Skip to main content

CWE archive

CWE-319 CVEs

Programmatic archive

897 CVEs tagged with CWE-31982 Critical, 359 High, 402 Medium, 54 Low, 0 Unrated.

CVE-2020-15954

Published Jul 27, 2020

KDE KMail 19.12.3 (aka 5.13.3) engages in unencrypted POP3 communication during times when the UI indicates that encryption is in use.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4397

Published Jul 22, 2020

IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 transmits sensitive information in plain text which could be obtained by an attacker using man in the middle techniques. IBM X-Force ID: 1…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-3442

Published Jul 20, 2020

The DuoConnect client enables users to establish SSH connections to hosts protected by a DNG instance. When a user initiates an SSH connection to a DNG-protected host for the firs…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-14171

Published Jul 9, 2020

Atlassian Bitbucket Server from version 4.9.0 before version 7.2.4 allows remote attackers to intercept unencrypted repository import requests via a Man-in-the-Middle (MITM) attac…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-10281

Published Jul 3, 2020

This vulnerability applies to the Micro Air Vehicle Link (MAVLink) protocol and allows a remote attacker to gain access to sensitive information provided it has access to the comm…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-2210

Published Jul 2, 2020

Jenkins Stash Branch Parameter Plugin 0.3.0 and earlier transmits configured passwords in plain text as part of its global Jenkins configuration form, potentially resulting in the…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5899

Published Jul 1, 2020

In NGINX Controller 3.0.0-3.4.0, recovery code required to change a user's password is transmitted and stored in the database in plain text, which allows an attacker who can inter…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-5594

Published Jun 23, 2020

Mitsubishi Electric MELSEC iQ-R, iQ-F, Q, L, and FX series CPU modules all versions contain a vulnerability that allows cleartext transmission of sensitive information between CPU…

CVSS 9.8 · Critical
Showing 626-650 of 897 CVEsPage 26 of 36