CWE-319

High likelihood

Cleartext Transmission of Sensitive Information

Parent: CWE-311 - Missing Encryption of Sensitive Data

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

898 vulnerabilities with CWE-319
CVE-2021-44480 HIGH
Wokka Lokka Q50 Firmware - Unauthenticated Sensitive Information Exposure via SMS Callback
CVSS 8.1
CVE-2021-37939 LOW
Kibana 7.8.0-7.15.1 - Authenticated Internal Host HTTP Response Disclosure via JIRA and IBM Resilient Connectors
CVSS 2.7
CVE-2021-38978 MEDIUM
IBM Tivoli Key Lifecycle Manager <4.1 - Info Disclosure
CVSS 5.9
CVE-2021-3792 MEDIUM
Motorola-branded Binatone Hubble Cameras - Info Disclosure
CVSS 5.3
CVE-2021-40366 HIGH
Climatix POL909 Firmware < 11.34 (AWM)/< 11.42 (AWB) Cleartext Transmission of Sensitive Info
CVSS 7.4
CVE-2021-3774 HIGH
Meross Smart Wi-Fi 2 Way Wall Switch <3.1.3 - Info Disclosure
CVSS 7.4
CVE-2021-29753 MEDIUM
IBM BA Workflow 18-21 & BPM 8.5-8.6 Cleartext Transmission of Sensitive Info
CVSS 5.9
CVE-2021-42699 MEDIUM
DAQFactory - Cleartext Transmission of Sensitive Information via HTTP Cookie
CVSS 5.7
CVE-2021-38418 HIGH
Delta Electronics DIALink <1.2.4.0 - Info Disclosure
CVSS 8.8
CVE-2021-43270 HIGH
Datalust Seq.App.EmailPlus Cleartext Transmission of Sensitive Information via SMTP Port 25
CVSS 7.5
CVE-2021-39341 HIGH
OptinMonster < 2.6.4 - Sensitive Information Disclosure via Insufficient Authorization
CVSS 8.2
CVE-2021-0296 HIGH
Juniper Networks CTPView <7.3R7, <9.1R3 - Info Disclosure
CVSS 7.4
CVE-2021-20599 CRITICAL
MELSEC iQ-R Safety and Process CPU Firmware - Unauthenticated Cleartext Transmission of Sensitive Information
CVSS 9.1
CVE-2021-39882 MEDIUM
GitLab - Unauthenticated Cleartext Transmission of Sensitive Information via User ID Endpoints
CVSS 5.3
CVE-2021-39342 MEDIUM
Credova Financial <= 1.4.8 - Cleartext Transmission of Sensitive Information via AJAX Action
CVSS 5.3
CVE-2021-22946 HIGH
curl >=7.20.0-7.78.0 - Info Disclosure
CVSS 7.5
CVE-2021-36165 MEDIUM
RICON Industrial Cellular Router S9922L <16.10.3 - Info Disclosure
CVSS 5.3
CVE-2021-40847 HIGH
NETGEAR Routers - Root Code Execution via Cleartext Circle Update Man-in-the-Middle
CVSS 8.1
CVE-2021-38142 HIGH
Barco MirrorOp Windows Sender <2.5.3.65 - RCE
CVSS 8.8
CVE-2021-39272 MEDIUM
fetchmail < 6.4.22 - Cleartext Transmission of Sensitive Information via STARTTLS Enforcement Bypass
CVSS 5.9
CVE-2021-33883 MEDIUM
B. Braun SpaceCom2 < 012U000062 - Cleartext Transmission of Sensitive Information
CVSS 5.9
CVE-2021-38373 MEDIUM
KDE KMail <19.12.3 - Info Disclosure
CVSS 5.3
CVE-2021-22923 MEDIUM
curl - Metalink Feature - Auth Bypass
CVSS 5.3
CVE-2021-29769 MEDIUM
IBM i2 Analyze 4.3.0-4.3.2 - Cleartext Transmission of Sensitive Information in Session Cookies
CVSS 4.3
CVE-2021-33900 HIGH
Apache Directory Studio < 2.0.0.v20210717-M17 - Cleartext Transmission of Sensitive Information via StartTLS and SASL
CVSS 7.5
Details
Vulnerabilities 898
Exploit Likelihood High