Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 10.0
CVE-2025-47419
Cleartext Transmission of Sensitive Information vulnerability in Crestron Automate VX allows Sniffing Network Traffic.
The device allows Web UI and …
Mitigation only
MEDIUM 6.5
CVE-2025-32884
An issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. By default, a GID is the user's phone number unless they specific…
Mesh Firmware
Mitigation only
MEDIUM 6.5
CVE-2025-32887
An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. A command channel includes the next hop. which can be intercepted a…
Mesh Firmware
Mitigation only
MEDIUM 6.5
CVE-2025-32881
An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. By default, the GID is the user's phone number unless they specific…
Mesh Firmware
Mitigation only
HIGH 8.7
CVE-2025-42603
This vulnerability exists in the Meon KYC solutions due to transmission of sensitive data in plain text within the response payloads of certain API e…
Mitigation only
HIGH 7.5
CVE-2025-43013
In JetBrains Toolbox App before 2.6 unencrypted credential transmission during SSH authentication was possible
Toolbox
2.6+
MEDIUM 5.9
CVE-2025-27722
Cleartext transmission of sensitive information issue exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, a man-in-the-middle attack may allo…
Mitigation only
MEDIUM 6.8
CVE-2025-26654
SAP Commerce Cloud (Public Cloud) does not allow to disable unencrypted HTTP (port 80) entirely, but instead allows a redirect from port 80 to 443 (H…
Mitigation only
HIGH 7.5
CVE-2025-2861
SaTECH BCU in its firmware version 2.1.3 uses the HTTP protocol. The use of the HTTP protocol for web browsing has the problem that information is ex…
Satech Bcu Firmware
Mitigation only
MEDIUM 6.5
CVE-2024-45361
A protocol flaw vulnerability exists in the Xiaomi Mi Connect Service APP. The vulnerability is caused by the validation logic is flawed and can be e…
Mitigation only
CRITICAL 9.0
CVE-2025-2311
Incorrect Use of Privileged APIs, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in Sechard Info…
Mitigation only
HIGH 7.5
CVE-2024-10718
In phpipam/phpipam version 1.5.1, the Secure attribute for sensitive cookies in HTTPS sessions is not set. This could cause the user agent to send th…
Phpipam
1.7.0+
HIGH 7.3
CVE-2024-44276
This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in iOS 18.2 and iPadOS 18.2. A user in a privi…
Ipados
18.2+
HIGH 7.5
CVE-2025-27594
The device uses an unencrypted, proprietary protocol for communication. Through this protocol, configuration data is transmitted and device authentic…
Mitigation only
HIGH 7.5
CVE-2024-13872
Bitdefender Box, versions 1.3.11.490 through 1.3.11.505, uses the insecure HTTP protocol to download assets over the Internet to update and restart d…
Box Firmware
after 1.3.11.505
MEDIUM 5.6
CVE-2025-22493
Secure flag not set and SameSIte was set to Lax in the Foreseer Reporting Software (FRS). Absence of this secure flag could lead into the session coo…
Mitigation only
HIGH 7.1
CVE-2025-24849
Lack of encryption in transit for cloud infrastructure facilitating potential for sensitive data manipulation or exposure.
No fix yet
MEDIUM 6.5
CVE-2025-25728
Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 were discovered to send communications to the update API i…
Mitigation only
MEDIUM 6.4
CVE-2022-41545
The administrative web interface of a Netgear C7800 Router running firmware version 6.01.07 (and possibly others) authenticates users via basic authe…
C7800 Firmware
Mitigation only
HIGH 7.5
CVE-2024-5462
If Brocade Fabric OS before Fabric OS 9.2.0 configuration settings are not set to encrypt SNMP passwords, then the SNMP privsecret / authsecret field…
Fabric Operating System
9.2.0+
HIGH 7.5
CVE-2025-1060
CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists that could result in the exposure
of data when network traffic is being…
Mitigation only
MEDIUM 6.5
CVE-2025-0556
In Progress® Telerik® Report Server, versions prior to 2025 Q1 (11.0.25.211) when using the older .NET Framework implementation, communication of non…
Telerik Report Server
11.0.25.211+
HIGH 7.5
CVE-2024-36558
Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h suffers from Cleartext Transmission of Sensitive Information due to …
Mitigation only
HIGH 7.5
CVE-2024-43187
IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 transmits sensitive or security-critical data in cleartext in a communicatio…
Security Verify Access
10.0.9.0+
HIGH 8.1
CVE-2025-23060
A vulnerability in HPE Aruba Networking ClearPass Policy Manager may, under certain circumstances, expose sensitive unencrypted information. Exploiti…
Clearpass Policy Manager
6.11.10 / 6.12.4+
MEDIUM 5.9
CVE-2023-35017
IBM Security Verify Governance 10.0.2 Identity Manager can transmit user credentials in clear text that could be obtained by an attacker using man in…
Security Verify Governance
Mitigation only
MEDIUM 5.9
CVE-2025-0784
A vulnerability has been found in Intelbras InControl up to 2.21.58 and classified as problematic. This vulnerability affects unknown code of the fil…
Incontrol Web
2.21.59+
HIGH 8.7
CVE-2025-0631
A Credential Exposure Vulnerability exists in the above-mentioned product and version. The vulnerability is due to using HTTP resulting in credential…
Mitigation only
MEDIUM 5.7
CVE-2025-0432
EWON Flexy 202 transmits user credentials in clear text with no encryption when a user is added, or user credentials are changed via its webpage.
Mitigation only
MEDIUM 6.5
CVE-2024-28786
IBM QRadar SIEM 7.5 transmits sensitive or security-critical data in cleartext in a communication channel that could be obtained by an unauthorized a…
Qradar Security Information And Event Manager
Mitigation only