Dell PowerScale OneFS 8.1.0 - 9.1.0 contains an LDAP Provider inability to connect over TLSv1.2 vulnerability. It may ma
pgsync before 0.6.7 is affected by Information Disclosure of sensitive information. Syncing the schema with the --schema
In JetBrains WebStorm before 2021.1, HTTP requests were used instead of HTTPS.
Cleartext transmission of sensitive information via Moxa Service in NPort IA5000A series serial devices. Successfully ex
Quassel through 0.13.1, when --require-ssl is enabled, launches without SSL or TLS support if a usable X.509 certificate
An issue was discovered in Arm Mbed TLS before 2.23.0. A remote attacker can recover plaintext because a certain Lucky 1
While investigating DIRSTUDIO-1219 it was noticed that configured StartTLS encryption was not applied when any SASL auth
A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FT
LaraCMS v1.0.1 transmits sensitive information in cleartext which can be intercepted by attackers.
Datalust Seq.App.EmailPlus (aka seq-app-htmlemail) 3.1.0-dev-00148, 3.1.0-dev-00170, and 3.1.0-dev-00176 can use clearte
The ksmbd server through 3.4.2, as used in the Linux kernel through 5.15.8, sometimes communicates in cleartext even tho
Trendnet AC2600 TEW-827DRU version 2.08B01 contains an security flaw in the web interface. HTTPS is not enabled on the d
Netgear Nighthawk R6700 version 1.0.4.120 does not utilize secure communication methods to the web interface. By default
Netgear Nighthawk R6700 version 1.0.4.120 does not utilize secure communication methods to the SOAP interface. By defaul
Intra-cluster communication does not use TLS. The services within the NGINX Controller 3.x before 3.4.0 namespace are us
The Juniper Networks CTPView server is not enforcing HTTP Strict Transport Security (HSTS). HSTS is an optional response
Meross Smart Wi-Fi 2 Way Wall Switch (MSS550X), on its 3.1.3 version and before, creates an open Wi-Fi Access Point with
A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.42), Climatix POL909 (AWM module
In the management interface on TP-Link Archer C5v 1.7_181221 devices, credentials are sent in a base64 format over clear
An issue was discovered in the eGeeTouch 3rd Generation Travel Padlock application for Android. The lock sends a pairing
Netgear RAX43 version 1.0.3.96 does not utilize secure communications to the web interface. By default, all communicatio
For MongoDB Ops Manager versions prior to and including 4.2.24 with multiple OM application servers, that have SSL turne
SITEL CAP/PRX firmware version 5.2.01 allows an attacker with access to the local network of the device to obtain the au
Local File Inclusion vulnerability in Ab Initio Control>Center before 4.0.2.6 allows remote attackers to retrieve arbitr
IBM QRadar SIEM 7.3 and 7.4 uses less secure methods for protecting data in transit between hosts when encrypt host conn
OctopusDSC is a PowerShell module with DSC resources that can be used to install and configure an Octopus Deploy Server
IBM Emptoris Strategic Supply Management 10.1.0, 10.1.1, and 10.1.3 transmits sensitive information in HTTP GET request
IBM Security Identity Governance and Intelligence 5.2.6 could allow a remote attacker to obtain sensitive information, c
IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a remote attacker to obtain sensitive information, cau
Cleartext transmission of sensitive information in Agora Video SDK prior to 3.1 allows a remote attacker to obtain acces
A smart proxy that provides a restful API to various sub-systems of the Foreman is affected by the flaw which can cause
The NPort IA5000A Series devices use Telnet as one of the network device management services. Telnet does not support th
IBM Cloud Pak for Security (CP4S) 1.4.0.0, 1.5.0.0, 1.5.0.1, 1.6.0.0, and 1.6.0.1 could allow a remote attacker to obtai
An issue was discovered in Couchbase Server 6.x through 6.6.1. The Couchbase Server UI is insecurely logging session coo
A Cleartext Transmission of Sensitive Information vulnerability in B. Braun SpaceCom2 prior to 012U000062 allows a remot
Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances, such as a certain situation
IBM Business Automation Workflow 18. 19, 20, 21, and IBM Business Process Manager 8.5 and d8.6 transmits or stores authe
IBM QRadar Network Security 5.4.0 and 5.5.0 transmits sensitive or security-critical data in cleartext in a communicatio
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information,
The affected product is vulnerable to cookie information being transmitted as cleartext over HTTP. An attacker can captu
The Taidii Diibear Android application 2.4.0 and all its derivatives allow attackers to view private chat messages and m
In Harbor 2.0 before 2.0.5 and 2.1.x before 2.1.2 the catalog’s registry API is exposed on an unauthenticated path.
An issue was discovered in Emote Remote Mouse through 4.0.0.0. Attackers can maximize or minimize the window of a runnin
Agenzia delle Entrate Desktop Telematico 1.0.0 contacts the jws.agenziaentrate.it server over cleartext HTTP, which allo
There is an Information Disclosure vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may
MagicMotion Flamingo 2 lacks BLE encryption, enabling data sniffing and packet forgery.
When curl is instructed to get content using the metalink feature, and a user name and password are used to download the
In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Ser
RICON Industrial Cellular Router S9922L 16.10.3(3794) is affected by cleartext storage of sensitive information and send
The Credova_Financial WordPress plugin discloses a site's associated Credova API account username and password in plaint
Frequently Asked Questions
What is CWE-319?
CWE-319 (CWE-319) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-319?
There are 1,101 CVE records associated with CWE-319 in our database. Of these, 79 are critical severity, 341 are high severity, and 407 are medium severity.
How can I protect against CWE-319 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-319 using AI-powered security agents.
Detect CWE-319 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-319 vulnerabilities across your infrastructure.
Get Started