CWE-319

High likelihood

Cleartext Transmission of Sensitive Information

Parent: CWE-311 - Missing Encryption of Sensitive Data

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

898 vulnerabilities with CWE-319
CVE-2024-35495 MEDIUM
TP-Link Kasa KP125M/Tapo P125M <1.0.0 - Info Disclosure
CVSS 4.3
CVE-2024-7713 HIGH
AI ChatBot with ChatGPT and Content Generator by AYS < 2.1.0 - Unauthenticated OpenAI API Key Exposure
CVSS 7.5
CVE-2024-47124 MEDIUM
goTenna Pro < 1.6.1 and < 2.0.3 - Cleartext Transmission of Sensitive Information
CVSS 4.3
CVE-2024-45838 MEDIUM
goTenna Pro ATAK Plugin < 2.0.7 - Cleartext Transmission of Sensitive Information
CVSS 4.3
CVE-2024-8059 MEDIUM
Lenovo ThinkAgile and ThinkSystem XCC - Cleartext Transmission of Sensitive Information in Audit Logs
CVSS 4.3
CVE-2024-45101 MEDIUM
Lenovo XClarity Administrator < 4.1 - Session Hijacking via SSO URL Manipulation
CVSS 6.8
CVE-2024-43180 MEDIUM
IBM Concert 1.0 - Cleartext Transmission of Sensitive Information
CVSS 4.3
CVE-2024-44105 HIGH
Ivanti Workspace Control < 10.18.99.0 - Authenticated Cleartext Transmission of Sensitive Information
CVSS 8.2
CVE-2024-41927 MEDIUM
IDEC KIT-FC6A PLC Firmware < 2.60 - Cleartext Transmission of Sensitive Information via Serial Communication Port
CVSS 4.6
CVE-2024-39746 MEDIUM
IBM Sterling Connect:Direct Web Services 6.0-6.3 - Cleartext Transmission of Sensitive Information
CVSS 5.9
CVE-2024-31905 MEDIUM
IBM QRadar Network Packet Capture <7.5 - Info Disclosure
CVSS 5.9
CVE-2024-31799 MEDIUM
GNCC's GC2 Indoor Security Camera 1080P - Info Disclosure
CVSS 4.6
CVE-2024-38167 MEDIUM
.NET 8.0.0-8.0.7 and Visual Studio 2022 17.6.0-17.6.17 - Cleartext Transmission of Sensitive Information
CVSS 6.5
CVE-2024-7408 MEDIUM
Airveda PM2.5 PM10 Monitor Firmware < 7.4.4.39 - Cleartext Transmission of Sensitive Information during AP Pairing
CVSS 6.5
CVE-2024-38891 HIGH
Caterease 16.0.1.1663-24.0.1.2405 - Cleartext Transmission of Sensitive Information
CVSS 7.5
CVE-2024-32864 MEDIUM
exacqVision Web Service < 24.03 - Cleartext Transmission of Sensitive Information
CVSS 6.4
CVE-2024-41262 HIGH
immudb 1.9.3 - Cleartext Transmission of Sensitive Information via ShowMetricsRaw and ShowMetricsAsText Functions
CVSS 7.4
CVE-2024-41687 HIGH
SyroTech SY-GPON-1110-WDONT Firmware - Cleartext Transmission of Sensitive Information via HTTP Session
CVSS 7.5
CVE-2024-6972 MEDIUM
Octopus Server 2024.1.437-2024.1.12759 - Cleartext Transmission of Sensitive Information in Task Log
CVSS 6.5
CVE-2024-41124 MEDIUM
Puncia < 0.21 - Missing Encryption of Sensitive Data via HTTP API_URLs
CVSS 6.3
CVE-2024-5631 MEDIUM
Longse NVR3608PGE2W and Zamel ZMB-01 - Cleartext Transmission of Sensitive Information
CVE-2024-6388 MEDIUM
Ubuntu Advantage Desktop Daemon <1.12 - Info Disclosure
CVSS 5.9
CVE-2024-37183 MEDIUM
Westermo L210-F2G Firmware - Cleartext Transmission of Sensitive Information
CVSS 5.7
CVE-2024-0066 MEDIUM
AXIS OS - Cleartext Transmission of Sensitive Information via O3C Feature
CVSS 5.3
CVE-2024-27166 HIGH
Toshiba Tec e-Studio multi-function peripheral (MFP) - Plaintext Password Exposure via Coredump Permissions
CVSS 7.4
Details
Vulnerabilities 898
Exploit Likelihood High