Show filters
206 Total Results
Displaying 41-50 of 206
Sort by:
Attacker Value
Unknown

CVE-2021-34825

Disclosure Date: June 17, 2021 (last updated February 22, 2025)
Quassel through 0.13.1, when --require-ssl is enabled, launches without SSL or TLS support if a usable X.509 certificate is not found on the local system.
Attacker Value
Unknown

CVE-2021-32612

Disclosure Date: June 16, 2021 (last updated February 22, 2025)
The VeryFitPro (com.veryfit2hr.second) application 3.2.8 for Android does all communication with the backend API over cleartext HTTP. This includes logins, registrations, and password change requests. This allows information theft and account takeover via network sniffing.
Attacker Value
Unknown

CVE-2021-22325

Disclosure Date: June 03, 2021 (last updated February 22, 2025)
There is an Information Disclosure vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may result in video streams being intercepted during transmission.
Attacker Value
Unknown

CVE-2021-23896

Disclosure Date: June 02, 2021 (last updated February 22, 2025)
Cleartext Transmission of Sensitive Information vulnerability in the administrator interface of McAfee Database Security (DBSec) prior to 4.8.2 allows an administrator to view the unencrypted password of the McAfee Insights Server used to pass data to the Insights Server. This user is restricted to only have access to DBSec data in the Insights Server.
Attacker Value
Unknown

CVE-2021-23018

Disclosure Date: June 01, 2021 (last updated February 22, 2025)
Intra-cluster communication does not use TLS. The services within the NGINX Controller 3.x before 3.4.0 namespace are using cleartext protocols inside the cluster.
Attacker Value
Unknown

CVE-2021-23846

Disclosure Date: May 28, 2021 (last updated February 22, 2025)
When using http protocol, the user password is transmitted as a clear text parameter for which it is possible to be obtained by an attacker through a MITM attack. This will be fixed starting from Firmware version 3.11.5, which will be released on the 30th of June, 2021.
Attacker Value
Unknown

CVE-2021-33408

Disclosure Date: May 27, 2021 (last updated February 22, 2025)
Local File Inclusion vulnerability in Ab Initio Control>Center before 4.0.2.6 allows remote attackers to retrieve arbitrary files. Fixed in v4.0.2.6 and v4.0.3.1.
Attacker Value
Unknown

CVE-2021-25643

Disclosure Date: May 26, 2021 (last updated February 22, 2025)
An issue was discovered in Couchbase Server 5.x and 6.x before 6.5.2 and 6.6.x before 6.6.2. Internal users with administrator privileges, @cbq-engine-cbauth and @index-cbauth, leak credentials in cleartext in the indexer.log file when they make a /listCreateTokens, /listRebalanceTokens, or /listMetadataTokens call.
Attacker Value
Unknown

CVE-2021-27924

Disclosure Date: May 19, 2021 (last updated February 22, 2025)
An issue was discovered in Couchbase Server 6.x through 6.6.1. The Couchbase Server UI is insecurely logging session cookies in the logs. This allows for the impersonation of a user if the log files are obtained by an attacker before a session cookie expires.
Attacker Value
Unknown

CVE-2020-27185

Disclosure Date: May 14, 2021 (last updated February 22, 2025)
Cleartext transmission of sensitive information via Moxa Service in NPort IA5000A series serial devices. Successfully exploiting the vulnerability could enable attackers to read authentication data, device configuration, and other sensitive data transmitted over Moxa Service.