Vulnerability index

Browse CVEs

798 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cleartext TransmissionCWE-319 × clear
MEDIUM 6.0 CVE-2026-15806 The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, d… Fix unknown Fix from $4,0002026-08-18 MEDIUM 6.5 CVE-2026-20294 A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitiv… No fix yet Fix from $1,6002026-08-05 HIGH 7.5 CVE-2026-18536 Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP. The Data::Entropy::RawSource::RandomOrg and Data::Entropy:… Data\ 0.010+ Fix from $1,9502026-08-01 MEDIUM 6.5 CVE-2026-64742 This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 an… Ipados 26.6+ Fix from $1,6002026-07-27 HIGH 8.2 CVE-2026-47255 AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0… No fix yet Fix from $1,9502026-07-20 MEDIUM 6.5 CVE-2026-48022 @hapi/wreck is an HTTP client utility. Prior to 18.1.2, Wreck strips credential headers including Authorization, Cookie, and Proxy-Authorization befo… No fix yet Fix from $1,6002026-07-17 MEDIUM 5.5 CVE-2026-34346 Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose informatio… Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,6002026-07-14 MEDIUM 5.9 CVE-2025-36336 IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 transmits data in clear text that could allow an attacker to obtain sensitive information us… Watsonx.data Intelligence Mitigation only Fix from $1,6002026-06-30 MEDIUM 5.9 CVE-2025-12530 IBM watsonx.data intelligence 5.2.2, 5.3.0, 5.3.1, 5.3.1 through Patch 1 transmits data in clear text that could allow an attacker to obtain sensitiv… Watsonx.data Intelligence Mitigation only Fix from $1,6002026-06-30 HIGH 7.5 CVE-2026-55844 Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2025.5.0, The iOS companion app ignores th… Mitigation only Fix from $1,9502026-06-29 HIGH 7.5 CVE-2026-49486 The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p()`, so although the control c… Apache Airflow Providers Ftp 3.15.1+ Fix from $1,9502026-06-26 CRITICAL 9.1 CVE-2026-44726 Deno is a JavaScript, TypeScript, and WebAssembly runtime. From 2.0.0 until 2.7.8, a flaw in Deno's Node.js tls compatibility layer could cause a TLS… Deno 2.7.8+ Fix from $2,3002026-06-23 MEDIUM 5.9 CVE-2026-55568 Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, in certain configurations, traffic expected to be protected by TLS on the hop to the proxy … Guzzle 7.12.1+ Fix from $1,6002026-06-23 HIGH 8.2 CVE-2026-11833 Overview: A vulnerability has been found in FAST/TOOLS and CI Server. The web server may return a response containing the CI Server setting informat… Mitigation only Fix from $1,9502026-06-23 MEDIUM 6.5 CVE-2026-50034 An attacker within BLE communication range can passively intercept wireless traffic and obtain sensitive health-related information, including gluc… Mitigation only Fix from $1,6002026-06-19 HIGH 7.5 CVE-2026-50200 Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Management.E… Patch available Fix from $1,9502026-06-17 MEDIUM 6.5 CVE-2026-9741 A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (QE) or Client-Side Field Level Encryption (CSFLE)… MongoDB 7.0.35 / 8.0.24+ Fix from $1,6002026-06-09 HIGH 8.7 CVE-2026-45432 This vulnerability exists in GX Earth ONT models due to the transmission of user credentials in plaintext over HTTP in its web management interface. … Mitigation only Fix from $1,9502026-06-04 HIGH 7.1 CVE-2026-8874 Version 3.0.7 of the Securly Chrome Extension downloads JSON files containing crisis alert keywords and filtering rules over unencrypted HTTP via the… Securly Mitigation only Fix from $1,9502026-06-03 MEDIUM 5.9 CVE-2026-36610 Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 transmits DDNS credentials over plaintext HTTP with only Base64 encoding. The firmware conta… Mitigation only Fix from $1,6002026-06-03 MEDIUM 5.9 CVE-2023-52951 A cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703 allows man-in-the-middle attackers t… Note Station Client 2.2.4-703+ Fix from $1,6002026-06-03 MEDIUM 5.9 CVE-2026-10584 Proxy server in Graph Explorer before 3.0.1 falls back to HTTP when certificate files are missing, which might allow remote threat actors to obtain s… Mitigation only Fix from $1,6002026-06-02 MEDIUM 5.9 CVE-2026-43625 CodexBar prior to 0.32.0 contains a session cookie leakage vulnerability that allows network attackers to intercept imported browser session cookies … Patch available Fix from $1,6002026-06-01 MEDIUM 6.3 CVE-2026-25599 Missing authentication and clear‑text transmission of data from the heat pumps to the control server, combined with the absence of input validation o… Mitigation only Fix from $1,6002026-06-01 HIGH 7.5 CVE-2026-34126 TP-Link has identified a vulnerability in Tapo L535E v1.0 and v3.0, Tapo P300 v1.0, and Tapo D100C v1.0, where Bluetooth communication during the ini… Tapo L535e Firmware Mitigation only Fix from $1,9502026-05-28 CRITICAL 9.8 CVE-2026-48902 The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set. Joomla\! 5.4.6 / 6.1.1+ Fix from $2,3002026-05-26 CRITICAL 9.8 CVE-2026-24212 NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is transmitted in clear text. A successful exploit of this vul… Isaac Launchable after 1.2 Fix from $2,3002026-05-26 MEDIUM 5.3 CVE-2026-38740 Foscam VD1 Video Doorbell before V5.3.13_1072 is vulnerable to Cleartext Transmission of Sensitive Information. The device transmits sensitive Sessio… Mitigation only Fix from $1,6002026-05-14 MEDIUM 5.4 CVE-2025-62310 HCL AION is affected by a vulnerability where encryption is not enforced for certain data transmissions or operations. This may expose sensitive info… No fix yet Fix from $1,6002026-05-14 HIGH 7.5 CVE-2026-6276 Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* b… Curl 8.20.0+ Fix from $1,9502026-05-13