The affected product is vulnerable due to cleartext transmission of credentials seen in the CIMPLICITY network, which ca
An issue was discovered in Rhinode Trading Paints through 2.0.36. TP Updater.exe uses cleartext HTTP to check, and reque
ISaGRAF Workbench communicates with Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x using TCP/IP. This communic
GE UR firmware versions prior to version 8.1x web server interface is supported on UR over HTTP protocol. It allows sens
Philips Vue PACS versions 12.2.x.x and prior transmits sensitive or security-critical data in cleartext in a communicati
Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 passwords are sent as plaintext during
An information disclosure vulnerability exists in the Web Application functionality of Moxa MXView Series 3.2.4. Network
Cleartext transmission of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Linux, W
Cleartext transmission of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Windows)
A cleartext transmission of sensitive information vulnerability exists in the OAS Engine configuration communications fu
Cleartext transmission of sensitive information vulnerability exists in STARDOM FCN Controller and FCJ Controller R1.01
Omron CS series, CJ series, and CP series PLCs through 2022-05-18 use cleartext passwords. They feature a UM Protection
In FiberHome VDSL2 Modem HG150-Ub_V3.0, Credentials of Admin are submitted in URL, which can be logged/sniffed.
AutomationDirect C-more EA9 HTTP webserver uses an insecure mechanism to transport credentials from client to web server
The Simple Single Sign On WordPress plugin through 4.1.0 leaks its OAuth client_secret, which could be used by attackers
In curl before 7.86.0, the HSTS check could be bypassed to trick it into staying with HTTP. Using its HSTS support, curl
UPSMON PRO transmits sensitive data in cleartext over HTTP protocol. An unauthenticated remote attacker can exploit this
Web Based Quiz System v1.0 transmits user passwords in plaintext during the authentication process, allowing attackers t
A vulnerability exists in curl <7.87.0 HSTS check that could be bypassed to trick it to keep using HTTP. Using its HSTS
An issue was discovered in HTCondor 9.0.x before 9.0.10 and 9.1.x before 9.5.1. An attacker who can capture HTCondor net
LRM version 2.4 and lower does not implement TLS encryption. A malicious actor can MITM attack sensitive data in-transit
Fresenius Kabi Agilia Link + version 3.0 does not enforce transport layer encryption. Therefore, transmitted data may be
Delta Electronics DIAEnergie (Version 1.7.5 and prior) is vulnerable to cleartext transmission as the web application ru
A Cleartext Transmission of Sensitive Information vulnerability in SUSE Rancher, Rancher allows attackers on the network
This advisory documents the impact of an internally found vulnerability in Arista EOS state streaming telemetry agent Te
Cleartext transmission of sensitive information vulnerability in authentication management in Synology Note Station Clie
IBM Spectrum Protect Plus 10.1.0 through 10.1.12 discloses sensitive information due to unencrypted data being used in
Jenkins Active Directory Plugin 2.25 and earlier does not encrypt the transmission of data between the Jenkins controlle
An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. The transmission of cleartext LDAP bind c
The Trend Controls IC protocol through 2022-05-06 allows Cleartext Transmission of Sensitive Information. According to F
A cleartext transmission of sensitive information exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 relating to Oauth token
The login password of the web administrative dashboard in Arcadyan Wifi routers VRV9506JAC23 is sent in cleartext, allow
Insights for Vulnerability Remediation (IVR) is vulnerable to man-in-the-middle attacks that may lead to information dis
This advisory documents the impact of an internally found vulnerability in Arista EOS state streaming telemetry agent Te
IBM Guardium Data Encryption (GDE) 5.0.0.2 and 5.0.0.3 could allow a remote attacker to obtain sensitive information, ca
An issue was discovered in Cobbler through 3.3.1. Routines in several files use the HTTP protocol instead of the more se
An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4. There is Cleartext Transmission of Sensitive Information.
IBM Security Identity Governance and Intelligence 5.2.4, 5.2.5, and 5.2.6 could allow a remote attacker to obtain sensit
Delta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 was discovered to transmit and store sensitive informatio
An information disclosure vulnerability exists in the License registration functionality of Bachmann Visutec GmbH Atvise
The server in Citilog 8.0 allows an attacker (in a man in the middle position between the server and its smart camera Ax
EspoCRM version 7.1.8 is vulnerable to Missing Secure Flag allowing the browser to send plain text cookies over an insec
The Passster WordPress plugin before 3.5.5.5.2 stores the password inside a cookie named "passster" using base64 encodin
PC Keyboard WiFi & Bluetooth allows an attacker (in a man-in-the-middle position between the server and a connected devi
Lazy Mouse allows an attacker (in a man in the middle position between the server and a connected device) to see all dat
Telepad allows an attacker (in a man-in-the-middle position between the server and a connected device) to see all data (
Softing Secure Integration Server V1.22 is vulnerable to authentication bypass via a machine-in-the-middle attack. The d
An issue was discovered in Luna Simo PPR1.180610.011/202001031830. It sends the following Personally Identifiable Inform
Xiongmai Camera XM-JPR2-LX V4.02.R12.A6420987.10002.147502.00000 is vulnerable to plain-text traffic sniffing.
Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 inadvertently disclose server-side sensitive
Frequently Asked Questions
What is CWE-319?
CWE-319 (CWE-319) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-319?
There are 1,101 CVE records associated with CWE-319 in our database. Of these, 79 are critical severity, 341 are high severity, and 407 are medium severity.
How can I protect against CWE-319 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-319 using AI-powered security agents.
Detect CWE-319 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-319 vulnerabilities across your infrastructure.
Get Started