Skip to main content

CWE archive

CWE-319 CVEs

Programmatic archive

897 CVEs tagged with CWE-31982 Critical, 359 High, 402 Medium, 54 Low, 0 Unrated.

CVE-2020-14248

Published Dec 16, 2020

BigFix Inventory up to v10.0.2 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier f…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-29380

Published Nov 29, 2020

An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices. TELNET is offere…

CVSS 5.9 · Medium

CVE-2020-5426

Published Nov 11, 2020

Scheduler for TAS prior to version 1.4.0 was permitting plaintext transmission of UAA client token by sending it over a non-TLS connection. This also depended on the configuration…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-27657

Published Oct 29, 2020

Cleartext transmission of sensitive information vulnerability in DDNS in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers to eavesdrop authentica…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-27656

Published Oct 29, 2020

Cleartext transmission of sensitive information vulnerability in DDNS in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to eavesdrop au…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-7744

Published Oct 15, 2020

This affects all versions of package com.mintegral.msdk:alphab. The Android SDK distributed by the company contains malicious functionality in this module that tracks: 1. Download…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15785

Published Sep 9, 2020

A vulnerability has been identified in Siveillance Video Client (All versions). In environments where Windows NTLM authentication is enabled the affected client application transm…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2232

Published Aug 12, 2020

Jenkins Email Extension Plugin 2.72 and 2.73 transmits and displays the SMTP password in plain text as part of the global Jenkins configuration form, potentially resulting in its…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-9526

Published Aug 10, 2020

CS2 Network P2P through 3.x, as used in millions of Internet of Things devices, suffers from an information exposure flaw that exposes user session data to supernodes in the netwo…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 601-625 of 897 CVEsPage 25 of 36