CS2 Network P2P through 3.x, as used in millions of Internet of Things devices, suffers from an information exposure fla
An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 9716
An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 a
Quick Heal Total Security before version 19.0 transmits quarantine and sysinfo files via clear text.
In Solstice Pod before 3.0.3, the web services allow users to connect to them over unencrypted channels via the Browser
The Global TV application 2.3.2 for Android and 4.7.5 for iOS sends Unencrypted Analytics.
Jenkins Logstash Plugin 2.3.1 and earlier transmits configured credentials in plain text as part of its global Jenkins c
Jenkins Repository Connector Plugin 1.2.6 and earlier transmits configured credentials in plain text as part of its glob
Jenkins Sonar Quality Gates Plugin 1.3.1 and earlier transmits configured credentials in plain text as part of its globa
Jenkins Quality Gates Plugin 2.5 and earlier transmits configured credentials in plain text as part of its global Jenkin
Jenkins OpenShift Deployer Plugin 1.2.0 and earlier transmits configured credentials in plain text as part of its global
"If port encryption is not enabled on the Domino Server, HCL Nomad on Android and iOS Platforms will communicate in clea
A vulnerability has been identified in Siveillance Video Client (All versions). In environments where Windows NTLM authe
BigFix Inventory up to v10.0.2 does not set the secure flag for the session cookie in an https session, which can cause
An information disclosure vulnerability exists in the Web Manager and telnet CLI functionality of Lantronix XPort EDGE 3
In versions prior to 3.3.0, the NGINX Controller is configured to communicate with its Postgres database server over une
The DuoConnect client enables users to establish SSH connections to hosts protected by a DNG instance. When a user initi
This affects all versions of package com.mintegral.msdk:alphab. The Android SDK distributed by the company contains mali
Jenkins Backlog Plugin 2.4 and earlier transmits configured credentials in plain text as part of job configuration forms
Jenkins DeployHub Plugin 8.0.14 and earlier transmits configured credentials in plain text as part of job configuration
Jenkins Skytap Cloud CI Plugin 2.07 and earlier transmits configured credentials in plain text as part of job configurat
BIOTRONIK CardioMessenger II, The affected products transmit credentials in clear-text prior to switching to an encrypte
Jenkins Stash Branch Parameter Plugin 0.3.0 and earlier transmits configured passwords in plain text as part of its glob
Jenkins SoapUI Pro Functional Testing Plugin 1.5 and earlier transmits project passwords in its configuration in plain t
A spoofing vulnerability exists in Microsoft Visual Studio as it includes a reply URL that is not secured by SSL, aka 'M
In versions 7.1.5-7.1.8, when a user connects to a VPN using BIG-IP Edge Client over an unsecure network, BIG-IP Edge Cl
Moxa IKS-G6824A series Versions 4.5 and prior, EDS-405A series Version 3.8 and prior, EDS-408A series Version 3.8 and pr
Pivotal Apps Manager Release, versions 665.0.x prior to 665.0.28, versions 666.0.x prior to 666.0.21, versions 667.0.x p
Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an insecure protocol to fet
Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior use a proprietary monitoring protocol that does not p
Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior use a proprietary configuration protocol that does no
ONTAP Select Deploy administration utility versions 2.2 through 2.12.1 transmit credentials in plaintext.
The Customer's Tomedo Server in Version 1.7.3 communicates to the Vendor Tomedo Server via HTTP (in cleartext) that can
Certain D-Link devices have a hardcoded Alphanetworks user account with TELNET access because of /etc/config/image_sign
Due to unencrypted and unauthenticated data communication, the wireless barcode scanner Inateck BCST-60 is prone to keys
An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL
An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Because o
An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. By default, the commu
Due to unencrypted and unauthenticated data communication, the wireless presenter Inateck WP2002 is prone to keystroke i
Due to unencrypted and unauthenticated data communication, the wireless presenter Inateck WP1001 v1.3C is prone to keyst
Due to unencrypted and unauthenticated data communication, the wireless presenter Logitech R700 Laser Presentation Remot
The Nulock application 1.5.0 for mobile devices sends a cleartext password over Bluetooth, which allows remote attackers
Viber through 11.7.0.5 allows a remote attacker who can capture a victim's internet traffic to steal their Viber account
A flaw was found in rhn-proxy. This vulnerability may allow the rhn-proxy to transmit user credentials in clear-text whe
Using ktlint to download and execute custom rulesets can result in arbitrary code execution as the served jars can be co
Eclipse hawkBit versions prior to 0.3.0M2 resolved Maven build artifacts for the Vaadin based UI over HTTP instead of HT
A cleartext transmission of sensitive information vulnerability in Fortinet FortiManager 5.2.0 through 5.2.7, 5.4.0 and
An authentication flaw in Shenzhen Yunni Technology iLnkP2P allows remote attackers to actively intercept user-to-device
JetBrains Kotlin versions before 1.3.30 were resolving artifacts using an http connection during the build process, pote
JetBrains Ktor framework (created using the Kotlin IDE template) versions before 1.1.0 were resolving artifacts using an
Frequently Asked Questions
What is CWE-319?
CWE-319 (CWE-319) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-319?
There are 1,101 CVE records associated with CWE-319 in our database. Of these, 79 are critical severity, 341 are high severity, and 407 are medium severity.
How can I protect against CWE-319 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-319 using AI-powered security agents.
Detect CWE-319 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-319 vulnerabilities across your infrastructure.
Get Started