Skip to main content

CWE archive

CWE-319 CVEs

Programmatic archive

897 CVEs tagged with CWE-31982 Critical, 359 High, 402 Medium, 54 Low, 0 Unrated.

CVE-2018-11050

Published Aug 1, 2018

Dell EMC NetWorker versions between 9.0 and 9.1.1.8 through 9.2.1.3, and the version 18.1.0.1 contain a Clear-Text authentication over network vulnerability in the Rabbit MQ Advan…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11338

Published Jul 31, 2018

Intuit Lacerte 2017 for Windows in a client/server environment transfers the entire customer list in cleartext over SMB, which allows attackers to (1) obtain sensitive information…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0025

Published Jul 11, 2018

When an SRX Series device is configured to use HTTP/HTTPS pass-through authentication services, a client sending authentication credentials in the initial HTTP/HTTPS session is at…

CVSS 6.1 · Medium

CVE-2018-8929

Published Jul 6, 2018

Improper restriction of communication channel to intended endpoints vulnerability in HTTP daemon in Synology SSL VPN Client before 1.2.4-0224 allows remote attackers to conduct ma…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2018-4227

Published Jun 8, 2018

An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. The issue involves the "Mail" component. It allows remote attacke…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-1454

Published Jun 5, 2018

IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transpor…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-16040

Published Jun 4, 2018

gfe-sass is a library for promises (CommonJS/Promises/A,B,D) gfe-sass downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-16035

Published Jun 4, 2018

The hubl-server module is a wrapper for the HubL Development Server. During installation hubl-server downloads a set of dependencies from api.hubapi.com. It appears in the code th…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1600

Published Jun 4, 2018

IBM BigFix Platform 9.2 and 9.5 transmits sensitive or security-critical data in clear text in a communication channel that can be sniffed by unauthorized actors. IBM X-Force ID:…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2017-0925

Published Mar 21, 2018

Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration API endpoint resulting in an information…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 826-850 of 897 CVEsPage 34 of 36