A vulnerability was detected in Mendi Neurofeedback Headset V4. Affected by this vulnerability is an unknown functionali
A flaw has been found in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. This affects an unknown part of the component Car
An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.core.mail.backends.smtp.EmailBackend`
rclone before 1.74.4 fails to strip the X-Amz-Security-Token header when an S3 redirect changes scheme from HTTPS to HTT
An attacker with a network connection could detect credentials in clear text.
This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the p
This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the t
The RF communication protocol in the Micca KE700 car alarm system does not encrypt its data frames. An attacker with a r
This vulnerability exists in e-Sushrut due to exposure of OTPs in plaintext within API responses. A remote attacker coul
STER uses unencrypted TCP traffic to transmit data over the network. It allows an attacker to conduct a Man-In-The-Middl
This vulnerability exists in GX Earth ONT models due to the transmission of user credentials in plaintext over HTTP in i
Overview: A vulnerability has been found in FAST/TOOLS and CI Server. The web server may return a response containing t
oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, auth.Client follows the realm URL from a registry's
The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HT
stigmem-node contains an insecure default configuration vulnerability that allows federation traffic to traverse network
A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During communication with a th
Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. The
When OpenSSL is unavailable on the server, the extension transmits TYPO3 system information in cleartext instead of encr
Cleartext Transmission of Sensitive Information, Use of Hard-coded Credentials vulnerability in Ataturk University ATA-A
An issue in MikroTik RouterOS v.7.14.2 and SwOS v.2.18 exposes the WebFig management interface over cleartext HTTP by de
CloudClassroom-PHP-Project v1.0 is affected by an insecure credential transmission vulnerability. The application transm
An issue was discovered on COROS PACE 3 devices through 3.0808.0. It implements a function to connect the watch to a WLA
TM2 Monitoring v3.04 contains an authentication bypass and plaintext credential disclosure.
Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the cluster manager component when requesting
Cleartext Transmission of Sensitive Information vulnerability in Dolusoft Omaspot allows Interception, Privilege Escalat
In the ConnectWise Automate Agent, communications could be configured to use HTTP instead of HTTPS. In such cases, an on
Infoblox BloxOne v2.4 was discovered to contain a business logic flaw due to thick client vulnerabilities.
On affected platforms running Arista EOS with secure Vxlan configured, restarting the Tunnelsec agent will result in pac
The mobile application is configured to allow clear text traffic to all domains and communicates with an API server over
Incorrect Use of Privileged APIs, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials
In Progress® Telerik® Report Server, versions prior to 2025 Q1 (11.0.25.211) when using the older .NET Framework impleme
Aikaan IoT management platform v3.25.0325-5-g2e9c59796 sends a newly generated password to users in plaintext via email
An issue was discovered in the method push.lite.avtech.com.AvtechLib.GetHttpsResponse in AVTECH EagleEyes Lite 2.0.0, th
GOM Player 2.3.90.5360 contains a remote code execution vulnerability in its Internet Explorer component that allows att
Intelbras IWR 3000N 1.9.8 exposes the Wi-Fi password in plaintext via the /api/wireless endpoint. Any unauthenticated us
When using domain users as BRAIN2 users, communication with Active Directory services is unencrypted. This can lead to t
ReyeeOS 1.204.1614 contains an unencrypted CWMP communication vulnerability that allows attackers to intercept and manip
Cognex In-Sight Explorer and In-Sight Camera Firmware expose a proprietary protocol on TCP port 1069 to perform manage
Cleartext transmission of sensitive information in Windows Hello allows an unauthorized attacker to bypass a security fe
Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h suffers from Cleartext Transmission of
CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists that could result in the exposure of data
If Brocade Fabric OS before Fabric OS 9.2.0 configuration settings are not set to encrypt SNMP passwords, then the SNMP
Bitdefender Box, versions 1.3.11.490 through 1.3.11.505, uses the insecure HTTP protocol to download assets over the Int
The device uses an unencrypted, proprietary protocol for communication. Through this protocol, configuration data is tra
In phpipam/phpipam version 1.5.1, the Secure attribute for sensitive cookies in HTTPS sessions is not set. This could ca
SaTECH BCU in its firmware version 2.1.3 uses the HTTP protocol. The use of the HTTP protocol for web browsing has the p
In certain cases, SNI could have been sent unencrypted even when encrypted DNS was enabled. This vulnerability was fixed
All communication with the REST API is unencrypted (HTTP), allowing an attacker to intercept traffic between an actor an
The server supports authentication methods in which credentials are sent in plaintext over unencrypted channels. If an a
Ecovacs Deebot T10 1.7.2 transmits Wi-Fi credentials in cleartext during the pairing process.
Frequently Asked Questions
What is CWE-319?
CWE-319 (CWE-319) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-319?
There are 1,101 CVE records associated with CWE-319 in our database. Of these, 79 are critical severity, 341 are high severity, and 407 are medium severity.
How can I protect against CWE-319 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-319 using AI-powered security agents.
Detect CWE-319 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-319 vulnerabilities across your infrastructure.
Get Started