Show filters
290 Total Results
Displaying 101-110 of 290
Sort by:
Attacker Value
Unknown
CVE-2021-43270
Disclosure Date: November 02, 2021 (last updated February 23, 2025)
Datalust Seq.App.EmailPlus (aka seq-app-htmlemail) 3.1.0-dev-00148, 3.1.0-dev-00170, and 3.1.0-dev-00176 can use cleartext SMTP on port 25 in some cases where encryption on port 465 was intended.
0
Attacker Value
Unknown
CVE-2021-39341
Disclosure Date: November 01, 2021 (last updated February 23, 2025)
The OptinMonster WordPress plugin is vulnerable to sensitive information disclosure and unauthorized setting updates due to insufficient authorization validation via the logged_in_or_has_api_key function in the ~/OMAPI/RestApi.php file that can used to exploit inject malicious web scripts on sites with the plugin installed. This affects versions up to, and including, 2.6.4.
0
Attacker Value
Unknown
CVE-2021-38418
Disclosure Date: October 21, 2021 (last updated February 23, 2025)
Delta Electronics DIALink versions 1.2.4.0 and prior runs by default on HTTP, which may allow an attacker to be positioned between the traffic and perform a machine-in-the-middle attack to access information without authorization.
0
Attacker Value
Unknown
CVE-2021-20599
Disclosure Date: October 14, 2021 (last updated February 23, 2025)
Cleartext Transmission of Sensitive InformationCleartext transmission of sensitive information vulnerability in MELSEC iQ-R series Safety CPU R08/16/32/120SFCPU firmware versions "26" and prior and MELSEC iQ-R series SIL2 Process CPU R08/16/32/120PSFCPU firmware versions "11" and prior allows a remote unauthenticated attacker to login to a target CPU module by obtaining credentials other than password.
0
Attacker Value
Unknown
CVE-2021-0296
Disclosure Date: October 13, 2021 (last updated February 23, 2025)
The Juniper Networks CTPView server is not enforcing HTTP Strict Transport Security (HSTS). HSTS is an optional response header which allows servers to indicate that content from the requested domain will only be served over HTTPS. The lack of HSTS may leave the system vulnerable to downgrade attacks, SSL-stripping man-in-the-middle attacks, and weakens cookie-hijacking protections. This issue affects Juniper Networks CTPView: 7.3 versions prior to 7.3R7; 9.1 versions prior to 9.1R3.
0
Attacker Value
Unknown
CVE-2021-39882
Disclosure Date: October 05, 2021 (last updated February 23, 2025)
In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user.
0
Attacker Value
Unknown
CVE-2020-20128
Disclosure Date: September 29, 2021 (last updated February 23, 2025)
LaraCMS v1.0.1 transmits sensitive information in cleartext which can be intercepted by attackers.
0
Attacker Value
Unknown
CVE-2021-22946
Disclosure Date: September 29, 2021 (last updated February 23, 2025)
A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLUSESSL_ALL` withlibcurl). This requirement could be bypassed if the server would return a properly crafted but perfectly legitimate response.This flaw would then make curl silently continue its operations **withoutTLS** contrary to the instructions and expectations, exposing possibly sensitive data in clear text over the network.
0
Attacker Value
Unknown
CVE-2021-39342
Disclosure Date: September 29, 2021 (last updated February 23, 2025)
The Credova_Financial WordPress plugin discloses a site's associated Credova API account username and password in plaintext via an AJAX action whenever a site user goes to checkout on a page that has the Credova Financing option enabled. This affects versions up to, and including, 1.4.8.
0
Attacker Value
Unknown
CVE-2021-36165
Disclosure Date: September 28, 2021 (last updated February 23, 2025)
RICON Industrial Cellular Router S9922L 16.10.3(3794) is affected by cleartext storage of sensitive information and sends username and password as base64.
0