The application fails to prevent users from connecting to it over unencrypted connections. An attacker able to modify a
IBM Security Verify Governance, Identity Manager 10.0.1 stores sensitive information including user credentials in plain
In certain Secustation products the administrator account password can be read. This affects V2.5.5.3116-S50-SMA-B201711
The physical IoT device of the AliveCor's KardiaMobile, a smartphone-based personal electrocardiogram (EKG) has no encr
In JetBrains IntelliJ IDEA before 2022.3.1 the "Validate JSP File" action used the HTTP protocol to download required JA
In Core Utilities, there is a possible log information disclosure. This could lead to local information disclosure of se
IBM Security Guardium 10.5, 10.6, 11.0, 11.1, 11.2, 11.3, and 11.4 stores user credentials in plain clear text which can
Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier includes password parameters from the original build in r
Using its HSTS support, curl can be instructed to use HTTPS directly insteadof using an insecure clear-text HTTP step ev
TYPO3 is an open source web content management system. Prior to versions 7.6.57 ELTS, 8.7.47 ELTS, 9.5.34 ELTS, 10.4.29,
A vulnerability classified as problematic was found in Teleopti WFM up to 7.1.0. Affected by this vulnerability is an un
Jenkins Build Notifications Plugin 1.5.0 and earlier transmits tokens in plain text as part of the global Jenkins config
Jenkins OpsGenie Plugin 1.9 and earlier transmits API keys in plain text as part of the global Jenkins configuration for
This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in macOS Monterey
user_oidc is an OpenID Connect user backend for Nextcloud. In versions prior to 1.2.1 sensitive information such as the
In Jenkins Gitea Plugin 1.4.4 and earlier, the implementation of Gitea personal access tokens did not support credential
DJI drone devices sold in 2017 through 2022 broadcast unencrypted information about the drone operator's physical locati
A vulnerability was found in ISS BlackICE PC Protection. It has been declared as problematic. Affected by this vulnerabi
Philips Interoperability Solution XDS versions 2.5 through 3.11 and 2018-1 through 2021-1 are vulnerable to clear text t
HotelDruid Hotel Management Software v3.0.3 and below was discovered to have exposed session tokens in multiple links vi
On specific hardware platforms, on BIG-IP versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.7, 14.1.x before 14.1.5.1,
A vulnerability was found in whohas. It has been rated as problematic. This issue affects some unknown processing of the
Exposure of Sensitive Information in Samsung Dialer application?prior to SMR Aug-2022 Release 1 allows local attackers t
Sensitive information accessible by physical probing of JTAG interface for some Intel(R) Processors with SGX may allow a
Video Insight VMS versions prior to 7.8 allows a remote attacker to execute arbitrary code with the system user privileg
The affected products contain vulnerable firmware, which could allow an attacker to sniff the traffic and decrypt login
IBM API Connect 5.0.0.0 through 5.0.8.10 could potentially leak sensitive information or allow for data corruption due t
There is a Cleartext Transmission of Sensitive Information Vulnerability in Huawei Smartphone. Successful exploitation o
Cleartext Transmission of Sensitive InformationCleartext transmission of sensitive information vulnerability in MELSEC i
Cleartext transmission of sensitive information vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM
Cleartext transmission of sensitive information in Netop Vision Pro up to and including 9.7.1 allows a remote unauthenti
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR Nigh
When using http protocol, the user password is transmitted as a clear text parameter for which it is possible to be obta
Barco MirrorOp Windows Sender before 2.5.3.65 uses cleartext HTTP and thus allows rogue software upgrades. An attacker o
Delta Electronics DIALink versions 1.2.4.0 and prior runs by default on HTTP, which may allow an attacker to be position
Cleartext transmission of sensitive information vulnerability in synorelayd in Synology DiskStation Manager (DSM) before
Cleartext transmission of sensitive information vulnerability in synorelayd in Synology DiskStation Manager (DSM) before
The OptinMonster WordPress plugin is vulnerable to sensitive information disclosure and unauthorized setting updates due
Wrongthink peer-to-peer, end-to-end encrypted messenger with PeerJS and Axolotl ratchet. In wrongthink from version 2.0.
In Fibaro Home Center 2 and Lite devices in all versions provide a web based management interface over unencrypted HTTP
An issue was discovered in Emote Remote Mouse through 4.0.0.0. It uses cleartext HTTP to check, and request, updates. Th
The VeryFitPro (com.veryfit2hr.second) application 3.2.8 for Android does all communication with the backend API over cl
The update process of the Circle Parental Control Service on various NETGEAR routers allows remote attackers to achieve
Wokka Lokka Q50 devices through 2021-11-30 allow remote attackers (who know the SIM phone number and password) to listen
The affected Reolink P2P products do not sufficiently protect data transferred between the local device and Reolink serv
The API in the Push extension for MediaWiki through 1.35 used cleartext for ApiPush credentials, allowing for potential
A CWE-319: Cleartext transmission of sensitive information vulnerability exists in PowerLogic ION7400, ION7650, ION7700/
A CWE-319: Cleartext transmission of sensitive information vulnerability exists in PowerLogic ION7400, ION7650, ION83xx/
IBM API Connect V10 is impacted by insecure communications during database replication. As the data replication happens
Advantech Spectre RT ERT351 Versions 5.1.3 and prior logins and passwords are transmitted in clear text form, which may
Frequently Asked Questions
What is CWE-319?
CWE-319 (CWE-319) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-319?
There are 1,101 CVE records associated with CWE-319 in our database. Of these, 79 are critical severity, 341 are high severity, and 407 are medium severity.
How can I protect against CWE-319 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-319 using AI-powered security agents.
Detect CWE-319 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-319 vulnerabilities across your infrastructure.
Get Started