Vulnerability index

Browse CVEs

798 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cleartext TransmissionCWE-319 × clear
Unclassified HIGH 7.4
CVE-2025-41708

Due to an unsecure default configuration HTTP is used instead of HTTPS for the web interface. An unauthenticated attacker on the same network could e…

Mitigation only
Fix from $1,950 2025-09-08
Unclassified HIGH 7.5
CVE-2025-7731

Cleartext Transmission of Sensitive Information vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU module allows a remote unauth…

Mitigation only
Fix from $1,950 2025-09-01
Bigfix Service Management MEDIUM 6.5
CVE-2025-31972

HCL BigFix SM is affected by a Sensitive Information Exposure vulnerability where internal connections do not use TLS encryption which could allow an…

Mitigation only
Fix from $1,600 2025-08-28
Unclassified HIGH 8.8
CVE-2025-52351

Aikaan IoT management platform v3.25.0325-5-g2e9c59796 sends a newly generated password to users in plaintext via email and also includes the same pa…

Mitigation only
Fix from $1,950 2025-08-21
Unclassified HIGH 8.5
CVE-2025-6180

The StrongDM Client insufficiently protected a pre-authentication token. Attackers could exploit this to intercept and reuse the token, potentially r…

Mitigation only
Fix from $1,950 2025-08-20
Intellij Idea HIGH 7.5
CVE-2025-57727

In JetBrains IntelliJ IDEA before 2025.2 credentials disclosure was possible via remote reference

Fix: 2025.2+
Fix from $1,950 2025-08-20
Sante Pacs Server HIGH 7.5
CVE-2025-54156

The Sante PACS Server Web Portal sends credential information without encryption.

Fix: 4.2.3+
Fix from $1,950 2025-08-18
Unclassified HIGH 7.0
CVE-2025-8863

YugabyteDB diagnostic information was transmitted over HTTP, which could expose sensitive data during transmission

Mitigation only
Fix from $1,950 2025-08-11
Mall MEDIUM 5.9
CVE-2025-8741

A vulnerability was found in macrozheng mall up to 1.0.3. It has been declared as problematic. Affected by this vulnerability is an unknown functiona…

Fix: after 1.0.3
Fix from $1,600 2025-08-08
Unclassified MEDIUM 6.9
CVE-2025-52586

The MOD3 command traffic between the monitoring application and the inverter is transmitted in plaintext without encryption or obfuscation. This vu…

Mitigation only
Fix from $1,600 2025-08-08
Guardium Data Protection HIGH 7.5
CVE-2025-36020

IBM Guardium Data Protection could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive credential info…

Mitigation only
Fix from $1,950 2025-08-06
Sync Gateway HIGH 7.3
CVE-2025-52490

An issue was discovered in Couchbase Sync Gateway before 3.2.6. In sgcollect_info_options.log and sync_gateway.log, there are cleartext passwords in …

Fix: 3.2.6+
Fix from $1,950 2025-07-29
Unclassified HIGH 7.5
CVE-2025-53703

DuraComm SPM-500 DP-10iN-100-MU transmits sensitive data without encryption over a channel that could be intercepted by attackers.

Mitigation only
Fix from $1,950 2025-07-22
Cognos Analytics Mobile HIGH 7.5
CVE-2025-36107

IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could allow malicious actors to obtain sensitive information due to the cleartext transmission…

Fix: 1.1.23+
Fix from $1,950 2025-07-21
Unclassified HIGH 8.7
CVE-2025-53756

This vulnerability exists in Digisol DG-GR6821AC Router due to cleartext transmission of credentials in its web management interface. A remote attack…

Mitigation only
Fix from $1,950 2025-07-16
Unclassified HIGH 7.5
CVE-2025-44251

Ecovacs Deebot T10 1.7.2 transmits Wi-Fi credentials in cleartext during the pairing process.

Mitigation only
Fix from $1,950 2025-07-10
Meac300 Fnade4 Firmware HIGH 7.5
CVE-2025-27457

All communication between the VNC server and client(s) is unencrypted. This allows an attacker to intercept the traffic and obtain sensitive data.

Mitigation only
Fix from $1,950 2025-07-03
Infosphere Information Server MEDIUM 5.9
CVE-2025-36034

IBM InfoSphere DataStage Flow Designer in IBM InfoSphere Information Server 11.7 discloses sensitive user information in API requests in clear text t…

Mitigation only
Fix from $1,600 2025-06-26
Unclassified MEDIUM 6.0
CVE-2025-5087

Kaleris NAVIS N4 ULC (Ultra Light Client) communicates insecurely using zlib-compressed data over HTTP. An attacker capable of observing network traf…

Mitigation only
Fix from $1,600 2025-06-24
Unclassified CRITICAL 10.0
CVE-2025-4378

Cleartext Transmission of Sensitive Information, Use of Hard-coded Credentials vulnerability in Ataturk University ATA-AOF Mobile Application allows …

Mitigation only
Fix from $2,300 2025-06-24
Coros Pace 3 Firmware CRITICAL 9.8
CVE-2025-32880

An issue was discovered on COROS PACE 3 devices through 3.0808.0. It implements a function to connect the watch to a WLAN. With WLAN access, the CORO…

Fix: after 3.0808.0
Fix from $2,300 2025-06-20
Cloudclassroom Php Project CRITICAL 9.8
CVE-2025-26199

CloudClassroom-PHP-Project v1.0 is affected by an insecure credential transmission vulnerability. The application transmits passwords over unencrypte…

Mitigation only
Fix from $2,300 2025-06-18
Media Server HIGH 7.5
CVE-2025-49194

The server supports authentication methods in which credentials are sent in plaintext over unencrypted channels. If an attacker were to intercept tra…

Mitigation only
Fix from $1,950 2025-06-12
Media Server HIGH 7.5
CVE-2025-49183

All communication with the REST API is unencrypted (HTTP), allowing an attacker to intercept traffic between an actor and the webserver. This leads t…

Mitigation only
Fix from $1,950 2025-06-12
Wifi Lock Controller V1 Rf Firmware MEDIUM 5.9
CVE-2025-44612

Tinxy WiFi Lock Controller v1 RF was discovered to transmit sensitive information in plaintext, including control information and device credentials,…

Mitigation only
Fix from $1,600 2025-05-30
Firefox HIGH 7.5
CVE-2025-5270

In certain cases, SNI could have been sent unencrypted even when encrypted DNS was enabled. This vulnerability was fixed in Firefox 139 and Thunderbi…

Fix: 139.0+
Fix from $1,950 2025-05-27
Pacs Server MEDIUM 6.5
CVE-2025-3480

MedDream WEB DICOM Viewer Cleartext Transmission of Credentials Information Disclosure Vulnerability. This vulnerability allows network-adjacent atta…

Mitigation only
Fix from $1,600 2025-05-22
Unclassified MEDIUM 5.3
CVE-2025-0136

Using the AES-128-CCM algorithm for IPSec on certain Palo Alto Networks PAN-OS® firewalls (PA-7500, PA-5400, PA-5400f, PA-3400, PA-1600, PA-1400, and…

Mitigation only
Fix from $1,600 2025-05-14
Unclassified HIGH 7.4
CVE-2025-27720

The Pixmeo Osirix MD Web Portal sends credential information without encryption, which could allow an attacker to steal credentials.

Mitigation only
Fix from $1,950 2025-05-08
Unclassified CRITICAL 9.1
CVE-2024-12378

On affected platforms running Arista EOS with secure Vxlan configured, restarting the Tunnelsec agent will result in packets being sent over the secu…

Mitigation only
Fix from $2,300 2025-05-08