Skip to main content

CWE archive

CWE-319 CVEs

Programmatic archive

897 CVEs tagged with CWE-31982 Critical, 359 High, 402 Medium, 54 Low, 0 Unrated.

CVE-2019-10251

Published Mar 28, 2019

The UCWeb UC Browser application through 2019-03-26 for Android uses HTTP to download certain modules associated with PDF and Microsoft Office files (related to libpicsel), which…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-9860

Published Mar 27, 2019

Due to unencrypted signal communication and predictability of rolling codes, an attacker can "desynchronize" an ABUS Secvest wireless remote control (FUBE50014 or FUBE50015) relat…

CVSS 7.5 · High

CVE-2019-4063

Published Mar 5, 2019

IBM Sterling B2B Integrator 5.2.0.1 through 6.0.0.0 Standard Edition could allow highly sensitive information to be transmitted in plain text. An attacker could obtain this inform…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-8345

Published Feb 15, 2019

The Help feature in the ES File Explorer File Manager application 4.1.9.7.4 for Android allows session hijacking by a Man-in-the-middle attacker on the local network because HTTPS…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-7675

Published Feb 9, 2019

An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. The default management application is delivered over cleartext HTTP with Basic Authentication, as demonstrated by the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-18908

Published Jan 20, 2019

The Sky Go Desktop application 1.0.19-1 through 1.0.23-1 for Windows performs several requests over cleartext HTTP. This makes the data submitted in these requests prone to Man in…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-17195

Published Dec 19, 2018

The template upload API endpoint accepted requests from different domain when sent in conjunction with ARP spoofing + man in the middle (MiTM) attack, resulting in a CSRF attack.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1525

Published Dec 6, 2018

IBM i2 Enterprise Insight Analysis 2.1.7 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-19111

Published Nov 8, 2018

The Google Cardboard application 1.8 for Android and 1.2 for iOS sends potentially private cleartext information to the Unity 3D Stats web site, as demonstrated by device make, mo…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-18071

Published Oct 9, 2018

An issue was discovered in the Daimler Mercedes-Benz Me app 2.11.0-846 for iOS. The encrypted Connected Vehicle API data exchange between the app and a server might be intercepted…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-15752

Published Oct 2, 2018

An issue was discovered in the MensaMax (aka com.breustedt.mensamax) application 4.3 for Android. Cleartext Transmission of Sensitive Information allows man-in-the-middle attacker…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-8842

Published Sep 26, 2018

Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software transmits sensitive or security-critical data in cleartext in a communication channel that can be s…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-14627

Published Sep 4, 2018

The IIOP OpenJDK Subsystem in WildFly before version 14.0.0 does not honour configuration when SSL transport is required. Servers before this version that are configured with the…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-12710

Published Aug 29, 2018

An issue was discovered on D-Link DIR-601 2.02NA devices. Being local to the network and having only "User" account (which is a low privilege account) access, an attacker can inte…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11749

Published Aug 24, 2018

When users are configured to use startTLS with RBAC LDAP, at login time, the user's credentials are sent via plaintext to the LDAP server. This affects Puppet Enterprise 2018.1.3,…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 801-825 of 897 CVEsPage 33 of 36