network can achieve remote code execution on an…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-38373

Published Aug 10, 2021

In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Server requires authentication" is checked.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-33900

Published Jul 26, 2021

While investigating DIRSTUDIO-1219 it was noticed that configured StartTLS encryption was not applied when any SASL authentication mechanism (DIGEST-MD5, GSSAPI) was used. While i…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-36423

Published Jul 19, 2021

An issue was discovered in Arm Mbed TLS before 2.23.0. A remote attacker can recover plaintext because a certain Lucky 13 countermeasure doesn't properly consider the case of a ha…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-36382

Published Jul 12, 2021

Devolutions Server before 2021.1.18, and LTS before 2020.3.20, allows attackers to intercept private keys via a man-in-the-middle attack against the connections/partial endpoint (…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-22380

Published Jun 30, 2021

There is a Cleartext Transmission of Sensitive Information Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect service confidentiality and…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-23846

Published Jun 18, 2021

When using http protocol, the user password is transmitted as a clear text parameter for which it is possible to be obtained by an attacker through a MITM attack. This will be fix…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-32612

Published Jun 16, 2021

The VeryFitPro (com.veryfit2hr.second) application 3.2.8 for Android does all communication with the backend API over cleartext HTTP. This includes logins, registrations, and pass…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-22325

Published Jun 3, 2021

There is an Information Disclosure vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may result in video streams being intercepted during transmiss…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-23896

Published Jun 2, 2021

Cleartext Transmission of Sensitive Information vulnerability in the administrator interface of McAfee Database Security (DBSec) prior to 4.8.2 allows an administrator to view the…

CVSS 3.2 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-23018

Published Jun 1, 2021

Intra-cluster communication does not use TLS. The services within the NGINX Controller 3.x before 3.4.0 namespace are using cleartext protocols inside the cluster.

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort
Showing 526-550 of 897 CVEsPage 22 of 36