CWE-319 · 823 записей
Cleartext Transmission of Sensitive Information
CVE этого класса
824 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
55В плане | CVE-2018-12710Proof of concept | An issue was discovered on D-Link DIR-601 2.02NA devices.dlink · dir-601 firmware · CWE-319 | Высокая8,0 | — | 76,5 % | 29 авг. 2018 г. |
51В плане | CVE-2024-25735Proof of concept | An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58.wyrestorm · apollo vx20 firmware · CWE-319 | Критическая9,1 | — | 50,6 % | 26 мар. 2024 г. |
46В плане | CVE-2016-5649Proof of concept | Netgear DGN2200 and DGND3700 disclose the administrator passwordnetgear · dgn2200 firmware · CWE-319 | Критическая9,8 | — | 23,6 % | 24 июл. 2018 г. |
42В плане | CVE-2018-1297Proof of concept | When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection.apache · jmeter · CWE-319 | Критическая9,8 | — | 9,9 % | 13 февр. 2018 г. |
40В плане | CVE-2021-20623Эксплойта нет | Video Insight VMS versions prior to 7.8 allows a remote attacker to execute arbitrary code with the system user privilege by sending a specipanasonic · video insight vms · CWE-319 | Критическая9,8 | — | 2,8 % | 5 февр. 2021 г. |
40В плане | CVE-2019-17393Эксплойта нет | The Customer's Tomedo Server in Version 1.7.3 communicates to the Vendor Tomedo Server via HTTP (in cleartext) that can be sniffed by unauthtomedo · server · CWE-319 | Критическая9,8 | — | 1,8 % | 18 окт. 2019 г. |
40В плане | CVE-2022-21829Эксплойта нет | Concrete CMS Versions 9.0.0 through 9.0.2 and 8.5.7 and below can download zip files over HTTP and execute code from those zip files which cconcretecms · concrete cms · CWE-319 | Критическая9,8 | — | 1,8 % | 24 июн. 2022 г. |
40В плане | CVE-2025-4378Эксплойта нет | Hardcoded Credentials in Ataturk University's ATA-AOF Mobile Applicationataturk university · ata-aof mobile application · CWE-319 | Критическая10,0 | — | 0,3 % | 24 июн. 2025 г. |
40В плане | CVE-2025-47419Эксплойта нет | Cleartext Transmission of Sensitive Information vulnerability in Crestron Automate VX allows Sniffing Network Traffic.crestron · automate vx · CWE-319 | Критическая10,0 | — | 0,3 % | 6 мая 2025 г. |
40В плане | CVE-2026-22306Эксплойта нет | Critical flaw impacting OZOLS ERP's automatic update channelozols grupa · ozols · CWE-319 | Критическая10,0 | — | 0,2 % | 19 авг. 2026 г. |
39Наблюдать | CVE-2023-25437Эксплойта нет | An issue was discovered in vTech VCS754 version 1.1.1.A before 1.1.1.H, allows attackers to gain escalated privileges and gain sensitive infvtech · vcs754a firmware · CWE-319 | Высокая8,8 | — | 14,1 % | 27 апр. 2023 г. |
39Наблюдать | CVE-2019-18852Эксплойта нет | Certain D-Link devices have a hardcoded Alphanetworks user account with TELNET access because of /etc/config/image_sign or /etc/alpha_configdlink · dir-600 b1 firmware · CWE-319 | Критическая9,8 | — | 1,6 % | 11 нояб. 2019 г. |
39Наблюдать | CVE-2020-5594Эксплойта нет | Mitsubishi Electric MELSEC iQ-R, iQ-F, Q, L, and FX series CPU modules all versions contain a vulnerability that allows cleartext transmissimitsubishielectric · melsec iq-r firmware · CWE-319 | Критическая9,8 | — | 1,3 % | 23 июн. 2020 г. |
39Наблюдать | CVE-2019-16672Эксплойта нет | An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 161weidmueller · ie-sw-pl09m-5gc-4gt firmware · CWE-319 | Критическая9,8 | — | 1,3 % | 6 дек. 2019 г. |
39Наблюдать | CVE-2020-9477Эксплойта нет | An issue was discovered on HUMAX HGA12R-02 BRGCAA 1.1.53 devices.humaxdigital · hga12r-02 firmware · CWE-319 | Критическая9,8 | — | 1,3 % | 4 мар. 2020 г. |
