Skip to main content

CWE archive

CWE-319 CVEs

Programmatic archive

897 CVEs tagged with CWE-31982 Critical, 359 High, 402 Medium, 54 Low, 0 Unrated.

CVE-2025-62330

Published Dec 16, 2025

HCL DevOps Deploy is susceptible to a cleartext transmission of sensitive information because the HTTP port remains accessible and does not redirect to HTTPS as intended. As a re…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-53881

Published Dec 15, 2025

ReyeeOS 1.204.1614 contains an unencrypted CWMP communication vulnerability that allows attackers to intercept and manipulate device communication through a man-in-the-middle atta…

CVSS 9.2 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-53875

Published Dec 15, 2025

GOM Player 2.3.90.5360 contains a remote code execution vulnerability in its Internet Explorer component that allows attackers to execute arbitrary code through DNS spoofing. Atta…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-13489

Published Dec 15, 2025

IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 IBM DevOps Deploy transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-65827

Published Dec 10, 2025

The mobile application is configured to allow clear text traffic to all domains and communicates with an API server over HTTP. As a result, an adversary located "upstream" can int…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-32384

Published Dec 1, 2025

Kerlink gateways running KerOS prior to version 5.10 expose their web interface exclusively over HTTP, without HTTPS support. This lack of transport layer security allows a man-in…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-63292

Published Nov 17, 2025

Freebox v5 HD (firmware = 1.7.20), Freebox v5 Crystal (firmware = 1.7.20), Freebox v6 Révolution r1–r3 (firmware = 4.7.x), Freebox Mini 4K (firmware = 4.7.x), and Freebox One (fir…

CVSS 3.5 · Low

CVE-2025-62765

Published Nov 15, 2025

General Industrial Controls Lynx+ Gateway is vulnerable to a cleartext transmission vulnerability that could allow an attacker to observe network traffic to obtain sensitive info…

CVSS 8.7 · High

CVE-2025-12508

Published Oct 31, 2025

When using domain users as BRAIN2 users, communication with Active Directory services is unencrypted. This can lead to the interception of authentication data and compromise confi…

CVSS 8.4 · High

CVE-2025-64389

Published Oct 31, 2025

The web server of the device performs exchanges of sensitive information in clear text through an insecure protocol.

CVSS 8.3 · High

CVE-2025-34271

Published Oct 30, 2025

Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the cluster manager component when requesting sensitive credentials from peer nodes over an unencrypted c…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-61481

Published Oct 27, 2025

An issue in MikroTik RouterOS v.7.14.2 and SwOS v.2.18 exposes the WebFig management interface over cleartext HTTP by default, allowing an on-path attacker to execute injected Jav…

CVSS 10.0 · Critical

CVE-2025-56447

Published Oct 22, 2025

TM2 Monitoring v3.04 contains an authentication bypass and plaintext credential disclosure.

CVSS 9.8 · Critical

CVE-2025-10641

Published Oct 21, 2025

All WorkExaminer Professional traffic between monitoring client, console and server is transmitted as plain text. This allows an attacker with access to the network to read the tr…

CVSS 7.1 · High
evidence mentions
2
Buzz score
21.0

CVE-2025-11492

Published Oct 16, 2025

In the ConnectWise Automate Agent, communications could be configured to use HTTP instead of HTTPS. In such cases, an on-path threat actor with a man-in-the-middle network positio…

CVSS 9.6 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-41718

Published Oct 14, 2025

A cleartext transmission of sensitive information vulnerability in the affected products allows an unauthorized remote attacker to gain login credentials and access the Web-UI.

CVSS 7.5 · High

CVE-2025-59448

Published Oct 6, 2025

Components of the YoSmart YoLink ecosystem through 2025-10-02 leverage unencrypted MQTT to communicate over the internet. An attacker with the ability to monitor network traffic c…

CVSS 4.7 · Medium

CVE-2025-59406

Published Oct 2, 2025

The Flock Safety Pisco com.flocksafety.android.pisco application 6.21.11 for Android (installed on Falcon and Sparrow License Plate Readers and Bravo Edge AI Compute Devices) has…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort
Showing 101-125 of 897 CVEsPage 5 of 36