Skip to main content

CWE archive

CWE-319 CVEs

Programmatic archive

897 CVEs tagged with CWE-31982 Critical, 359 High, 402 Medium, 54 Low, 0 Unrated.

CVE-2019-12122

Published Mar 18, 2020

An issue was discovered in ONAP Portal through Dublin. By executing a call to ONAPPORTAL/portalApi/loggedinUser, an attacker who possesses a user's cookie may retrieve that user's…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-5107

Published Mar 11, 2020

A cleartext transmission vulnerability exists in the network communication functionality of WAGO e!Cockpit version 1.5.1.1. An attacker with access to network traffic can easily i…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-6198

Published Mar 10, 2020

SAP Solution Manager (Diagnostics Agent), version 720, allows unencrypted connections from unauthenticated sources. This allows an attacker to control all remote functions on the…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-2157

Published Mar 9, 2020

Jenkins Skytap Cloud CI Plugin 2.07 and earlier transmits configured credentials in plain text as part of job configuration forms, potentially resulting in their exposure.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2156

Published Mar 9, 2020

Jenkins DeployHub Plugin 8.0.14 and earlier transmits configured credentials in plain text as part of job configuration forms, potentially resulting in their exposure.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2155

Published Mar 9, 2020

Jenkins OpenShift Deployer Plugin 1.2.0 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2153

Published Mar 9, 2020

Jenkins Backlog Plugin 2.4 and earlier transmits configured credentials in plain text as part of job configuration forms, potentially resulting in their exposure.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2151

Published Mar 9, 2020

Jenkins Quality Gates Plugin 2.5 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposu…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2150

Published Mar 9, 2020

Jenkins Sonar Quality Gates Plugin 1.3.1 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in thei…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2149

Published Mar 9, 2020

Jenkins Repository Connector Plugin 1.2.6 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in the…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2143

Published Mar 9, 2020

Jenkins Logstash Plugin 2.3.1 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-7907

Published Feb 21, 2020

In the JetBrains Scala plugin before 2019.2.1, some artefact dependencies were resolved over unencrypted connections.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-20061

Published Feb 10, 2020

The user-introduction email in MFScripts YetiShare v3.5.2 through v4.5.4 may leak the (system-picked) password if this email is sent in cleartext. In other words, the user is not…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 676-700 of 897 CVEsPage 28 of 36