Search Results (4765 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-18176 2 Ibm, Redhat 3 Financial Transaction Manager, Financial Transaction Manager Ftmfor Redhat Openshift, Openshift 2026-10-07 7.4 High
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive information.
CVE-2025-5154 2 Phonepe, Phonepe App 2 Phonepe, Phonepe App 2026-10-07 2.3 Low
A vulnerability was identified in PhonePe App 25.03.21.0 on Android. This affects an unknown function of the file /data/data/com.phonepe.app/databases/ of the component SQLite Database. The manipulation leads to cleartext storage in a file or on disk. The attack needs to be performed locally. The exploit is publicly available and might be used. The actual existence of this vulnerability is currently in question. The root-requirement of the attack is reflected by the CVSS vector attribute PR:H. The vendor explains: "[A]s per the PoC this vulnerability needs a rooted device to exploit. PhonePe does not consider vulnerabilities found in rooted device as valid because there is not real-world exploit scenario."
CVE-2026-104706 1 Mitel 1 Mivoice Office 400 2026-10-06 N/A
DigitalCanion has discovered a path traversal vulnerability that allows to view or download sensitive system files over the portal https://<ip>:8443 via menus Administration -> View Logs
CVE-2026-105766 1 Chainguard 1 Chainguard Academy (edu) 2026-10-06 3.1 Low
Use of the backend-facing $scheme variable in the trailing-slash directory redirect in nginx.conf of Chainguard Academy (edu) from commit 0b75ff98057f69b044a3e7194e428066ac5ad0d4 before commit 93dc0e50739c225f5aee2e803800a47fc0feb906 allows an on-path network attacker to read or modify documentation content served to a victim via an HTTPS request for a slashless directory path, because TLS terminates at the load balancer in front of Nginx and the resulting 301 response redirects the client to a plaintext http:// URL. Browsers that ship the HSTS preload list are not affected, because the .dev top-level domain is preloaded; clients that do not enforce HSTS, such as command-line HTTP clients and scripts that follow redirects, are affected.
CVE-2026-104806 1 Mitel 1 Mivoice Office 400 2026-10-06 N/A
DigitalCanion has discovered a path traversal vulnerability that allows an attacker to access files outside of the intended directory. The specific flaw exists within the Maintenance → System Logs functionality of the web management portal listening on TCP port 443. The application fails to properly validate user-supplied file paths, allowing an attacker to manipulate the requested path and traverse the underlying directory structure. By exploiting this vulnerability, an attacker can access and download files located outside the intended system logs directory, including potentially sensitive system and application files.
CVE-2026-76114 1 Dell 2 Policy Manager For Secure Connect Gateway, Secure Connect Gateway Policy Manager 2026-10-06 5.9 Medium
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Cleartext Transmission of Sensitive Information vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
CVE-2026-67105 1 Hcltech 1 Bigfix Service Management 2026-10-05 7.4 High
HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to intercept unencrypted HTTP traffic between backend services, enabling the extraction of sensitive data and potential man-in-the-middle (MitM) attacks.
CVE-2026-105179 1 Sourcecodester 1 Drug Recommendation System 2026-10-05 2.7 Low
A weakness has been identified in SourceCodester Drug Recommendation System 1.0. This affects an unknown function of the file Admin/add_user.php of the component Password Handler. Executing a manipulation of the argument Password can lead to missing encryption of sensitive data. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.
CVE-2026-104810 2026-10-05 N/A
This vulnerability allows remote attackers to delete sensitive files on vulnerable installations of Mitel MiVoice Office 400. Authentication is required to exploit this vulnerability. The specific flaw exists within the web portal listening on TCP port 443, under Maintenance → File Management → File Browser, which is affected by a directory traversal vulnerability. By exploiting this vulnerability, an authenticated attacker can access and delete files outside of the intended directory, including files belonging to the Mitel application and the underlying Linux system. Deleting critical system or application files can result in a denial-of-service condition affecting the underlying system.
CVE-2026-64893 1 Johnson Controls 1 Easyio Neo 2026-10-02 N/A
- Cleartext Transmission of Sensitive Information vulnerability in Johnson Controls EasyIO NEO allows - Man In the Middle Attack. This issue affects EasyIO NEO: before 3.3b25.
CVE-2026-103097 2 Geovision, Geovision Inc. 2 Gv-eye, Gv-eye 2026-10-02 7.5 High
An API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may allow unauthorized users to extract and misuse the key.
CVE-2026-103096 2 Geovision, Geovision Inc. 2 Gv-eye, Gv-eye 2026-10-02 7.5 High
API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may allow unauthorized users to extract and misuse the key.
CVE-2026-103098 2 Geovision, Geovision Inc. 2 Gv-eye, Gv-eye 2026-10-02 7.5 High
Transmission of a sensitive key in the URL over an unencrypted HTTP connection.  The request is sent over HTTP rather than HTTPS, meaning the key is transmitted in plaintext across the network. An attacker with the ability to monitor network traffic could intercept the request and obtain the key
CVE-2026-102670 1 Joyland 1 Joyland.ai 2026-10-02 4.3 Medium
Joyland AI app explicitly permits cleartext HTTP traffic on Android 9+ where the default is to block it.
CVE-2026-55394 1 Teledyne Flir 1 Aware2 2026-10-02 N/A
Unencrypted traffic in the 802.11 network of Teledyne FLIR Aware2 versions through 6.9.0.2 allows adjacent unauthenticated attackers to intercept, hijack, or modify session traffic against Teledyne FLIR PackBot robots running this software via sniffing or hijacking network traffic.
CVE-2026-55396 1 Teledyne Flir 1 Aware2 2026-10-02 N/A
Cleartext transmission without a cryptographic integrity check in operator control unit to robot UDP traffic in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows adjacent unauthenticated attackers to intercept, hijack, or modify control traffic against Teledyne FLIR PackBot and FirstLook robots running this software via sniffing or hijacking network traffic.
CVE-2026-14984 1 Teledyne Flir 1 Aware2 2026-10-02 N/A
Cleartext transmission in the primary control endpoints of Teledyne FLIR Aware2 versions through 6.9.0.2 allows remote unauthenticated attackers to intercept, hijack, or modify session traffic against Teledyne FLIR PackBot robots running this software via sniffing or hijacking network traffic.
CVE-2026-82826 1 Hitachi Industrial Equipment Systems 1 Hitachi Coding Software Suite 2026-10-01 7.5 High
Hitachi Coding Software Suite contains a vulnerability related to the Cleartext Transmission of Sensitive Information which allows an attacker to eavesdrop on with authentication credentials and sensitive data in transit. This issue affects Hitachi Coding Software Suite: through 3.3.0.
CVE-2026-81691 1 Jahlives 1 Openssl Encrypt 2026-10-01 7.5 High
openssl_encrypt versions before 1.4.9 fail to validate server URLs in login and register_with_email functions, accepting unencrypted http:// URLs and unconfigured hosts. Attackers on the network path can intercept cleartext credentials including client_id, passwords, and JWTs to achieve full keyserver account takeover.
CVE-2026-81688 1 Jahlives 1 Openssl Encrypt 2026-10-01 7.5 High
openssl_encrypt versions before 1.4.9 store an unkeyed SHA-256 hash of the plaintext in the cleartext file header metadata. Attackers can read this hash without the password to confirm guessed plaintexts offline or fingerprint identical plaintexts across separately-encrypted files.