Skip to main content

CWE archive

CWE-319 CVEs

Programmatic archive

900 CVEs tagged with CWE-31982 Critical, 360 High, 404 Medium, 54 Low, 0 Unrated.

CVE-2025-59448

Published Oct 6, 2025

Components of the YoSmart YoLink ecosystem through 2025-10-02 leverage unencrypted MQTT to communicate over the internet. An attacker with the ability to monitor network traffic c…

CVSS 4.7 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2025-59406

Published Oct 2, 2025

The Flock Safety Pisco com.flocksafety.android.pisco application 6.21.11 for Android (installed on Falcon and Sparrow License Plate Readers and Bravo Edge AI Compute Devices) has…

CVSS 6.2 · Medium
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2025-36274

Published Sep 26, 2025

IBM Aspera HTTP Gateway 2.0.0 through 2.3.1 stores sensitive information in clear text in easily obtainable files which can be read by an unauthenticated user.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-10540

Published Sep 25, 2025

iMonitor EAM 9.6394 transmits communication between the EAM client agent and the EAM server, as well as between the EAM monitor management software and the server, in plaintext wi…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2017-20200

Published Sep 23, 2025

A vulnerability has been found in Coinomi up to 1.7.6. This issue affects some unknown processing. Such manipulation leads to cleartext transmission of sensitive information. The…

CVSS 2.9 · Low

CVE-2025-10776

Published Sep 22, 2025

A vulnerability was detected in LionCoders SalePro POS up to 5.5.0. This issue affects some unknown processing of the component Login. Performing manipulation results in cleartext…

CVSS 2.9 · Low
evidence mentions
5
Buzz score
24.4

CVE-2025-54818

Published Sep 18, 2025

Cognex In-Sight Explorer and In-Sight Camera Firmware expose a proprietary protocol on TCP port 1069 to perform management operations such as modifying system properties. The u…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-47698

Published Sep 18, 2025

An adjacent attacker without authentication can exploit this vulnerability to retrieve a set of user-privileged credentials. These credentials are present during the firmware upgr…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-7743

Published Sep 16, 2025

Cleartext Transmission of Sensitive Information vulnerability in Dolusoft Omaspot allows Interception, Privilege Escalation. This issue affects Omaspot: before 12.09.2025.

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-50110

Published Sep 15, 2025

An issue was discovered in the method push.lite.avtech.com.AvtechLib.GetHttpsResponse in AVTECH EagleEyes Lite 2.0.0, the GetHttpsResponse method transmits sensitive information -…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-41708

Published Sep 8, 2025

Due to an unsecure default configuration HTTP is used instead of HTTPS for the web interface. An unauthenticated attacker on the same network could exploit this to learn sensitive…

CVSS 7.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-7731

Published Sep 1, 2025

Cleartext Transmission of Sensitive Information vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU module allows a remote unauthenticated attacker to obtain c…

CVSS 7.5 · High

CVE-2025-31972

Published Aug 28, 2025

HCL BigFix SM is affected by a Sensitive Information Exposure vulnerability where internal connections do not use TLS encryption which could allow an attacker unauthorized access…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-52351

Published Aug 21, 2025

Aikaan IoT management platform v3.25.0325-5-g2e9c59796 sends a newly generated password to users in plaintext via email and also includes the same password as a query parameter in…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2025-6180

Published Aug 20, 2025

The StrongDM Client insufficiently protected a pre-authentication token. Attackers could exploit this to intercept and reuse the token, potentially redeeming valid authentication…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-57727

Published Aug 20, 2025

In JetBrains IntelliJ IDEA before 2025.2 credentials disclosure was possible via remote reference

CVSS 4.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-8863

Published Aug 11, 2025

YugabyteDB diagnostic information was transmitted over HTTP, which could expose sensitive data during transmission

CVSS 7.0 · High

CVE-2025-8741

Published Aug 8, 2025

A vulnerability was found in macrozheng mall up to 1.0.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/login.…

CVSS 2.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-52586

Published Aug 8, 2025

The MOD3 command traffic between the monitoring application and the inverter is transmitted in plaintext without encryption or obfuscation. This vulnerability may allow an attac…

CVSS 7.5 · High
evidence mentions
3
Buzz score
23.9

CVE-2025-54799

Published Aug 7, 2025

Let's Encrypt client and ACME library written in Go (Lego). In versions 4.25.1 and below, the github.com/go-acme/lego/v4/acme/api package (thus the lego library and the lego cli a…

CVSS 2.3 · Low
evidence mentions
2
Buzz score
16.0

CVE-2025-36020

Published Aug 6, 2025

IBM Guardium Data Protection could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive credential information.

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-52490

Published Jul 29, 2025

An issue was discovered in Couchbase Sync Gateway before 3.2.6. In sgcollect_info_options.log and sync_gateway.log, there are cleartext passwords in redacted and unredacted output.

CVSS 7.3 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort
Showing 126-150 of 900 CVEsPage 6 of 36