Skip to main content

CWE archive

CWE-319 CVEs

Programmatic archive

897 CVEs tagged with CWE-31982 Critical, 359 High, 402 Medium, 54 Low, 0 Unrated.

CVE-2020-8356

Published Mar 9, 2021

An internal product security audit of LXCO, prior to version 1.2.2, discovered that optional passwords, if specified, for the Syslog and SMTP forwarders are written to an internal…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4695

Published Mar 8, 2021

IBM API Connect V10 is impacted by insecure communications during database replication. As the data replication happens over insecure communication channels, an attacker can view…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-25605

Published Feb 17, 2021

Cleartext transmission of sensitive information in Agora Video SDK prior to 3.1 allows a remote attacker to obtain access to audio and video of any ongoing Agora video call throug…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-20335

Published Feb 11, 2021

For MongoDB Ops Manager versions prior to and including 4.2.24 with multiple OM application servers, that have SSL turned on for their MongoDB processes, the upgrade to MongoDB Op…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-8355

Published Feb 10, 2021

An internal product security audit of Lenovo XClarity Administrator (LXCA) prior to version 3.1.0 discovered the Windows OS credentials provided by the LXCA user to perform driver…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20623

Published Feb 5, 2021

Video Insight VMS versions prior to 7.8 allows a remote attacker to execute arbitrary code with the system user privilege by sending a specially crafted request.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-29662

Published Feb 2, 2021

In Harbor 2.0 before 2.0.5 and 2.1.x before 2.1.2 the catalog’s registry API is exposed on an unauthenticated path.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-29005

Published Jan 29, 2021

The API in the Push extension for MediaWiki through 1.35 used cleartext for ApiPush credentials, allowing for potential information disclosure.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-25169

Published Jan 26, 2021

The affected Reolink P2P products do not sufficiently protect data transferred between the local device and Reolink servers. This can allow an attacker to access sensitive informa…

CVSS 7.5 · High

CVE-2021-21270

Published Jan 22, 2021

OctopusDSC is a PowerShell module with DSC resources that can be used to install and configure an Octopus Deploy Server and Tentacle agent. In OctopusDSC version 4.0.977 and earli…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4893

Published Jan 7, 2021

IBM Emptoris Strategic Supply Management 10.1.0, 10.1.1, and 10.1.3 transmits sensitive information in HTTP GET request parameters. This may lead to information disclosure via man…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4899

Published Jan 5, 2021

IBM API Connect 5.0.0.0 through 5.0.8.10 could potentially leak sensitive information or allow for data corruption due to plain text transmission of sensitive information across t…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-19944

Published Dec 31, 2020

A cleartext transmission of sensitive information vulnerability has been reported to affect certain QTS devices. If exploited, this vulnerability allows a remote attacker to gain…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11718

Published Dec 23, 2020

An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and below. Its software-update packages are downloaded via cleartext HTTP.

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort
Showing 576-600 of 897 CVEsPage 24 of 36