Vulnerabilities > Cleartext Transmission of Sensitive Information

DATE CVE VULNERABILITY TITLE RISK
2020-03-09 CVE-2020-2149 Cleartext Transmission of Sensitive Information vulnerability in Jenkins Repository Connector
Jenkins Repository Connector Plugin 1.2.6 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.
network
low complexity
jenkins CWE-319
5.3
2020-03-09 CVE-2020-2143 Cleartext Transmission of Sensitive Information vulnerability in Jenkins Logstash
Jenkins Logstash Plugin 2.3.1 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.
network
low complexity
jenkins CWE-319
5.3
2020-03-04 CVE-2020-9550 Cleartext Transmission of Sensitive Information vulnerability in Rubetek Smarthome Firmware 2020
Rubetek SmartHome 2020 devices use unencrypted 433 MHz communication between controllers and beacons, allowing an attacker to sniff and spoof beacon requests remotely.
network
low complexity
rubetek CWE-319
critical
9.8
2020-03-04 CVE-2020-9477 Cleartext Transmission of Sensitive Information vulnerability in Humaxdigital Hga12R-02 Firmware Brgcaa1.1.53
An issue was discovered on HUMAX HGA12R-02 BRGCAA 1.1.53 devices.
network
low complexity
humaxdigital CWE-319
critical
9.8
2020-02-21 CVE-2020-7907 Cleartext Transmission of Sensitive Information vulnerability in Jetbrains Scala
In the JetBrains Scala plugin before 2019.2.1, some artefact dependencies were resolved over unencrypted connections.
network
low complexity
jetbrains CWE-319
7.5
2020-02-12 CVE-2020-5399 Cleartext Transmission of Sensitive Information vulnerability in multiple products
Cloud Foundry CredHub, versions prior to 2.5.10, connects to a MySQL database without TLS even when configured to use TLS.
network
high complexity
pivotal-software cloudfoundry CWE-319
7.4
2020-02-10 CVE-2019-20061 Cleartext Transmission of Sensitive Information vulnerability in Mfscripts Yetishare
The user-introduction email in MFScripts YetiShare v3.5.2 through v4.5.4 may leak the (system-picked) password if this email is sent in cleartext.
network
low complexity
mfscripts CWE-319
7.5
2020-02-05 CVE-2020-8507 Cleartext Transmission of Sensitive Information vulnerability in Rogersmedia Citytv Video
The Citytv Video application 4.08.0 for Android and 3.35 for iOS sends Unencrypted Analytics.
network
low complexity
rogersmedia CWE-319
7.5
2020-02-05 CVE-2020-8506 Cleartext Transmission of Sensitive Information vulnerability in Corusent Global TV
The Global TV application 2.3.2 for Android and 4.7.5 for iOS sends Unencrypted Analytics.
network
low complexity
corusent CWE-319
5.3
2020-01-26 CVE-2020-7984 Cleartext Transmission of Sensitive Information vulnerability in Solarwinds N-Central 12.2
SolarWinds N-central before 12.1 SP1 HF5 and 12.2 before SP1 HF2 allows remote attackers to retrieve cleartext domain admin credentials from the Agent & Probe settings, and obtain other sensitive information.
network
low complexity
solarwinds CWE-319
7.5