A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions with SINEMA Remote Connect Ed
An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. By default, the GID is the user's phon
An issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. By default, a GID is the user's phon
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.15.0 to 1.15.15, 1
A vulnerability has been found in Intelbras InControl up to 2.21.58 and classified as problematic. This vulnerability af
IBM InfoSphere Information Server 11.7 DataStage Flow Designer transmits sensitive information via URL or query parame
A vulnerability, which was classified as problematic, has been found in Comodo Dragon up to 134.0.6998.179. Affected by
A vulnerability was found in macrozheng mall up to 1.0.3. It has been declared as problematic. Affected by this vulnerab
A vulnerability was detected in LionCoders SalePro POS up to 5.5.0. This issue affects some unknown processing of the co
A vulnerability has been found in Coinomi up to 1.7.6. This issue affects some unknown processing. Such manipulation lea
An improper access control vulnerability in the Endpoint Traffic Policy Enforcement https://docs.paloaltonetworks.com/g
A vulnerability was reported in version 1.0 of the Bluetooth Transmission Alliance protocol adopted by Motorola Smart Co
Freebox v5 HD (firmware = 1.7.20), Freebox v5 Crystal (firmware = 1.7.20), Freebox v6 Révolution r1–r3 (firmware = 4.7.x
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 transmits passwords of user accounts in
A vulnerability classified as problematic has been found in Consumer Comanda Mobile up to 14.9.3.2/15.0.0.8. This affect
A flaw was found in Ansible. Sensitive cookies without security flags over non-encrypted channels can lead to Man-in-the
A vulnerability was found in Tomofun Furbo 360 and Furbo Mini. This affects an unknown function of the component Bluetoo
HCL IEM is affected by a password in cleartext vulnerability. Sensitive information is transmitted without adequate pro
HCL IEM is affected by an authorization token sent in cookie vulnerability. A token used for authentication and authori
HCL MyXalytics is affected by a cleartext transmission of sensitive information vulnerability. The application transmit
A Credential Exposure Vulnerability exists in the above-mentioned product and version. The vulnerability is due to using
This vulnerability exists in the Meon KYC solutions due to transmission of sensitive data in plain text within the respo
Cleartext Transmission of Sensitive Information vulnerability in Crestron Automate VX allows Sniffing Network Traffic.
Using the AES-128-CCM algorithm for IPSec on certain Palo Alto Networks PAN-OS® firewalls (PA-7500, PA-5400, PA-5400f, P
Kaleris NAVIS N4 ULC (Ultra Light Client) communicates insecurely using zlib-compressed data over HTTP. An attacker capa
This vulnerability exists in Digisol DG-GR6821AC Router due to cleartext transmission of credentials in its web manageme
Let's Encrypt client and ACME library written in Go (Lego). In versions 4.25.1 and below, the github.com/go-acme/lego/v4
YugabyteDB diagnostic information was transmitted over HTTP, which could expose sensitive data during transmission
The StrongDM Client insufficiently protected a pre-authentication token. Attackers could exploit this to intercept and r
An adjacent attacker without authentication can exploit this vulnerability to retrieve a set of user-privileged credenti
The web server of the device performs exchanges of sensitive information in clear text through an insecure protocol.
Under certain circumstances, attacker can capture the network key, read or write encrypted packets on the PowerG network
DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability i
A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC
Web browser interface may manipulate application username/password in clear text or Base64 encoding providing a higher p
Improper data protection on the ventilator's serial interface could allow an attacker to send and receive messages that
An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext password
A vulnerability in a weak JWT token in Watcharr v1.43.0 and below allows attackers to perform privilege escalation using
Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability
An unauthenticated remote attacker can influence the communication due to the lack of encryption of sensitive data via a
In Brocade SANnav, before Brocade SANnav v2.3.0, syslog traffic received clear text. This could allow an unauthenticate
B&R Automation Studio Upgrade Service and B&R Technology Guarding use insufficient cryptography for communication to the
dectalk-tts is a Node package to interact with the aeiou Dectalk web API. In `[email protected]`, network requests to th
Cleartext transmission of sensitive information in the management console of Ivanti Workspace Control before version 202
A flaw was found in the ansible automation platform. An insecure WebSocket connection was being used in installation fro
The affected product is vulnerable to a cleartext transmission of sensitive information vulnerability, which may allow
This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to transmission of authentication credentials
This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to transmission of authentication credentials
An issue discovereed in EBYTE E880-IR01-V1.1 allows an attacker to obtain sensitive information via crafted POST request
IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure protocols in some instances that could allow an attac
Frequently Asked Questions
What is CWE-319?
CWE-319 (CWE-319) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-319?
There are 1,101 CVE records associated with CWE-319 in our database. Of these, 79 are critical severity, 341 are high severity, and 407 are medium severity.
How can I protect against CWE-319 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-319 using AI-powered security agents.
Detect CWE-319 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-319 vulnerabilities across your infrastructure.
Get Started