CWE-319

High likelihood

Cleartext Transmission of Sensitive Information

Parent: CWE-311 - Missing Encryption of Sensitive Data

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

882 vulnerabilities with CWE-319
CVE-2021-36165 MEDIUM
RICON Industrial Cellular Router S9922L <16.10.3 - Info Disclosure
CVSS 5.3
CVE-2021-40847 HIGH
NETGEAR Routers - Root Code Execution via Cleartext Circle Update Man-in-the-Middle
CVSS 8.1
CVE-2021-38142 HIGH
Barco MirrorOp Windows Sender <2.5.3.65 - RCE
CVSS 8.8
CVE-2021-39272 MEDIUM
fetchmail < 6.4.22 - Cleartext Transmission of Sensitive Information via STARTTLS Enforcement Bypass
CVSS 5.9
CVE-2021-33883 MEDIUM
B. Braun SpaceCom2 < 012U000062 - Cleartext Transmission of Sensitive Information
CVSS 5.9
CVE-2021-38373 MEDIUM
KDE KMail <19.12.3 - Info Disclosure
CVSS 5.3
CVE-2021-22923 MEDIUM
curl - Metalink Feature - Auth Bypass
CVSS 5.3
CVE-2021-29769 MEDIUM
IBM i2 Analyze 4.3.0-4.3.2 - Cleartext Transmission of Sensitive Information in Session Cookies
CVSS 4.3
CVE-2021-33900 HIGH
Apache Directory Studio < 2.0.0.v20210717-M17 - Cleartext Transmission of Sensitive Information via StartTLS and SASL
CVSS 7.5
CVE-2021-1896 MEDIUM
Qualcomm Firmware - Cleartext Transmission of Sensitive Information via WLAN Packet Forwarding
CVSS 4.3
CVE-2021-36382 LOW
Devolutions Server <2021.1.18-2020.3.20 - Man In The Middle
CVSS 2.6
CVE-2021-22380 CRITICAL
Huawei Smartphone - Info Disclosure
CVSS 9.1
CVE-2021-23846 HIGH
Bosch B426 Firmware - Cleartext Transmission of Sensitive Information via HTTP
CVSS 8.8
CVE-2021-34825 HIGH
Quassel < 0.13.1 - Cleartext Transmission of Sensitive Information via Missing Certificate Check
CVSS 7.5
CVE-2021-32612 HIGH
VeryFitPro 3.2.8 - Cleartext Transmission of Sensitive Information via HTTP
CVSS 8.1
CVE-2021-22325 MEDIUM
Huawei EMUI and Magic UI - Cleartext Transmission of Sensitive Video Stream Data
CVSS 5.3
CVE-2021-23896 LOW
McAfee Database Security < 4.8.2 - Cleartext Transmission of Sensitive Information in Administrator Interface
CVSS 3.2
CVE-2021-23018 HIGH
NGINX Controller <3.4.0 - Info Disclosure
CVSS 7.4
CVE-2021-33408 MEDIUM
Ab Initio Control>Center <4.0.2.6-4.0.3.1 - Local File Inclusion
CVSS 6.5
CVE-2021-25643 MEDIUM
Couchbase Server 5.x-6.5.1 and 6.6.x < 6.6.2 - Cleartext Credential Exposure in Indexer Log
CVSS 4.9
CVE-2021-27924 MEDIUM
Couchbase Server <6.6.1 - Info Disclosure
CVSS 5.9
CVE-2021-32456 MEDIUM
SITEL CAP/PRX Firmware 5.2.01 - Cleartext Transmission of Sensitive Information
CVSS 6.5
CVE-2021-20564 MEDIUM
IBM Cloud Pak for Security <1.6.0.1 - Info Disclosure
CVSS 5.9
CVE-2021-31898 HIGH
JetBrains WebStorm < 2021.1 - Cleartext Transmission of Sensitive Information
CVSS 7.5
CVE-2021-3003 MEDIUM
Agenzia delle Entrate Desktop Telematico 1.0.0 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities 882
Exploit Likelihood High