Vulnerability index

Browse CVEs

798 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cleartext TransmissionCWE-319 × clear
Unclassified MEDIUM 6.0
CVE-2026-15806

The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, d…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.5
CVE-2026-20294

A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitiv…

No fix yet
Fix from $1,600 2026-08-05
Data\ HIGH 7.5
CVE-2026-18536

Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP. The Data::Entropy::RawSource::RandomOrg and Data::Entropy:…

Fix: 0.010+
Fix from $1,950 2026-08-01
Ipados MEDIUM 6.5
CVE-2026-64742

This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 an…

Fix: 26.6+
Fix from $1,600 2026-07-27
Unclassified HIGH 8.2
CVE-2026-47255

AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0…

No fix yet
Fix from $1,950 2026-07-20
Unclassified MEDIUM 6.5
CVE-2026-48022

@hapi/wreck is an HTTP client utility. Prior to 18.1.2, Wreck strips credential headers including Authorization, Cookie, and Proxy-Authorization befo…

No fix yet
Fix from $1,600 2026-07-17
Windows 10 1607 MEDIUM 5.5
CVE-2026-34346

Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose informatio…

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,600 2026-07-14
Watsonx.data Intelligence MEDIUM 5.9
CVE-2025-36336

IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 transmits data in clear text that could allow an attacker to obtain sensitive information us…

Mitigation only
Fix from $1,600 2026-06-30
Watsonx.data Intelligence MEDIUM 5.9
CVE-2025-12530

IBM watsonx.data intelligence 5.2.2, 5.3.0, 5.3.1, 5.3.1 through Patch 1 transmits data in clear text that could allow an attacker to obtain sensitiv…

Mitigation only
Fix from $1,600 2026-06-30
Unclassified HIGH 7.5
CVE-2026-55844

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2025.5.0, The iOS companion app ignores th…

Mitigation only
Fix from $1,950 2026-06-29
Apache Airflow Providers Ftp HIGH 7.5
CVE-2026-49486

The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p()`, so although the control c…

Fix: 3.15.1+
Fix from $1,950 2026-06-26
Deno CRITICAL 9.1
CVE-2026-44726

Deno is a JavaScript, TypeScript, and WebAssembly runtime. From 2.0.0 until 2.7.8, a flaw in Deno's Node.js tls compatibility layer could cause a TLS…

Fix: 2.7.8+
Fix from $2,300 2026-06-23
Guzzle MEDIUM 5.9
CVE-2026-55568

Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, in certain configurations, traffic expected to be protected by TLS on the hop to the proxy …

Fix: 7.12.1+
Fix from $1,600 2026-06-23
Unclassified HIGH 8.2
CVE-2026-11833

Overview: A vulnerability has been found in FAST/TOOLS and CI Server. The web server may return a response containing the CI Server setting informat…

Mitigation only
Fix from $1,950 2026-06-23
Unclassified MEDIUM 6.5
CVE-2026-50034

An attacker within BLE communication range can passively intercept wireless traffic and obtain sensitive health-related information, including gluc…

Mitigation only
Fix from $1,600 2026-06-19
Unclassified HIGH 7.5
CVE-2026-50200

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Management.E…

Patch available
Fix from $1,950 2026-06-17
MongoDB MEDIUM 6.5
CVE-2026-9741

A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (QE) or Client-Side Field Level Encryption (CSFLE)…

Fix: 7.0.35 / 8.0.24+
Fix from $1,600 2026-06-09
Unclassified HIGH 8.7
CVE-2026-45432

This vulnerability exists in GX Earth ONT models due to the transmission of user credentials in plaintext over HTTP in its web management interface. …

Mitigation only
Fix from $1,950 2026-06-04
Securly HIGH 7.1
CVE-2026-8874

Version 3.0.7 of the Securly Chrome Extension downloads JSON files containing crisis alert keywords and filtering rules over unencrypted HTTP via the…

Mitigation only
Fix from $1,950 2026-06-03
Unclassified MEDIUM 5.9
CVE-2026-36610

Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 transmits DDNS credentials over plaintext HTTP with only Base64 encoding. The firmware conta…

Mitigation only
Fix from $1,600 2026-06-03
Note Station Client MEDIUM 5.9
CVE-2023-52951

A cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703 allows man-in-the-middle attackers t…

Fix: 2.2.4-703+
Fix from $1,600 2026-06-03
Unclassified MEDIUM 5.9
CVE-2026-10584

Proxy server in Graph Explorer before 3.0.1 falls back to HTTP when certificate files are missing, which might allow remote threat actors to obtain s…

Mitigation only
Fix from $1,600 2026-06-02
Unclassified MEDIUM 5.9
CVE-2026-43625

CodexBar prior to 0.32.0 contains a session cookie leakage vulnerability that allows network attackers to intercept imported browser session cookies …

Patch available
Fix from $1,600 2026-06-01
Unclassified MEDIUM 6.3
CVE-2026-25599

Missing authentication and clear‑text transmission of data from the heat pumps to the control server, combined with the absence of input validation o…

Mitigation only
Fix from $1,600 2026-06-01
Tapo L535e Firmware HIGH 7.5
CVE-2026-34126

TP-Link has identified a vulnerability in Tapo L535E v1.0 and v3.0, Tapo P300 v1.0, and Tapo D100C v1.0, where Bluetooth communication during the ini…

Mitigation only
Fix from $1,950 2026-05-28
Joomla\! CRITICAL 9.8
CVE-2026-48902

The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.

Fix: 5.4.6 / 6.1.1+
Fix from $2,300 2026-05-26
Isaac Launchable CRITICAL 9.8
CVE-2026-24212

NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is transmitted in clear text. A successful exploit of this vul…

Fix: after 1.2
Fix from $2,300 2026-05-26
Unclassified MEDIUM 5.3
CVE-2026-38740

Foscam VD1 Video Doorbell before V5.3.13_1072 is vulnerable to Cleartext Transmission of Sensitive Information. The device transmits sensitive Sessio…

Mitigation only
Fix from $1,600 2026-05-14
Unclassified MEDIUM 5.4
CVE-2025-62310

HCL AION is affected by a vulnerability where encryption is not enforced for certain data transmissions or operations. This may expose sensitive info…

No fix yet
Fix from $1,600 2026-05-14
Curl HIGH 7.5
CVE-2026-6276

Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* b…

Fix: 8.20.0+
Fix from $1,950 2026-05-13