CWE-319 · 823 kayıt
Cleartext Transmission of Sensitive Information
Bu sınıftaki CVE’ler
824 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
55Planlayın | CVE-2018-12710Kavram kanıtı | An issue was discovered on D-Link DIR-601 2.02NA devices.dlink · dir-601 firmware · CWE-319 | Yüksek8,0 | — | %76,5 | 29 Ağu 2018 |
51Planlayın | CVE-2024-25735Kavram kanıtı | An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58.wyrestorm · apollo vx20 firmware · CWE-319 | Kritik9,1 | — | %50,6 | 26 Mar 2024 |
46Planlayın | CVE-2016-5649Kavram kanıtı | Netgear DGN2200 and DGND3700 disclose the administrator passwordnetgear · dgn2200 firmware · CWE-319 | Kritik9,8 | — | %23,6 | 24 Tem 2018 |
42Planlayın | CVE-2018-1297Kavram kanıtı | When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection.apache · jmeter · CWE-319 | Kritik9,8 | — | %9,9 | 13 Şub 2018 |
40Planlayın | CVE-2021-20623İstismar yok | Video Insight VMS versions prior to 7.8 allows a remote attacker to execute arbitrary code with the system user privilege by sending a specipanasonic · video insight vms · CWE-319 | Kritik9,8 | — | %2,8 | 5 Şub 2021 |
40Planlayın | CVE-2019-17393İstismar yok | The Customer's Tomedo Server in Version 1.7.3 communicates to the Vendor Tomedo Server via HTTP (in cleartext) that can be sniffed by unauthtomedo · server · CWE-319 | Kritik9,8 | — | %1,8 | 18 Eki 2019 |
40Planlayın | CVE-2022-21829İstismar yok | Concrete CMS Versions 9.0.0 through 9.0.2 and 8.5.7 and below can download zip files over HTTP and execute code from those zip files which cconcretecms · concrete cms · CWE-319 | Kritik9,8 | — | %1,8 | 24 Haz 2022 |
40Planlayın | CVE-2025-4378İstismar yok | Hardcoded Credentials in Ataturk University's ATA-AOF Mobile Applicationataturk university · ata-aof mobile application · CWE-319 | Kritik10,0 | — | %0,3 | 24 Haz 2025 |
40Planlayın | CVE-2025-47419İstismar yok | Cleartext Transmission of Sensitive Information vulnerability in Crestron Automate VX allows Sniffing Network Traffic.crestron · automate vx · CWE-319 | Kritik10,0 | — | %0,3 | 6 May 2025 |
40Planlayın | CVE-2026-22306İstismar yok | Critical flaw impacting OZOLS ERP's automatic update channelozols grupa · ozols · CWE-319 | Kritik10,0 | — | %0,2 | 19 Ağu 2026 |
39İzleyin | CVE-2023-25437İstismar yok | An issue was discovered in vTech VCS754 version 1.1.1.A before 1.1.1.H, allows attackers to gain escalated privileges and gain sensitive infvtech · vcs754a firmware · CWE-319 | Yüksek8,8 | — | %14,1 | 27 Nis 2023 |
39İzleyin | CVE-2019-18852İstismar yok | Certain D-Link devices have a hardcoded Alphanetworks user account with TELNET access because of /etc/config/image_sign or /etc/alpha_configdlink · dir-600 b1 firmware · CWE-319 | Kritik9,8 | — | %1,6 | 11 Kas 2019 |
39İzleyin | CVE-2020-5594İstismar yok | Mitsubishi Electric MELSEC iQ-R, iQ-F, Q, L, and FX series CPU modules all versions contain a vulnerability that allows cleartext transmissimitsubishielectric · melsec iq-r firmware · CWE-319 | Kritik9,8 | — | %1,3 | 23 Haz 2020 |
39İzleyin | CVE-2019-16672İstismar yok | An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 161weidmueller · ie-sw-pl09m-5gc-4gt firmware · CWE-319 | Kritik9,8 | — | %1,3 | 6 Ara 2019 |
39İzleyin | CVE-2020-9477İstismar yok | An issue was discovered on HUMAX HGA12R-02 BRGCAA 1.1.53 devices.humaxdigital · hga12r-02 firmware · CWE-319 | Kritik9,8 | — | %1,3 | 4 Mar 2020 |
39İzleyin | CVE-2023-33730Kavram kanıtı | Privilege Escalation in the "GetUserCurrentPwd" function in Microworld Technologies eScan Management Console 14.0.1400.2281 allows any remotescanav · escan management console · CWE-319 | Kritik9,8 | — | %1,2 | 31 May 2023 |