39Наблюдать | CVE-2023-33730Proof of concept | Privilege Escalation in the "GetUserCurrentPwd" function in Microworld Technologies eScan Management Console 14.0.1400.2281 allows any remotescanav · escan management console · CWE-319 | Критическая9,8 | — | 1,2 % | 31 мая 2023 г. |
39Наблюдать | CVE-2020-10376Эксплойта нет | Technicolor TC7337NET 08.89.17.23.03 devices allow remote attackers to discover passwords by sniffing the network for an "Authorization: Bastechnicolor · tc7337net firmware · CWE-319 | Критическая9,8 | — | 1,1 % | 11 мар. 2020 г. |
39Наблюдать | CVE-2018-11422Эксплойта нет | Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior use a proprietary configuration protocol that does not provide confidentimoxa · oncell g3150-hspa firmware · CWE-319 | Критическая9,8 | — | 1,0 % | 3 июл. 2019 г. |
39Наблюдать | CVE-2018-7259Эксплойта нет | The FSX / P3Dv4 installer 2.0.1.231 for Flight Sim Labs A320-X sends a user's Google account credentials to http://installLog.flightsimlabs.flightsimlabs · a320-x · CWE-319 | Критическая9,8 | — | 1,0 % | 19 февр. 2018 г. |
39Наблюдать | CVE-2022-33321Эксплойта нет | Cleartext Transmission of Sensitive Information vulnerability due to the use of Basic Authentication for HTTP connections in Mitsubishi Elecmitsubishielectric · mac-557if-e firmware · CWE-319 | Критическая9,8 | — | 1,0 % | 8 нояб. 2022 г. |
39Наблюдать | CVE-2020-25190Эксплойта нет | MOXA NPort IAW5000A-I/O Seriesmoxa · nport iaw5000a-i\/o firmware · CWE-319 | Критическая9,8 | — | 1,0 % | 23 дек. 2020 г. |
39Наблюдать | CVE-2020-12040Эксплойта нет | Sigma Spectrum Infusion System v's6.x (model 35700BAX) and Baxter Spectrum Infusion System Version(s) 8.x (model 35700BAX2) at the applicatibaxter · sigma spectrum infusion system firmware · CWE-319 | Критическая9,8 | — | 0,9 % | 29 июн. 2020 г. |
39Наблюдать | CVE-2018-11421Эксплойта нет | Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior use a proprietary monitoring protocol that does not provide confidentialimoxa · oncell g3150-hspa firmware · CWE-319 | Критическая9,8 | — | 0,9 % | 3 июл. 2019 г. |
39Наблюдать | CVE-2019-15911Эксплойта нет | An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO.asus · hg100 firmware · CWE-319 | Критическая9,8 | — | 0,8 % | 20 дек. 2019 г. |
39Наблюдать | CVE-2019-5505Эксплойта нет | ONTAP Select Deploy administration utility versions 2.2 through 2.12.1 transmit credentials in plaintext.netapp · ontap select deploy administration utility · CWE-319 | Критическая9,8 | — | 0,8 % | 24 сент. 2019 г. |
- CVE-2018-1271055В плане
An issue was discovered on D-Link DIR-601 2.02NA devices.
ВысокаяCVSS 8,0Proof of conceptEPSS 77 %dlink · dir-601 firmware29 авг. 2018 г.
- CVE-2024-2573551В плане
An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58.
КритическаяCVSS 9,1Proof of conceptEPSS 51 %wyrestorm · apollo vx20 firmware26 мар. 2024 г.
- CVE-2016-564946В плане
Netgear DGN2200 and DGND3700 disclose the administrator password
КритическаяCVSS 9,8Proof of conceptEPSS 24 %netgear · dgn2200 firmware24 июл. 2018 г.
- CVE-2018-129742В плане
When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection.
КритическаяCVSS 9,8Proof of conceptEPSS 10 %apache · jmeter13 февр. 2018 г.
- CVE-2021-2062340В плане
Video Insight VMS versions prior to 7.8 allows a remote attacker to execute arbitrary code with the system user privilege by sending a speci
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %panasonic · video insight vms5 февр. 2021 г.
- CVE-2019-1739340В плане
The Customer's Tomedo Server in Version 1.7.3 communicates to the Vendor Tomedo Server via HTTP (in cleartext) that can be sniffed by unauth
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %tomedo · server18 окт. 2019 г.
