Vulnerability index

Browse CVEs

798 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cleartext TransmissionCWE-319 × clear
MEDIUM 5.9 CVE-2026-4873 A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool. If an in… Curl 8.20.0+ Fix from $1,6002026-05-13 HIGH 7.5 CVE-2026-45180 Catalyst::Plugin::Statsd versions through 0.10.0 for Perl may leak session ids. If the communication channel to the statsd daemon is not secured (fo… Mitigation only Fix from $1,9502026-05-10 MEDIUM 5.3 CVE-2026-45179 Plack::Middleware::Statsd versions before 0.9.0 for Perl may leak user IP addresses. If the communication channel to the statsd daemon is not secure… Mitigation only Fix from $1,6002026-05-10 MEDIUM 5.3 CVE-2026-32683 Some EZVIZ products utilize older versions of cloud feature modules with legacy API interfaces, which pose a data transmission risk. Attackers can ex… Mitigation only Fix from $1,6002026-05-09 CRITICAL 9.1 CVE-2025-59852 HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability where data is transmitted over the network without encrypt… Dfxanalytics 4.1+ Fix from $2,3002026-05-06 HIGH 8.1 CVE-2026-7610 A vulnerability has been found in TRENDnet TEW-821DAP 1.12B01. This affects an unknown function of the file /www/cgi/ssi of the component Firmware Up… Tew 821dap Firmware No fix yet Fix from $1,9502026-05-02 HIGH 8.8 CVE-2026-42514 This vulnerability exists in e-Sushrut due to exposure of OTPs in plaintext within API responses. A remote attacker could exploit this vulnerability … Mitigation only Fix from $1,9502026-04-29 MEDIUM 5.3 CVE-2026-40431 A vulnerability exists in SenseLive X3050’s web management interface due to its reliance on unencrypted HTTP for all administrative communication. Be… X3500 Firmware Mitigation only Fix from $1,6002026-04-24 HIGH 7.5 CVE-2026-41275 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the password reset functionality on cloud.fl… Flowise 3.1.0+ Fix from $1,9502026-04-23 MEDIUM 5.3 CVE-2025-31981 HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, allowing unencrypted access.  A… Bigfix Service Management Mitigation only Fix from $1,6002026-04-21 MEDIUM 5.7 CVE-2026-40045 OpenClaw before 2026.4.2 accepts non-loopback cleartext ws:// gateway endpoints and transmits stored gateway credentials over unencrypted connections… Openclaw 2026.4.2+ Fix from $1,6002026-04-21 HIGH 7.1 CVE-2026-6066 ConnectWise has released a security update for ConnectWise Automate™ that addresses a behavior in the ConnectWise Automate Solution Center where cert… Automate 2026.4+ Fix from $1,9502026-04-20 MEDIUM 6.5 CVE-2026-33569 Anviz CX2 Lite and CX7 administrative sessions occur over HTTP, enabling on‑path attackers to sniff credentials and session data, which can be used… Cx7 Firmware Mitigation only Fix from $1,6002026-04-17 HIGH 7.5 CVE-2026-22155 A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, F… Fortisoar 7.5.3 / 7.6.4+ Fix from $1,9502026-04-14 MEDIUM 6.5 CVE-2026-21742 A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, F… Fortisoar 7.5.3 / 7.6.4+ Fix from $1,6002026-04-14 HIGH 7.5 CVE-2026-31923 Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. This can occur due to `ssl_verify` in openid-connect plugin configur… Apisix 3.16.0+ Fix from $1,9502026-04-14 MEDIUM 5.3 CVE-2026-31924 Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. tencent-cloud-cls log export uses plaintext HTTP This issue affects … Apisix 3.16.0+ Fix from $1,6002026-04-14 HIGH 7.5 CVE-2026-5115 The PaperCut NG/MF (specifically, the embedded application for Konica Minolta devices) is vulnerable to session hijacking. The PaperCut NG/MF Embedde… Papercut Mf 25.0.5 / 25.0.9+ Fix from $1,9502026-03-31 HIGH 8.2 CVE-2026-5119 A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext … Enterprise Linux No fix yet Fix from $1,9502026-03-30 MEDIUM 6.5 CVE-2026-1014 IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to exposure of sensitive information via JSON server response manipulation. Infosphere Information Server after 11.7.1.6 Fix from $1,6002026-03-25 MEDIUM 5.9 CVE-2025-64648 IBM Concert 1.0.0 through 2.2.0 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle tec… Concert after 2.2.0 Fix from $1,6002026-03-25 MEDIUM 6.1 CVE-2026-20115 A vulnerability in Cisco IOS XE Software for Cisco Meraki could allow a remote, unauthenticated attacker to view confidential device information. … Mitigation only Fix from $1,6002026-03-25 CRITICAL 9.1 CVE-2026-24060 Service information is not encrypted when transmitted as BACnet packets over the wire, and can be sniffed, intercepted, and modified by an attacker… Mitigation only Fix from $2,3002026-03-21 HIGH 7.5 CVE-2026-32309 Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, the Hub-based unlock flow explicitly supports hub+http and c… Cryptomator 1.19.1+ Fix from $1,9502026-03-20 MEDIUM 5.9 CVE-2026-32838 Edimax GS-5008PL firmware version 1.00.54 and prior use cleartext HTTP for the web management interface without implementing TLS or SSL encryption. A… Gs 5008pl Firmware after 1.00.54 Fix from $1,6002026-03-17 MEDIUM 5.7 CVE-2026-32745 In JetBrains Datalore before 2026.1 session hijacking was possible due to missing secure attribute for cookie settings Datalore 2026.1+ Fix from $1,6002026-03-13 HIGH 7.5 CVE-2025-13718 IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow a remote attacker to obtain sensitive informa… Sterling Partner Engagement Manager 6.2.3.6 / 6.2.4.3+ Fix from $1,9502026-03-13 HIGH 7.5 CVE-2026-23661 Cleartext transmission of sensitive information in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. Azure Iot Explorer 0.15.13+ Fix from $1,9502026-03-10 HIGH 7.5 CVE-2026-23662 Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. Azure Iot Explorer 0.15.13+ Fix from $1,9502026-03-10 HIGH 7.5 CVE-2025-70048 An issue pertaining to CWE-319: Cleartext Transmission of Sensitive Information was discovered in Nexusoft NexusInterface v3.2.0-beta.2. Nexusinterface Mitigation only Fix from $1,9502026-03-09