Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.9
CVE-2026-4873
A vulnerability exists where a connection requiring TLS incorrectly reuses an
existing unencrypted connection from the same connection pool. If an in…
Curl
8.20.0+
HIGH 7.5
CVE-2026-45180
Catalyst::Plugin::Statsd versions through 0.10.0 for Perl may leak session ids.
If the communication channel to the statsd daemon is not secured (fo…
Mitigation only
MEDIUM 5.3
CVE-2026-45179
Plack::Middleware::Statsd versions before 0.9.0 for Perl may leak user IP addresses.
If the communication channel to the statsd daemon is not secure…
Mitigation only
MEDIUM 5.3
CVE-2026-32683
Some EZVIZ products utilize older versions of cloud feature modules with legacy API interfaces, which pose a data transmission risk. Attackers can ex…
Mitigation only
CRITICAL 9.1
CVE-2025-59852
HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability where data is transmitted over the network without encrypt…
Dfxanalytics
4.1+
HIGH 8.1
CVE-2026-7610
A vulnerability has been found in TRENDnet TEW-821DAP 1.12B01. This affects an unknown function of the file /www/cgi/ssi of the component Firmware Up…
Tew 821dap Firmware
No fix yet
HIGH 8.8
CVE-2026-42514
This vulnerability exists in e-Sushrut due to exposure of OTPs in plaintext within API responses. A remote attacker could exploit this vulnerability …
Mitigation only
MEDIUM 5.3
CVE-2026-40431
A vulnerability exists in SenseLive X3050’s web management interface due to its reliance on unencrypted HTTP for all administrative communication. Be…
X3500 Firmware
Mitigation only
HIGH 7.5
CVE-2026-41275
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the password reset functionality on cloud.fl…
Flowise
3.1.0+
MEDIUM 5.3
CVE-2025-31981
HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, allowing unencrypted access. A…
Bigfix Service Management
Mitigation only
MEDIUM 5.7
CVE-2026-40045
OpenClaw before 2026.4.2 accepts non-loopback cleartext ws:// gateway endpoints and transmits stored gateway credentials over unencrypted connections…
Openclaw
2026.4.2+
HIGH 7.1
CVE-2026-6066
ConnectWise has released a security update for ConnectWise Automate™ that addresses a behavior in the ConnectWise Automate Solution Center where cert…
Automate
2026.4+
MEDIUM 6.5
CVE-2026-33569
Anviz CX2 Lite and CX7 administrative sessions occur over HTTP, enabling
on‑path attackers to sniff credentials and session data, which can be
used…
Cx7 Firmware
Mitigation only
HIGH 7.5
CVE-2026-22155
A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, F…
Fortisoar
7.5.3 / 7.6.4+
MEDIUM 6.5
CVE-2026-21742
A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, F…
Fortisoar
7.5.3 / 7.6.4+
HIGH 7.5
CVE-2026-31923
Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX.
This can occur due to `ssl_verify` in openid-connect plugin configur…
Apisix
3.16.0+
MEDIUM 5.3
CVE-2026-31924
Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX.
tencent-cloud-cls log export uses plaintext HTTP
This issue affects …
Apisix
3.16.0+
HIGH 7.5
CVE-2026-5115
The PaperCut NG/MF (specifically, the embedded application for Konica Minolta devices) is vulnerable to session hijacking. The PaperCut NG/MF Embedde…
Papercut Mf
25.0.5 / 25.0.9+
HIGH 8.2
CVE-2026-5119
A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext …
Enterprise Linux
No fix yet
MEDIUM 6.5
CVE-2026-1014
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to exposure of sensitive information via JSON server response manipulation.
Infosphere Information Server
after 11.7.1.6
MEDIUM 5.9
CVE-2025-64648
IBM Concert 1.0.0 through 2.2.0 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle tec…
Concert
after 2.2.0
MEDIUM 6.1
CVE-2026-20115
A vulnerability in Cisco IOS XE Software for Cisco Meraki could allow a remote, unauthenticated attacker to view confidential device information.
…
Mitigation only
CRITICAL 9.1
CVE-2026-24060
Service information is not encrypted when transmitted as BACnet packets
over the wire, and can be sniffed, intercepted, and modified by an
attacker…
Mitigation only
HIGH 7.5
CVE-2026-32309
Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, the Hub-based unlock flow explicitly supports hub+http and c…
Cryptomator
1.19.1+
MEDIUM 5.9
CVE-2026-32838
Edimax GS-5008PL firmware version 1.00.54 and prior use cleartext HTTP for the web management interface without implementing TLS or SSL encryption. A…
Gs 5008pl Firmware
after 1.00.54
MEDIUM 5.7
CVE-2026-32745
In JetBrains Datalore before 2026.1 session hijacking was possible due to missing secure attribute for cookie settings
Datalore
2026.1+
HIGH 7.5
CVE-2025-13718
IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow a remote attacker to obtain sensitive informa…
Sterling Partner Engagement Manager
6.2.3.6 / 6.2.4.3+
HIGH 7.5
CVE-2026-23661
Cleartext transmission of sensitive information in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.
Azure Iot Explorer
0.15.13+
HIGH 7.5
CVE-2026-23662
Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.
Azure Iot Explorer
0.15.13+
HIGH 7.5
CVE-2025-70048
An issue pertaining to CWE-319: Cleartext Transmission of Sensitive Information was discovered in Nexusoft NexusInterface v3.2.0-beta.2.
Nexusinterface
Mitigation only