An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. The is
There are few web pages associated with the genie app on the Netgear WNDR4500 running firmware version V1.0.1.40_1.0.687
Intuit Lacerte 2017 for Windows in a client/server environment transfers the entire customer list in cleartext over SMB,
An issue was discovered in the Daimler Mercedes-Benz Me app 2.11.0-846 for iOS. The encrypted Connected Vehicle API data
The template upload API endpoint accepted requests from different domain when sent in conjunction with ARP spoofing + ma
There is a SRTP icon display vulnerability in Huawei eSpace product. An unauthenticated, remote attacker launches man-in
Improper restriction of communication channel to intended endpoints vulnerability in HTTP daemon in Synology SSL VPN Cli
Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project se
SimpliSafe Original has Unencrypted Keypad Transmissions, which allows physically proximate attackers to discover the PI
Abbott Laboratories Accent and Anthem pacemakers manufactured prior to Aug 28, 2017 transmit unencrypted patient informa
An issue was discovered on Vgate iCar 2 Wi-Fi OBD2 Dongle devices. The data packets that are sent between the iOS or And
The QBee MultiSensor Camera through 4.16.4 accepts unencrypted network traffic from clients (such as the QBee Cam applic
When an SRX Series device is configured to use HTTP/HTTPS pass-through authentication services, a client sending authent
Samsung Display Solutions App before 3.02 for Android allows man-in-the-middle attackers to spoof B2B content by leverag
A Cleartext Transmission of Sensitive Information issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1
ikst versions before 1.1.2 download resources over HTTP, which leaves it vulnerable to MITM attacks.
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to obtain sensitive information, ca
IBM i2 Enterprise Insight Analysis 2.1.7 could allow a remote attacker to obtain sensitive information, caused by the fa
A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attack
A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attack
The SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) stores the username and
The Themes App Honor 8 Lite Huawei mobile phones with software of versions before Prague-L31C576B172, versions before Pr
The IIOP OpenJDK Subsystem in WildFly before version 14.0.0 does not honour configuration when SSL transport is required
The Google Cardboard application 1.8 for Android and 1.2 for iOS sends potentially private cleartext information to the
Communications between Medtronic MiniMed MMT pumps and wireless accessories are transmitted in cleartext. A sufficiently
SimpliSafe Original has Unencrypted Sensor Transmissions, which allows physically proximate attackers to obtain potentia
Schneider Electric Ampla MES 6.4 provides capability to interact with data from third party databases. When connectivity
In the "NQ Contacts Backup & Restore" application 1.1 for Android, no HTTPS is used for transmitting login and synced us
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, an undocumented, root-privilege administration web
An issue was discovered on Dahua DHI-HCVR7216A-S3 3.210.0001.10 build 2016-06-06 devices. The Dahua DVR Protocol, which
IBM Integration Bus 9.0 and 10.0 transmits user credentials in plain in clear text which can be read by an attacker usin
During a routine security analysis, it was found that one of the ports in Apache Impala (incubating) 2.7.0 to 2.8.0 sent
Shotwell version 0.24.4 or earlier and 0.25.3 or earlier is vulnerable to an information disclosure in the web publishin
Mirasys Video Management System (VMS) 6.x before 6.4.6, 7.x before 7.5.15, and 8.x before 8.1.1 has a login process in w
An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "MobileBackup" comp
The Vibease Wireless Remote Vibrator app for Android and the Vibease Chat app for iOS use cleartext to exchange messages
Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows attackers to eavesdrop and tamper with updates by leveragi
IBM Tivoli Monitoring Portal V6 client could allow a local attacker to gain elevated privileges for IBM Tivoli Monitorin
A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unaut
An Information Exposure issue was discovered in ProMinent MultiFLEX M10a Controller web interface. When an authenticated
An issue was discovered in Enigmail before 1.9.9. A remote attacker can obtain cleartext content by sending an encrypted
Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, a
An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "iTunes Store" co
An issue was discovered on OnePlus One, X, 2, 3, and 3T devices. Due to a lenient updater-script in the OnePlus OTA imag
An issue was discovered on OnePlus One and X devices. Due to a lenient updater-script on the OnePlus One and X OTA image
The client-forwarder in Elastic Cloud Enterprise versions prior to 1.0.2 do not properly encrypt traffic to ZooKeeper. I
An unintended cleartext issue exists in Go before 1.8.4 and 1.9.x before 1.9.1. RFC 4954 requires that, during SMTP, the
IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) transmits sensitive or security-critical data in cleartext
kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full htt
An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the "Captive Netwo
Frequently Asked Questions
What is CWE-319?
CWE-319 (CWE-319) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-319?
There are 1,101 CVE records associated with CWE-319 in our database. Of these, 79 are critical severity, 341 are high severity, and 407 are medium severity.
How can I protect against CWE-319 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-319 using AI-powered security agents.
Detect CWE-319 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-319 vulnerabilities across your infrastructure.
Get Started