Skip to main content

CWE archive

CWE-319 CVEs

Programmatic archive

897 CVEs tagged with CWE-31982 Critical, 359 High, 402 Medium, 54 Low, 0 Unrated.

CVE-2026-24455

Published Feb 20, 2026

The embedded web interface of the device does not support HTTPS/TLS for authentication and uses HTTP Basic Authentication. Traffic is encoded but not encrypted, exposing user cr…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2025-27903

Published Feb 17, 2026

IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 IBM Db2 Recovery Expert for Linux, UNIX and Windows transmits data in a cleartext communication channel that could allow an att…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-2539

Published Feb 15, 2026

The RF communication protocol in the Micca KE700 car alarm system does not encrypt its data frames. An attacker with a radio interception tool (e.g., SDR) can capture the random n…

CVSS 5.7 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-10174

Published Feb 11, 2026

Cleartext Transmission of Sensitive Information vulnerability in Pan Software & Information Technologies Ltd. PanCafe Pro allows Flooding. This issue affects PanCafe Pro: from <…

CVSS 8.3 · High
evidence mentions
2
Buzz score
21.0

CVE-2025-66604

Published Feb 9, 2026

A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The library version could be displayed on the web page. This information could be exploi…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2026-24441

Published Feb 3, 2026

Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior expose account credentials in plaintext within HTTP responses, allowing an on-path attacker to obtain sensitive authe…

CVSS 8.2 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-1777

Published Feb 2, 2026

The Amazon SageMaker Python SDK before v3.2.0 and v2.256.0 includes the ModelBuilder HMAC signing key in the cleartext response elements of the DescribeTrainingJob function. A thi…

CVSS 8.5 · High
evidence mentions
4
Buzz score
26.1

CVE-2026-22274

Published Jan 23, 2026

Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Transmission of Sensitive Information vulnerability in the Fabric…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-22271

Published Jan 23, 2026

Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Transmission of Sensitive Information vulnerability. An unauthenti…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-0767

Published Jan 23, 2026

Open WebUI Cleartext Transmission of Credentials Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on af…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-64769

Published Jan 16, 2026

The Process Optimization application suite leverages connection channels/protocols that by-default are not encrypted and could become subject to hijacking or data leakage in cer…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2026-22080

Published Jan 9, 2026

This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the transmission of credentials encoded using reversible Base64…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-22079

Published Jan 9, 2026

This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the plaintext transmission of login credentials during the initi…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-22544

Published Jan 7, 2026

An attacker with a network connection could detect credentials in clear text.

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2020-36917

Published Jan 6, 2026

iDS6 DSSPro Digital Signage System 6.2 contains a sensitive information disclosure vulnerability that allows remote attackers to intercept authentication credentials through clear…

CVSS 8.6 · High

CVE-2020-36914

Published Jan 6, 2026

QiHang Media Web Digital Signage 3.0.9 contains a sensitive information disclosure vulnerability that allows remote attackers to intercept user authentication credentials through…

CVSS 8.6 · High

CVE-2025-61738

Published Dec 22, 2025

Under certain circumstances, attacker can capture the network key, read or write encrypted packets on the PowerG network.

CVSS 2.3 · Low
Showing 76-100 of 897 CVEsPage 4 of 36