- CVE-2022-2182940В плане
Concrete CMS Versions 9.0.0 through 9.0.2 and 8.5.7 and below can download zip files over HTTP and execute code from those zip files which c
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %concretecms · concrete cms24 июн. 2022 г.
- CVE-2025-437840В плане
Hardcoded Credentials in Ataturk University's ATA-AOF Mobile Application
КритическаяCVSS 10,0Эксплойта нетEPSS 0 %ataturk university · ata-aof mobile application24 июн. 2025 г.
- CVE-2025-4741940В плане
Cleartext Transmission of Sensitive Information vulnerability in Crestron Automate VX allows Sniffing Network Traffic.
КритическаяCVSS 10,0Эксплойта нетEPSS 0 %crestron · automate vx6 мая 2025 г.
- CVE-2026-2230640В плане
Critical flaw impacting OZOLS ERP's automatic update channel
КритическаяCVSS 10,0Эксплойта нетEPSS 0 %ozols grupa · ozols19 авг. 2026 г.
- CVE-2023-2543739Наблюдать
An issue was discovered in vTech VCS754 version 1.1.1.A before 1.1.1.H, allows attackers to gain escalated privileges and gain sensitive inf
ВысокаяCVSS 8,8Эксплойта нетEPSS 14 %vtech · vcs754a firmware27 апр. 2023 г.
- CVE-2019-1885239Наблюдать
Certain D-Link devices have a hardcoded Alphanetworks user account with TELNET access because of /etc/config/image_sign or /etc/alpha_config
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %dlink · dir-600 b1 firmware11 нояб. 2019 г.
- CVE-2020-559439Наблюдать
Mitsubishi Electric MELSEC iQ-R, iQ-F, Q, L, and FX series CPU modules all versions contain a vulnerability that allows cleartext transmissi
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mitsubishielectric · melsec iq-r firmware23 июн. 2020 г.
- CVE-2019-1667239Наблюдать
An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 161
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %weidmueller · ie-sw-pl09m-5gc-4gt firmware6 дек. 2019 г.
- CVE-2020-947739Наблюдать
An issue was discovered on HUMAX HGA12R-02 BRGCAA 1.1.53 devices.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %humaxdigital · hga12r-02 firmware4 мар. 2020 г.
- CVE-2023-3373039Наблюдать
Privilege Escalation in the "GetUserCurrentPwd" function in Microworld Technologies eScan Management Console 14.0.1400.2281 allows any remot
КритическаяCVSS 9,8Proof of conceptEPSS 1 %escanav · escan management console31 мая 2023 г.
- CVE-2020-1037639Наблюдать
Technicolor TC7337NET 08.89.17.23.03 devices allow remote attackers to discover passwords by sniffing the network for an "Authorization: Bas
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %technicolor · tc7337net firmware11 мар. 2020 г.
- CVE-2018-1142239Наблюдать
Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior use a proprietary configuration protocol that does not provide confidenti
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %moxa · oncell g3150-hspa firmware3 июл. 2019 г.
- CVE-2018-725939Наблюдать
The FSX / P3Dv4 installer 2.0.1.231 for Flight Sim Labs A320-X sends a user's Google account credentials to http://installLog.flightsimlabs.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %flightsimlabs · a320-x19 февр. 2018 г.
- CVE-2022-3332139Наблюдать
Cleartext Transmission of Sensitive Information vulnerability due to the use of Basic Authentication for HTTP connections in Mitsubishi Elec
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mitsubishielectric · mac-557if-e firmware8 нояб. 2022 г.
- CVE-2020-2519039Наблюдать
MOXA NPort IAW5000A-I/O Series
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %moxa · nport iaw5000a-i\/o firmware23 дек. 2020 г.
- CVE-2020-1204039Наблюдать
Sigma Spectrum Infusion System v's6.x (model 35700BAX) and Baxter Spectrum Infusion System Version(s) 8.x (model 35700BAX2) at the applicati
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %baxter · sigma spectrum infusion system firmware29 июн. 2020 г.
- CVE-2018-1142139Наблюдать
Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior use a proprietary monitoring protocol that does not provide confidentiali
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %moxa · oncell g3150-hspa firmware3 июл. 2019 г.
- CVE-2019-1591139Наблюдать
An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %asus · hg100 firmware20 дек. 2019 г.
- CVE-2019-550539Наблюдать
ONTAP Select Deploy administration utility versions 2.2 through 2.12.1 transmit credentials in plaintext.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %netapp · ontap select deploy administration utility24 сент. 2019 г.