Vulnerabilities > Cleartext Transmission of Sensitive Information

DATE CVE VULNERABILITY TITLE RISK
2023-02-01 CVE-2023-23130 Cleartext Transmission of Sensitive Information vulnerability in Connectwise Automate 2022.11
Connectwise Automate 2022.11 is vulnerable to Cleartext authentication.
network
high complexity
connectwise CWE-319
5.9
2023-01-26 CVE-2023-24440 Cleartext Transmission of Sensitive Information vulnerability in Jenkins Jira Pipeline Steps 2.0.165.V8846Cf59F3Db
Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier transmits the private key in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.
local
low complexity
jenkins CWE-319
5.5
2023-01-11 CVE-2022-0553 Cleartext Transmission of Sensitive Information vulnerability in Zephyrproject Zephyr
There is no check to see if slot 0 is being uploaded from the device to the host.
low complexity
zephyrproject CWE-319
4.6
2023-01-09 CVE-2022-23509 Cleartext Transmission of Sensitive Information vulnerability in Weave Gitops
Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise.
local
low complexity
weave CWE-319
6.0
2023-01-05 CVE-2022-3929 Cleartext Transmission of Sensitive Information vulnerability in Hitachienergy Foxman-Un and Unem
Communication between the client and the server application of the affected products is partially done using CORBA (Common Object Request Broker Architecture) over TCP/IP.
network
low complexity
hitachienergy CWE-319
critical
9.8
2023-01-04 CVE-2023-0055 Cleartext Transmission of Sensitive Information vulnerability in Pyload 0.5.0
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository pyload/pyload prior to 0.5.0b3.dev32.
network
low complexity
pyload CWE-319
5.3
2022-12-23 CVE-2022-43551 Cleartext Transmission of Sensitive Information vulnerability in multiple products
A vulnerability exists in curl <7.87.0 HSTS check that could be bypassed to trick it to keep using HTTP.
network
low complexity
haxx fedoraproject netapp splunk CWE-319
7.5
2022-12-22 CVE-2022-22758 Cleartext Transmission of Sensitive Information vulnerability in Mozilla Firefox
When clicking on a tel: link, USSD codes, specified after a <code>\*</code> character, would be included in the phone number.
network
low complexity
mozilla CWE-319
8.8
2022-12-22 CVE-2022-47895 Cleartext Transmission of Sensitive Information vulnerability in Jetbrains Intellij Idea
In JetBrains IntelliJ IDEA before 2022.3.1 the "Validate JSP File" action used the HTTP protocol to download required JAR files.
network
low complexity
jetbrains CWE-319
7.5
2022-12-19 CVE-2021-4258 Cleartext Transmission of Sensitive Information vulnerability in Whohas Project Whohas
A vulnerability was found in whohas.
network
low complexity
whohas-project CWE-319
7.5