DuraComm SPM-500 DP-10iN-100-MU transmits sensitive data without encryption over a channel that could be intercepted b
Cleartext Transmission of Sensitive Information vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU
IBM Aspera HTTP Gateway 2.0.0 through 2.3.1 stores sensitive information in clear text in easily obtainable files which
A cleartext transmission of sensitive information vulnerability in the affected products allows an unauthorized remote a
General Industrial Controls Lynx+ Gateway is vulnerable to a cleartext transmission vulnerability that could allow an a
Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.00
Solstice Pod API (version 5.5, 6.2) contains an unauthenticated API endpoint (`/api/config`) that exposes sensitive info
DVP-12SE - Modbus/TCP Cleartext Transmission of Sensitive Information
The Pixmeo Osirix MD Web Portal sends credential information without encryption, which could allow an attacker to steal
The Sante PACS Server Web Portal sends credential information without encryption.
Due to an unsecure default configuration HTTP is used instead of HTTPS for the web interface. An unauthenticated attacke
This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in iOS 18.2 and i
An issue was discovered in Couchbase Sync Gateway before 3.2.6. In sgcollect_info_options.log and sync_gateway.log, ther
Lack of encryption in transit for cloud infrastructure facilitating potential for sensitive data manipulation or exposur
An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. A command channel includes the next ho
All WorkExaminer Professional traffic between monitoring client, console and server is transmitted as plain text. This a
In JetBrains Toolbox App before 2.6 unencrypted credential transmission during SSH authentication was possible
The MOD3 command traffic between the monitoring application and the inverter is transmitted in plaintext without encryp
A privilege escalation vulnerability was discovered that could allow a valid, authenticated LXCA user to escalate their
All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 expose clear text credentials in the web portal.
SAP Commerce Cloud (Public Cloud) does not allow to disable unencrypted HTTP (port 80) entirely, but instead allows a re
Kerlink gateways running KerOS prior to version 5.10 expose their web interface exclusively over HTTP, without HTTPS sup
A vulnerability in HPE Aruba Networking ClearPass Policy Manager may, under certain circumstances, expose sensitive unen
The OTA firmware update mechanism in Netun Solutions HelpFlash IoT (firmware v18_178_221102_ASCII_PRO_1R5_50) uses hard-
The HI-SCAN 6040i Hitrax HX-03-19-I was discovered to transmit user credentials in cleartext over the GIOP protocol. Thi
IBM QRadar SIEM 7.5 transmits sensitive or security-critical data in cleartext in a communication channel that could be
Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 were discovered to send commu
A protocol flaw vulnerability exists in the Xiaomi Mi Connect Service APP. The vulnerability is caused by the validation
MedDream WEB DICOM Viewer Cleartext Transmission of Credentials Information Disclosure Vulnerability. This vulnerability
All communication between the VNC server and client(s) is unencrypted. This allows an attacker to intercept the traffic
HCL BigFix SM is affected by a Sensitive Information Exposure vulnerability where internal connections do not use TLS en
iMonitor EAM 9.6394 transmits communication between the EAM client agent and the EAM server, as well as between the EAM
The administrative web interface of a Netgear C7800 Router running firmware version 6.01.07 (and possibly others) authen
The Flock Safety Pisco com.flocksafety.android.pisco application 6.21.11 for Android (installed on Falcon and Sparrow Li
IBM Concert Software 1.0.0 and 1.0.1 could allow a remote attacker to obtain sensitive information, caused by the failur
IBM Security Verify Governance 10.0.2 Identity Manager can transmit user credentials in clear text that could be obtaine
IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 transmits sensitive or security-critical data i
Cleartext transmission of sensitive information issue exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, a man-
Tinxy WiFi Lock Controller v1 RF was discovered to transmit sensitive information in plaintext, including control inform
IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could allow malicious actors to obtain sensitive information due
IBM Guardium Data Protection could allow a remote attacker to obtain sensitive information due to cleartext transmission
A cleartext transmission vulnerability exists in the WEBVIEW-M functionality of Socomec DIRIS Digiware M-70 1.6.9. A spe
IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 IBM DevOps Deploy transmits data in clear text that could allow an attac
HCL DevOps Deploy is susceptible to a cleartext transmission of sensitive information because the HTTP port remains acce
EWON Flexy 202 transmits user credentials in clear text with no encryption when a user is added, or user credentials are
Secure flag not set and SameSIte was set to Lax in the Foreseer Reporting Software (FRS). Absence of this secure flag co
IBM InfoSphere DataStage Flow Designer in IBM InfoSphere Information Server 11.7 discloses sensitive user information in
Arctera/Veritas Data Insight before 7.1.2 can send cleartext credentials when configured to use HTTP Basic Authenticatio
In JetBrains IntelliJ IDEA before 2025.2 credentials disclosure was possible via remote reference
Components of the YoSmart YoLink ecosystem through 2025-10-02 leverage unencrypted MQTT to communicate over the internet
Frequently Asked Questions
What is CWE-319?
CWE-319 (CWE-319) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-319?
There are 1,101 CVE records associated with CWE-319 in our database. Of these, 79 are critical severity, 341 are high severity, and 407 are medium severity.
How can I protect against CWE-319 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-319 using AI-powered security agents.
Detect CWE-319 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-319 vulnerabilities across your infrastructure.
Get Started