Vulnerability index

Browse CVEs

798 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cleartext TransmissionCWE-319 × clear
Rustdesk HIGH 7.5
CVE-2026-30795

Cleartext Transmission of Sensitive Information vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Andro…

Fix: after 1.4.5
Fix from $1,950 2026-03-05
Pebble Prism Ultra Firmware CRITICAL 9.6
CVE-2025-69969

A lack of authentication and authorization mechanisms in the Bluetooth Low Energy (BLE) communication protocol of SRK Powertech Pvt Ltd Pebble Prism …

Fix: 2.5.8+
Fix from $2,300 2026-03-04
App Connect Enterprise Certified Containers Operands MEDIUM 5.9
CVE-2025-13490

IBM App Connect Operator versions CD 11.3.0 through 11.6.0 and 12.1.0 through 12.20.0, LTS versions 12.0.0 through 12.0.20, and IBM App Connect Enter…

Fix: after 12.20.1
Fix from $1,600 2026-03-03
Hanwha Vms Integration MEDIUM 5.6
CVE-2026-20801

Cleartext Transmission of Sensitive Information (CWE-319) in a component used in the Gallagher Hanwha VMS and Gallagher NxWitness VMS integrations al…

Mitigation only
Fix from $1,600 2026-03-03
Android MEDIUM 6.5
CVE-2024-43766

In multiple functions of btm_ble_sec.cc, there is a possible unencrypted communication due to Invalid error handling. This could lead to remote (prox…

Mitigation only
Fix from $1,600 2026-03-02
Unclassified HIGH 7.5
CVE-2025-58107

In Microsoft Exchange through 2019, Exchange ActiveSync (EAS) configurations on on-premises servers may transmit sensitive data from Samsung mobile d…

Mitigation only
Fix from $1,950 2026-03-02
Sl902 Swtgw124as Firmware MEDIUM 5.9
CVE-2026-27752

SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 transmit authentication credentials over unencrypted HTTP, allowing attackers to capture c…

Fix: after 200.1.20
Fix from $1,600 2026-02-27
Unclassified HIGH 7.5
CVE-2026-24455

The embedded web interface of the device does not support HTTPS/TLS for authentication and uses HTTP Basic Authentication. Traffic is encoded but n…

Mitigation only
Fix from $1,950 2026-02-20
Db2 Recovery Expert MEDIUM 5.9
CVE-2025-27903

IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 IBM Db2 Recovery Expert for Linux, UNIX and Windows transmits data in a cleartext communication c…

Mitigation only
Fix from $1,600 2026-02-17
Unclassified MEDIUM 5.7
CVE-2026-2539

The RF communication protocol in the Micca KE700 car alarm system does not encrypt its data frames. An attacker with a radio interception tool (e.g.,…

Mitigation only
Fix from $1,600 2026-02-15
Unclassified HIGH 8.3
CVE-2025-10174

Cleartext Transmission of Sensitive Information vulnerability in Pan Software & Information Technologies Ltd. PanCafe Pro allows Flooding. This issu…

Mitigation only
Fix from $1,950 2026-02-11
Fast\/tools MEDIUM 5.3
CVE-2025-66604

A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The library version could be displayed on the web page. Th…

Mitigation only
Fix from $1,600 2026-02-09
Uc 1222a Firmware MEDIUM 6.8
CVE-2026-0714

A physical attack vulnerability exists in certain Moxa industrial computers using TPM-backed LUKS full-disk encryption on Moxa Industrial Linux 3, wh…

Fix: after 1.4
Fix from $1,600 2026-02-05
Ac7 Firmware MEDIUM 5.9
CVE-2026-24441

Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior expose account credentials in plaintext within HTTP responses, allowing an on-path atta…

Fix: after 03.03.03.01
Fix from $1,600 2026-02-03
Unclassified HIGH 7.2
CVE-2026-1777

The Amazon SageMaker Python SDK before v3.2.0 and v2.256.0 includes the ModelBuilder HMAC signing key in the cleartext response elements of the Descr…

Mitigation only
Fix from $1,950 2026-02-02
Digital Employee Experience MEDIUM 6.5
CVE-2026-23564

A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an…

Fix: 26.1+
Fix from $1,600 2026-01-29
Elastic Cloud Storage MEDIUM 6.5
CVE-2026-22274

Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Transmission of Sensitive Informatio…

Fix: 4.2.0.0+
Fix from $1,600 2026-01-23
Elastic Cloud Storage HIGH 7.5
CVE-2026-22271

Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Transmission of Sensitive Informatio…

Fix: 4.2.0.0+
Fix from $1,950 2026-01-23
Open Webui MEDIUM 6.5
CVE-2026-0767

Open WebUI Cleartext Transmission of Credentials Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclo…

Mitigation only
Fix from $1,600 2026-01-23
Process Optimization HIGH 7.1
CVE-2025-64769

The Process Optimization application suite leverages connection channels/protocols that by-default are not encrypted and could become subject to hi…

Fix: 2025+
Fix from $1,950 2026-01-16
Thinkplus Fu100 Firmware MEDIUM 5.5
CVE-2025-13454

A potential vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to gain access to sensitive de…

Mitigation only
Fix from $1,600 2026-01-14
Dx Netops Spectrum HIGH 7.5
CVE-2025-69272

Cleartext Transmission of Sensitive Information vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Sniffing Attacks.This issue aff…

Fix: 21.2.2+
Fix from $1,950 2026-01-12
Unclassified HIGH 8.7
CVE-2026-22080

This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the transmission of credentials en…

Mitigation only
Fix from $1,950 2026-01-09
Unclassified HIGH 8.7
CVE-2026-22079

This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the plaintext transmission of logi…

Mitigation only
Fix from $1,950 2026-01-09
Facesentry Access Control System Firmware MEDIUM 5.9
CVE-2019-25278

FaceSentry Access Control System 6.4.8 contains a cleartext transmission vulnerability that allows remote attackers to intercept authentication crede…

No fix yet
Fix from $1,600 2026-01-08
Unclassified HIGH 8.7
CVE-2026-22544

An attacker with a network connection could detect credentials in clear text.

No fix yet
Fix from $1,950 2026-01-07
Unclassified HIGH 7.5
CVE-2020-36914

QiHang Media Web Digital Signage 3.0.9 contains a sensitive information disclosure vulnerability that allows remote attackers to intercept user authe…

No fix yet
Fix from $1,950 2026-01-06
Unclassified HIGH 7.5
CVE-2020-36917

iDS6 DSSPro Digital Signage System 6.2 contains a sensitive information disclosure vulnerability that allows remote attackers to intercept authentica…

No fix yet
Fix from $1,950 2026-01-06
Pa4 Firmware HIGH 7.5
CVE-2025-67159

Vatilon v1.12.37-20240124 was discovered to transmit user credentials in plaintext.

No fix yet
Fix from $1,950 2026-01-02
Dvp 12se Firmware HIGH 7.5
CVE-2025-62578

DVP-12SE - Modbus/TCP Cleartext Transmission of Sensitive Information

Mitigation only
Fix from $1,950 2025-12-26