CWE-319

High likelihood

Cleartext Transmission of Sensitive Information

Parent: CWE-311 - Missing Encryption of Sensitive Data

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

898 vulnerabilities with CWE-319
CVE-2023-0053 HIGH
SAUTER Controls Nova 200-220 - Info Disclosure
CVSS 7.5
CVE-2023-23915 MEDIUM
curl 7.77.0-7.87.0 - Cleartext Transmission of Sensitive Information via HSTS Cache Overwrite
CVSS 6.5
CVE-2023-23914 CRITICAL
curl < 7.88.0 - Cleartext Transmission of Sensitive Information via HSTS State Mismanagement
CVSS 9.1
CVE-2023-22806 HIGH
LS ELECTRIC XBC-DN32U 01.80 - Cleartext Transmission of Sensitive Information via XGT Protocol
CVSS 7.5
CVE-2023-0001 MEDIUM
Palo Alto Networks Cortex XDR < - Info Disclosure
CVSS 6.0
CVE-2023-25016 HIGH
Couchbase Server < 6.6.6, 7.x < 7.0.5, 7.1.x < 7.1.2 - Cleartext Transmission of Sensitive Information
CVSS 7.5
CVE-2023-23130 MEDIUM
Connectwise Automate 2022.11 - Cleartext Transmission of Sensitive Information
CVSS 5.9
CVE-2023-24440 MEDIUM
Jenkins JIRA Pipeline Steps Plugin <2.0.165.v8846cf59f3db - Info Di...
CVSS 5.5
CVE-2023-22863 MEDIUM
IBM Robotic Process Automation 20.12.0-21.0.2 - Cleartext Transmission of Sensitive Information via Default HTTP
CVSS 5.9
CVE-2023-22597 MEDIUM
InRouter 302 < 3.5.56 & InRouter 615 < 2.3.0.r5542 - Cleartext Sensitive Data via Cloud
CVSS 6.5
CVE-2023-0055 MEDIUM
pyload <0.5.0b3.dev32 - Info Disclosure
CVSS 5.3
CVE-2022-41545 MEDIUM
Netgear C7800 Router <6.01.07 - Info Disclosure
CVSS 6.4
CVE-2022-32510 HIGH
Nuki Home Solutions - Unencrypted Channel
CVSS 7.1
CVE-2022-22385 MEDIUM
IBM Security Verify Privilege On-Premises <11.5 - Info Disclosure
CVSS 5.9
CVE-2022-47892 MEDIUM
NetMan 204 Firmware - Unauthenticated Sensitive Information Exposure via config.cgi
CVSS 5.3
CVE-2022-47560 MEDIUM
Ormazabal ekorRCI and ekorCCP Firmware - Cleartext Transmission of Sensitive Information
CVSS 5.7
CVE-2022-3261 MEDIUM
Red Hat OpenStack Platform - Cleartext Transmission of Sensitive Information in /var/log/messages
CVSS 4.4
CVE-2022-41327 HIGH
Fortinet FortiOS <7.2.4, FortiProxy <7.2.1 - Info Disclosure
CVSS 7.8
CVE-2022-46680 HIGH
PowerLogic ION9000, ION7400, PM8000, ION8650, ION8800 Firmware < 4.0.0 - Cleartext Transmission of Sensitive Information
CVSS 8.8
CVE-2022-38458 MEDIUM
Netgear Orbi Router RBR750 4.6.8.5 - Info Disclosure
CVSS 6.5
CVE-2022-32906 MEDIUM
Apple Music < 3.9.10 - Cleartext Transmission of Sensitive Information
CVSS 5.3
CVE-2022-45546 HIGH
ScreenCheck BadgeMaker 2.6.2.0 - Cleartext Transmission of Sensitive Information in Authentication Component
CVSS 7.5
CVE-2022-40693 HIGH
Moxa SDS-3008 Series < 2.1 - Cleartext Transmission of Sensitive Information via Web Application
CVSS 7.5
CVE-2022-47714 CRITICAL
Last Yard 22.09.8-1 - Cleartext Transmission of Sensitive Information
CVSS 9.8
CVE-2022-0553 MEDIUM
Zephyr < 3.0.0 - Cleartext Transmission of Sensitive Information via Unencrypted Firmware Upload
CVSS 6.5
Details
Vulnerabilities 898
Exploit Likelihood High