Vulnerability index

Browse CVEs

798 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cleartext TransmissionCWE-319 × clear
Curl MEDIUM 5.9
CVE-2026-4873

A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool. If an in…

Fix: 8.20.0+
Fix from $1,600 2026-05-13
Unclassified HIGH 7.5
CVE-2026-45180

Catalyst::Plugin::Statsd versions through 0.10.0 for Perl may leak session ids. If the communication channel to the statsd daemon is not secured (fo…

Mitigation only
Fix from $1,950 2026-05-10
Unclassified MEDIUM 5.3
CVE-2026-45179

Plack::Middleware::Statsd versions before 0.9.0 for Perl may leak user IP addresses. If the communication channel to the statsd daemon is not secure…

Mitigation only
Fix from $1,600 2026-05-10
Unclassified MEDIUM 5.3
CVE-2026-32683

Some EZVIZ products utilize older versions of cloud feature modules with legacy API interfaces, which pose a data transmission risk. Attackers can ex…

Mitigation only
Fix from $1,600 2026-05-09
Dfxanalytics CRITICAL 9.1
CVE-2025-59852

HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability where data is transmitted over the network without encrypt…

Fix: 4.1+
Fix from $2,300 2026-05-06
Tew 821dap Firmware HIGH 8.1
CVE-2026-7610

A vulnerability has been found in TRENDnet TEW-821DAP 1.12B01. This affects an unknown function of the file /www/cgi/ssi of the component Firmware Up…

No fix yet
Fix from $1,950 2026-05-02
Unclassified HIGH 8.8
CVE-2026-42514

This vulnerability exists in e-Sushrut due to exposure of OTPs in plaintext within API responses. A remote attacker could exploit this vulnerability …

Mitigation only
Fix from $1,950 2026-04-29
X3500 Firmware MEDIUM 5.3
CVE-2026-40431

A vulnerability exists in SenseLive X3050’s web management interface due to its reliance on unencrypted HTTP for all administrative communication. Be…

Mitigation only
Fix from $1,600 2026-04-24
Flowise HIGH 7.5
CVE-2026-41275

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the password reset functionality on cloud.fl…

Fix: 3.1.0+
Fix from $1,950 2026-04-23
Bigfix Service Management MEDIUM 5.3
CVE-2025-31981

HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, allowing unencrypted access.  A…

Mitigation only
Fix from $1,600 2026-04-21
Openclaw MEDIUM 5.7
CVE-2026-40045

OpenClaw before 2026.4.2 accepts non-loopback cleartext ws:// gateway endpoints and transmits stored gateway credentials over unencrypted connections…

Fix: 2026.4.2+
Fix from $1,600 2026-04-21
Automate HIGH 7.1
CVE-2026-6066

ConnectWise has released a security update for ConnectWise Automate™ that addresses a behavior in the ConnectWise Automate Solution Center where cert…

Fix: 2026.4+
Fix from $1,950 2026-04-20
Cx7 Firmware MEDIUM 6.5
CVE-2026-33569

Anviz CX2 Lite and CX7 administrative sessions occur over HTTP, enabling on‑path attackers to sniff credentials and session data, which can be used…

Mitigation only
Fix from $1,600 2026-04-17
Fortisoar HIGH 7.5
CVE-2026-22155

A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, F…

Fix: 7.5.3 / 7.6.4+
Fix from $1,950 2026-04-14
Fortisoar MEDIUM 6.5
CVE-2026-21742

A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, F…

Fix: 7.5.3 / 7.6.4+
Fix from $1,600 2026-04-14
Apisix HIGH 7.5
CVE-2026-31923

Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. This can occur due to `ssl_verify` in openid-connect plugin configur…

Fix: 3.16.0+
Fix from $1,950 2026-04-14
Apisix MEDIUM 5.3
CVE-2026-31924

Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. tencent-cloud-cls log export uses plaintext HTTP This issue affects …

Fix: 3.16.0+
Fix from $1,600 2026-04-14
Papercut Mf HIGH 7.5
CVE-2026-5115

The PaperCut NG/MF (specifically, the embedded application for Konica Minolta devices) is vulnerable to session hijacking. The PaperCut NG/MF Embedde…

Fix: 25.0.5 / 25.0.9+
Fix from $1,950 2026-03-31
Enterprise Linux HIGH 8.2
CVE-2026-5119

A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext …

No fix yet
Fix from $1,950 2026-03-30
Infosphere Information Server MEDIUM 6.5
CVE-2026-1014

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to exposure of sensitive information via JSON server response manipulation.

Fix: after 11.7.1.6
Fix from $1,600 2026-03-25
Concert MEDIUM 5.9
CVE-2025-64648

IBM Concert 1.0.0 through 2.2.0 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle tec…

Fix: after 2.2.0
Fix from $1,600 2026-03-25
Unclassified MEDIUM 6.1
CVE-2026-20115

A vulnerability in Cisco IOS XE Software for Cisco Meraki could allow a remote, unauthenticated attacker to view confidential device information. …

Mitigation only
Fix from $1,600 2026-03-25
Unclassified CRITICAL 9.1
CVE-2026-24060

Service information is not encrypted when transmitted as BACnet packets over the wire, and can be sniffed, intercepted, and modified by an attacker…

Mitigation only
Fix from $2,300 2026-03-21
Cryptomator HIGH 7.5
CVE-2026-32309

Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, the Hub-based unlock flow explicitly supports hub+http and c…

Fix: 1.19.1+
Fix from $1,950 2026-03-20
Gs 5008pl Firmware MEDIUM 5.9
CVE-2026-32838

Edimax GS-5008PL firmware version 1.00.54 and prior use cleartext HTTP for the web management interface without implementing TLS or SSL encryption. A…

Fix: after 1.00.54
Fix from $1,600 2026-03-17
Datalore MEDIUM 5.7
CVE-2026-32745

In JetBrains Datalore before 2026.1 session hijacking was possible due to missing secure attribute for cookie settings

Fix: 2026.1+
Fix from $1,600 2026-03-13
Sterling Partner Engagement Manager HIGH 7.5
CVE-2025-13718

IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow a remote attacker to obtain sensitive informa…

Fix: 6.2.3.6 / 6.2.4.3+
Fix from $1,950 2026-03-13
Azure Iot Explorer HIGH 7.5
CVE-2026-23661

Cleartext transmission of sensitive information in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.

Fix: 0.15.13+
Fix from $1,950 2026-03-10
Azure Iot Explorer HIGH 7.5
CVE-2026-23662

Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.

Fix: 0.15.13+
Fix from $1,950 2026-03-10
Nexusinterface HIGH 7.5
CVE-2025-70048

An issue pertaining to CWE-319: Cleartext Transmission of Sensitive Information was discovered in Nexusoft NexusInterface v3.2.0-beta.2.

Mitigation only
Fix from $1,950 2026-03-09