Vulnerability index

Browse CVEs

798 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cleartext TransmissionCWE-319 × clear
HIGH 7.5 CVE-2026-30795 Cleartext Transmission of Sensitive Information vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Andro… Rustdesk after 1.4.5 Fix from $1,9502026-03-05 CRITICAL 9.6 CVE-2025-69969 A lack of authentication and authorization mechanisms in the Bluetooth Low Energy (BLE) communication protocol of SRK Powertech Pvt Ltd Pebble Prism … Pebble Prism Ultra Firmware 2.5.8+ Fix from $2,3002026-03-04 MEDIUM 5.9 CVE-2025-13490 IBM App Connect Operator versions CD 11.3.0 through 11.6.0 and 12.1.0 through 12.20.0, LTS versions 12.0.0 through 12.0.20, and IBM App Connect Enter… App Connect Enterprise Certified Containers Operands after 12.20.1 Fix from $1,6002026-03-03 MEDIUM 5.6 CVE-2026-20801 Cleartext Transmission of Sensitive Information (CWE-319) in a component used in the Gallagher Hanwha VMS and Gallagher NxWitness VMS integrations al… Hanwha Vms Integration Mitigation only Fix from $1,6002026-03-03 MEDIUM 6.5 CVE-2024-43766 In multiple functions of btm_ble_sec.cc, there is a possible unencrypted communication due to Invalid error handling. This could lead to remote (prox… Android Mitigation only Fix from $1,6002026-03-02 HIGH 7.5 CVE-2025-58107 In Microsoft Exchange through 2019, Exchange ActiveSync (EAS) configurations on on-premises servers may transmit sensitive data from Samsung mobile d… Mitigation only Fix from $1,9502026-03-02 MEDIUM 5.9 CVE-2026-27752 SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 transmit authentication credentials over unencrypted HTTP, allowing attackers to capture c… Sl902 Swtgw124as Firmware after 200.1.20 Fix from $1,6002026-02-27 HIGH 7.5 CVE-2026-24455 The embedded web interface of the device does not support HTTPS/TLS for authentication and uses HTTP Basic Authentication. Traffic is encoded but n… Mitigation only Fix from $1,9502026-02-20 MEDIUM 5.9 CVE-2025-27903 IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 IBM Db2 Recovery Expert for Linux, UNIX and Windows transmits data in a cleartext communication c… Db2 Recovery Expert Mitigation only Fix from $1,6002026-02-17 MEDIUM 5.7 CVE-2026-2539 The RF communication protocol in the Micca KE700 car alarm system does not encrypt its data frames. An attacker with a radio interception tool (e.g.,… Mitigation only Fix from $1,6002026-02-15 HIGH 8.3 CVE-2025-10174 Cleartext Transmission of Sensitive Information vulnerability in Pan Software & Information Technologies Ltd. PanCafe Pro allows Flooding. This issu… Mitigation only Fix from $1,9502026-02-11 MEDIUM 5.3 CVE-2025-66604 A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The library version could be displayed on the web page. Th… Fast\/tools Mitigation only Fix from $1,6002026-02-09 MEDIUM 6.8 CVE-2026-0714 A physical attack vulnerability exists in certain Moxa industrial computers using TPM-backed LUKS full-disk encryption on Moxa Industrial Linux 3, wh… Uc 1222a Firmware after 1.4 Fix from $1,6002026-02-05 MEDIUM 5.9 CVE-2026-24441 Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior expose account credentials in plaintext within HTTP responses, allowing an on-path atta… Ac7 Firmware after 03.03.03.01 Fix from $1,6002026-02-03 HIGH 7.2 CVE-2026-1777 The Amazon SageMaker Python SDK before v3.2.0 and v2.256.0 includes the ModelBuilder HMAC signing key in the cleartext response elements of the Descr… Mitigation only Fix from $1,9502026-02-02 MEDIUM 6.5 CVE-2026-23564 A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an… Digital Employee Experience 26.1+ Fix from $1,6002026-01-29 MEDIUM 6.5 CVE-2026-22274 Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Transmission of Sensitive Informatio… Elastic Cloud Storage 4.2.0.0+ Fix from $1,6002026-01-23 HIGH 7.5 CVE-2026-22271 Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Transmission of Sensitive Informatio… Elastic Cloud Storage 4.2.0.0+ Fix from $1,9502026-01-23 MEDIUM 6.5 CVE-2026-0767 Open WebUI Cleartext Transmission of Credentials Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclo… Open Webui Mitigation only Fix from $1,6002026-01-23 HIGH 7.1 CVE-2025-64769 The Process Optimization application suite leverages connection channels/protocols that by-default are not encrypted and could become subject to hi… Process Optimization 2025+ Fix from $1,9502026-01-16 MEDIUM 5.5 CVE-2025-13454 A potential vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to gain access to sensitive de… Thinkplus Fu100 Firmware Mitigation only Fix from $1,6002026-01-14 HIGH 7.5 CVE-2025-69272 Cleartext Transmission of Sensitive Information vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Sniffing Attacks.This issue aff… Dx Netops Spectrum 21.2.2+ Fix from $1,9502026-01-12 HIGH 8.7 CVE-2026-22080 This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the transmission of credentials en… Mitigation only Fix from $1,9502026-01-09 HIGH 8.7 CVE-2026-22079 This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the plaintext transmission of logi… Mitigation only Fix from $1,9502026-01-09 MEDIUM 5.9 CVE-2019-25278 FaceSentry Access Control System 6.4.8 contains a cleartext transmission vulnerability that allows remote attackers to intercept authentication crede… Facesentry Access Control System Firmware No fix yet Fix from $1,6002026-01-08 HIGH 8.7 CVE-2026-22544 An attacker with a network connection could detect credentials in clear text. No fix yet Fix from $1,9502026-01-07 HIGH 7.5 CVE-2020-36914 QiHang Media Web Digital Signage 3.0.9 contains a sensitive information disclosure vulnerability that allows remote attackers to intercept user authe… No fix yet Fix from $1,9502026-01-06 HIGH 7.5 CVE-2020-36917 iDS6 DSSPro Digital Signage System 6.2 contains a sensitive information disclosure vulnerability that allows remote attackers to intercept authentica… No fix yet Fix from $1,9502026-01-06 HIGH 7.5 CVE-2025-67159 Vatilon v1.12.37-20240124 was discovered to transmit user credentials in plaintext. Pa4 Firmware No fix yet Fix from $1,9502026-01-02 HIGH 7.5 CVE-2025-62578 DVP-12SE - Modbus/TCP Cleartext Transmission of Sensitive Information Dvp 12se Firmware Mitigation only Fix from $1,9502025-12-26