Show filters
303 Total Results
Displaying 111-120 of 303
Sort by:
Attacker Value
Unknown

CVE-2021-3774

Disclosure Date: November 05, 2021 (last updated February 23, 2025)
Meross Smart Wi-Fi 2 Way Wall Switch (MSS550X), on its 3.1.3 version and before, creates an open Wi-Fi Access Point without the required security measures in its initial setup. This could allow a remote attacker to obtain the Wi-Fi SSID as well as the password configured by the user from Meross app via Http/JSON plain request.
Attacker Value
Unknown

CVE-2021-42699

Disclosure Date: November 05, 2021 (last updated February 23, 2025)
The affected product is vulnerable to cookie information being transmitted as cleartext over HTTP. An attacker can capture network traffic, obtain the user’s cookie and take over the account.
Attacker Value
Unknown

CVE-2021-29753

Disclosure Date: November 04, 2021 (last updated February 23, 2025)
IBM Business Automation Workflow 18. 19, 20, 21, and IBM Business Process Manager 8.5 and d8.6 transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Attacker Value
Unknown

CVE-2021-43270

Disclosure Date: November 02, 2021 (last updated February 23, 2025)
Datalust Seq.App.EmailPlus (aka seq-app-htmlemail) 3.1.0-dev-00148, 3.1.0-dev-00170, and 3.1.0-dev-00176 can use cleartext SMTP on port 25 in some cases where encryption on port 465 was intended.
Attacker Value
Unknown

CVE-2021-39341

Disclosure Date: November 01, 2021 (last updated February 23, 2025)
The OptinMonster WordPress plugin is vulnerable to sensitive information disclosure and unauthorized setting updates due to insufficient authorization validation via the logged_in_or_has_api_key function in the ~/OMAPI/RestApi.php file that can used to exploit inject malicious web scripts on sites with the plugin installed. This affects versions up to, and including, 2.6.4.
0
Attacker Value
Unknown

CVE-2021-38418

Disclosure Date: October 21, 2021 (last updated February 23, 2025)
Delta Electronics DIALink versions 1.2.4.0 and prior runs by default on HTTP, which may allow an attacker to be positioned between the traffic and perform a machine-in-the-middle attack to access information without authorization.
Attacker Value
Unknown

CVE-2021-20599

Disclosure Date: October 14, 2021 (last updated February 23, 2025)
Cleartext Transmission of Sensitive InformationCleartext transmission of sensitive information vulnerability in MELSEC iQ-R series Safety CPU R08/16/32/120SFCPU firmware versions "26" and prior and MELSEC iQ-R series SIL2 Process CPU R08/16/32/120PSFCPU firmware versions "11" and prior allows a remote unauthenticated attacker to login to a target CPU module by obtaining credentials other than password.
Attacker Value
Unknown

CVE-2021-0296

Disclosure Date: October 13, 2021 (last updated February 23, 2025)
The Juniper Networks CTPView server is not enforcing HTTP Strict Transport Security (HSTS). HSTS is an optional response header which allows servers to indicate that content from the requested domain will only be served over HTTPS. The lack of HSTS may leave the system vulnerable to downgrade attacks, SSL-stripping man-in-the-middle attacks, and weakens cookie-hijacking protections. This issue affects Juniper Networks CTPView: 7.3 versions prior to 7.3R7; 9.1 versions prior to 9.1R3.
0
Attacker Value
Unknown

CVE-2021-39882

Disclosure Date: October 05, 2021 (last updated February 23, 2025)
In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user.
Attacker Value
Unknown

CVE-2020-20128

Disclosure Date: September 29, 2021 (last updated February 23, 2025)
LaraCMS v1.0.1 transmits sensitive information in cleartext which can be intercepted by attackers.