39İzleyin | CVE-2020-10376İstismar yok | Technicolor TC7337NET 08.89.17.23.03 devices allow remote attackers to discover passwords by sniffing the network for an "Authorization: Bastechnicolor · tc7337net firmware · CWE-319 | Kritik9,8 | — | %1,1 | 11 Mar 2020 |
39İzleyin | CVE-2018-11422İstismar yok | Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior use a proprietary configuration protocol that does not provide confidentimoxa · oncell g3150-hspa firmware · CWE-319 | Kritik9,8 | — | %1,0 | 3 Tem 2019 |
39İzleyin | CVE-2018-7259İstismar yok | The FSX / P3Dv4 installer 2.0.1.231 for Flight Sim Labs A320-X sends a user's Google account credentials to http://installLog.flightsimlabs.flightsimlabs · a320-x · CWE-319 | Kritik9,8 | — | %1,0 | 19 Şub 2018 |
39İzleyin | CVE-2022-33321İstismar yok | Cleartext Transmission of Sensitive Information vulnerability due to the use of Basic Authentication for HTTP connections in Mitsubishi Elecmitsubishielectric · mac-557if-e firmware · CWE-319 | Kritik9,8 | — | %1,0 | 8 Kas 2022 |
39İzleyin | CVE-2020-25190İstismar yok | MOXA NPort IAW5000A-I/O Seriesmoxa · nport iaw5000a-i\/o firmware · CWE-319 | Kritik9,8 | — | %1,0 | 23 Ara 2020 |
39İzleyin | CVE-2020-12040İstismar yok | Sigma Spectrum Infusion System v's6.x (model 35700BAX) and Baxter Spectrum Infusion System Version(s) 8.x (model 35700BAX2) at the applicatibaxter · sigma spectrum infusion system firmware · CWE-319 | Kritik9,8 | — | %0,9 | 29 Haz 2020 |
39İzleyin | CVE-2018-11421İstismar yok | Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior use a proprietary monitoring protocol that does not provide confidentialimoxa · oncell g3150-hspa firmware · CWE-319 | Kritik9,8 | — | %0,9 | 3 Tem 2019 |
39İzleyin | CVE-2019-15911İstismar yok | An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO.asus · hg100 firmware · CWE-319 | Kritik9,8 | — | %0,8 | 20 Ara 2019 |
39İzleyin | CVE-2019-5505İstismar yok | ONTAP Select Deploy administration utility versions 2.2 through 2.12.1 transmit credentials in plaintext.netapp · ontap select deploy administration utility · CWE-319 | Kritik9,8 | — | %0,8 | 24 Eyl 2019 |
- CVE-2018-1271055Planlayın
An issue was discovered on D-Link DIR-601 2.02NA devices.
YüksekCVSS 8,0Kavram kanıtıEPSS %77dlink · dir-601 firmware29 Ağu 2018
- CVE-2024-2573551Planlayın
An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58.
KritikCVSS 9,1Kavram kanıtıEPSS %51wyrestorm · apollo vx20 firmware26 Mar 2024
- CVE-2016-564946Planlayın
Netgear DGN2200 and DGND3700 disclose the administrator password
KritikCVSS 9,8Kavram kanıtıEPSS %24netgear · dgn2200 firmware24 Tem 2018
- CVE-2018-129742Planlayın
When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection.
KritikCVSS 9,8Kavram kanıtıEPSS %10apache · jmeter13 Şub 2018
- CVE-2021-2062340Planlayın
Video Insight VMS versions prior to 7.8 allows a remote attacker to execute arbitrary code with the system user privilege by sending a speci
KritikCVSS 9,8İstismar yokEPSS %3panasonic · video insight vms5 Şub 2021
- CVE-2019-1739340Planlayın
The Customer's Tomedo Server in Version 1.7.3 communicates to the Vendor Tomedo Server via HTTP (in cleartext) that can be sniffed by unauth
KritikCVSS 9,8İstismar yokEPSS %2tomedo · server18 Eki 2019
- CVE-2022-2182940Planlayın
Concrete CMS Versions 9.0.0 through 9.0.2 and 8.5.7 and below can download zip files over HTTP and execute code from those zip files which c
KritikCVSS 9,8İstismar yokEPSS %2concretecms · concrete cms24 Haz 2022
- CVE-2025-437840Planlayın
Hardcoded Credentials in Ataturk University's ATA-AOF Mobile Application
KritikCVSS 10,0İstismar yokEPSS %0ataturk university · ata-aof mobile application24 Haz 2025
- CVE-2025-4741940Planlayın
Cleartext Transmission of Sensitive Information vulnerability in Crestron Automate VX allows Sniffing Network Traffic.
