Vulnerabilities > Cleartext Transmission of Sensitive Information

DATE CVE VULNERABILITY TITLE RISK
2021-11-09 CVE-2021-40366 Cleartext Transmission of Sensitive Information vulnerability in Siemens Climatix Pol909 Firmware
A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.42), Climatix POL909 (AWM module) (All versions < V11.34).
network
high complexity
siemens CWE-319
7.4
2021-11-08 CVE-2020-4152 Cleartext Transmission of Sensitive Information vulnerability in IBM Qradar Network Security
IBM QRadar Network Security 5.4.0 and 5.5.0 transmits sensitive or security-critical data in cleartext in a communication channel that can be obtained using man in the middle techniques.
network
high complexity
ibm CWE-319
5.9
2021-11-05 CVE-2021-3774 Cleartext Transmission of Sensitive Information vulnerability in Meross Mss550X Firmware 3.1.3
Meross Smart Wi-Fi 2 Way Wall Switch (MSS550X), on its 3.1.3 version and before, creates an open Wi-Fi Access Point without the required security measures in its initial setup.
network
low complexity
meross CWE-319
6.5
2021-11-05 CVE-2021-29753 Cleartext Transmission of Sensitive Information vulnerability in IBM products
IBM Business Automation Workflow 18.
network
high complexity
ibm CWE-319
5.9
2021-11-02 CVE-2021-43270 Cleartext Transmission of Sensitive Information vulnerability in Datalust Seq.App.Emailplus 3.1.0
Datalust Seq.App.EmailPlus (aka seq-app-htmlemail) 3.1.0-dev-00148, 3.1.0-dev-00170, and 3.1.0-dev-00176 can use cleartext SMTP on port 25 in some cases where encryption on port 465 was intended.
network
low complexity
datalust CWE-319
7.5
2021-10-05 CVE-2021-39882 Cleartext Transmission of Sensitive Information vulnerability in Gitlab
In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user.
network
low complexity
gitlab CWE-319
5.3
2021-09-29 CVE-2020-20128 Cleartext Transmission of Sensitive Information vulnerability in Laracms Project Laracms 1.0.1
LaraCMS v1.0.1 transmits sensitive information in cleartext which can be intercepted by attackers.
network
low complexity
laracms-project CWE-319
7.5
2021-09-29 CVE-2021-22946 Cleartext Transmission of Sensitive Information vulnerability in multiple products
A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLUSESSL_ALL` withlibcurl).
7.5
2021-09-28 CVE-2021-36165 Cleartext Transmission of Sensitive Information vulnerability in Riconmobile S9922L Firmware 16.10.3(3794)
RICON Industrial Cellular Router S9922L 16.10.3(3794) is affected by cleartext storage of sensitive information and sends username and password as base64.
network
low complexity
riconmobile CWE-319
5.3
2021-09-21 CVE-2021-40847 Cleartext Transmission of Sensitive Information vulnerability in Netgear products
The update process of the Circle Parental Control Service on various NETGEAR routers allows remote attackers to achieve remote code execution as root via a MitM attack.
network
high complexity
netgear CWE-319
8.1