KritikCVSS 10,0İstismar yokEPSS %0crestron · automate vx6 May 2025
- CVE-2026-2230640Planlayın
Critical flaw impacting OZOLS ERP's automatic update channel
KritikCVSS 10,0İstismar yokEPSS %0ozols grupa · ozols19 Ağu 2026
- CVE-2023-2543739İzleyin
An issue was discovered in vTech VCS754 version 1.1.1.A before 1.1.1.H, allows attackers to gain escalated privileges and gain sensitive inf
YüksekCVSS 8,8İstismar yokEPSS %14vtech · vcs754a firmware27 Nis 2023
- CVE-2019-1885239İzleyin
Certain D-Link devices have a hardcoded Alphanetworks user account with TELNET access because of /etc/config/image_sign or /etc/alpha_config
KritikCVSS 9,8İstismar yokEPSS %2dlink · dir-600 b1 firmware11 Kas 2019
- CVE-2020-559439İzleyin
Mitsubishi Electric MELSEC iQ-R, iQ-F, Q, L, and FX series CPU modules all versions contain a vulnerability that allows cleartext transmissi
KritikCVSS 9,8İstismar yokEPSS %1mitsubishielectric · melsec iq-r firmware23 Haz 2020
- CVE-2019-1667239İzleyin
An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 161
KritikCVSS 9,8İstismar yokEPSS %1weidmueller · ie-sw-pl09m-5gc-4gt firmware6 Ara 2019
- CVE-2020-947739İzleyin
An issue was discovered on HUMAX HGA12R-02 BRGCAA 1.1.53 devices.
KritikCVSS 9,8İstismar yokEPSS %1humaxdigital · hga12r-02 firmware4 Mar 2020
- CVE-2023-3373039İzleyin
Privilege Escalation in the "GetUserCurrentPwd" function in Microworld Technologies eScan Management Console 14.0.1400.2281 allows any remot
KritikCVSS 9,8Kavram kanıtıEPSS %1escanav · escan management console31 May 2023
- CVE-2020-1037639İzleyin
Technicolor TC7337NET 08.89.17.23.03 devices allow remote attackers to discover passwords by sniffing the network for an "Authorization: Bas
KritikCVSS 9,8İstismar yokEPSS %1technicolor · tc7337net firmware11 Mar 2020
- CVE-2018-1142239İzleyin
Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior use a proprietary configuration protocol that does not provide confidenti
KritikCVSS 9,8İstismar yokEPSS %1moxa · oncell g3150-hspa firmware3 Tem 2019
- CVE-2018-725939İzleyin
The FSX / P3Dv4 installer 2.0.1.231 for Flight Sim Labs A320-X sends a user's Google account credentials to http://installLog.flightsimlabs.
KritikCVSS 9,8İstismar yokEPSS %1flightsimlabs · a320-x19 Şub 2018
- CVE-2022-3332139İzleyin
Cleartext Transmission of Sensitive Information vulnerability due to the use of Basic Authentication for HTTP connections in Mitsubishi Elec
KritikCVSS 9,8İstismar yokEPSS %1mitsubishielectric · mac-557if-e firmware8 Kas 2022
- CVE-2020-2519039İzleyin
MOXA NPort IAW5000A-I/O Series
KritikCVSS 9,8İstismar yokEPSS %1moxa · nport iaw5000a-i\/o firmware23 Ara 2020
- CVE-2020-1204039İzleyin
Sigma Spectrum Infusion System v's6.x (model 35700BAX) and Baxter Spectrum Infusion System Version(s) 8.x (model 35700BAX2) at the applicati
KritikCVSS 9,8İstismar yokEPSS %1baxter · sigma spectrum infusion system firmware29 Haz 2020
- CVE-2018-1142139İzleyin
Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior use a proprietary monitoring protocol that does not provide confidentiali
KritikCVSS 9,8İstismar yokEPSS %1moxa · oncell g3150-hspa firmware3 Tem 2019
- CVE-2019-1591139İzleyin
An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO.
KritikCVSS 9,8İstismar yokEPSS %1asus · hg100 firmware20 Ara 2019
- CVE-2019-550539İzleyin
ONTAP Select Deploy administration utility versions 2.2 through 2.12.1 transmit credentials in plaintext.
KritikCVSS 9,8İstismar yokEPSS %1netapp · ontap select deploy administration utility24 Eyl 2019