Cleartext transmission of sensitive information for some BigDL software maintained by Intel(R) before version 2.5.0 may
Johan Fagerström, member of the AXIS OS Bug Bounty Program, has found that a O3C feature may expose sensitive traffic be
A flaw was found in Event-Driven Automation (EDA) in Ansible Automation Platform (AAP), which lacks encryption of sensit
An authentication-bypass issue in the RDP component of One Identity Safeguard for Privileged Sessions (SPS) On Premise b
A flaw was found in moodle. The cURL wrapper in Moodle strips HTTPAUTH and USERPWD headers during emulated redirects, bu
In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions below 9.3.2408.101, 9.2.2
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected w
Information Disclosure in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to read the Wi
Cleartext transmission of sensitive information vulnerability exists in multiple IDEC PLCs. If an attacker sends a speci
IBM Watson CP4D Data Stores 4.6.0, 4.6.1, 4.6.2, and 4.6.3 does not encrypt sensitive or critical information before sto
The POPS! Rebel application 5.0 for Android, in POPS! Rebel Bluetooth Glucose Monitoring System, sends unencrypted gluco
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.3 does not set the secure
It is possible for an API key to be logged in clear text in the audit log file after an invalid login attempt.
IBM Concert 1.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to g
IPMI credentials may be captured in XCC audit log entries when the account username length is 16 characters.
The goTenna Pro ATAK Plugin does not encrypt callsigns in messages. It is advised to not use sensitive information in c
The goTenna Pro App does not encrypt callsigns in messages. It is recommended to not use sensitive information in calls
An Information Disclosure vulnerability in the Telemetry component in TP-Link Kasa KP125M V1.0.0 and Tapo P125M 1.0.0 Bu
Vilo 5 Mesh WiFi System <= 5.16.1.33 is vulnerable to Information Disclosure. An information leak in the Boa webserver a
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensiti
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensiti
Webservice API endpoints for Assisted Service Module within SAP Commerce Cloud has information disclosure vulnerability.
A bug in query analysis of certain complex self-referential $lookup subpipelines may result in literal values in express
Sametime is impacted by sensitive information passed in URL.
Longse NVR (Network Video Recorder) model NVR3608PGE2W, as well as products based on this device, are transmitting user'
** UNSUPPORTED WHEN ASSIGNED ** This vulnerability exists in D3D Security IP Camera D8801 due to usage of weak authentic
The Syrus4 IoT gateway utilizes an unsecured MQTT server to download and execute arbitrary commands, allowing a remote u
Last Yard 22.09.8-1 does not enforce HSTS headers
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 does not defend against physical access to U-Boot via the UA
Privilege Escalation in the "GetUserCurrentPwd" function in Microworld Technologies eScan Management Console 14.0.1400.2
A remote unprivileged attacker can intercept the communication via e.g. Man-In-The-Middle, due to the absence of Transpo
A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functional
The affected devices transmit sensitive information unencrypted allowing a remote unauthenticated attacker to capture an
Cleartext Transmission of Sensitive Information vulnerability in Hitachi Device Manager on Windows, Linux (Device Manage
An issue was discovered in vTech VCS754 version 1.1.1.A before 1.1.1.H, allows attackers to gain escalated privileges an
A CWE-319: Cleartext transmission of sensitive information vulnerability exists that could cause disclosure of sensitiv
A flaw was found in the Keycloak package, more specifically org.keycloak.userprofile. When a user registers itself throu
Insufficient authentication in the MQTT backend (broker) allows an attacker to access and even manipulate the telemetry
Communication between the client and the server application of the affected products is partially done using CORBA (Com
The Android Client application, when enrolled with the define method 1 (the user manually inserts the server ip address
An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v
A cleartext transmission of sensitive information vulnerability [CWE-319] in Fortinet FortiOS version 7.2.0 through 7.2.
A flaw was found in Red Hat OpenShift Data Science. When exporting a pipeline from the Elyra notebook pipeline editor as
Couchbase Server before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2 exposes Sensitive Information to an Unauthorized
A cleartext transmission vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Et
LS ELECTRIC XBC-DN32U with operating system version 01.80 transmits sensitive information in cleartext when communicatin
Information Disclosure in Authentication Component of ScreenCheck BadgeMaker 2.6.2.0 application allows internal attacke
SAUTER Controls Nova 200–220 Series with firmware version 3.3-006 and prior and BACnetstac version 4.2.1 and prior have
Cleartext Transmission of Sensitive Information vulnerability in ForgeRock Inc. OpenIDM and Java Remote Connector Server
Jenkins Kubernetes Plugin 3909.v1f2c633e8590 and earlier does not properly mask (i.e., replace with asterisks) credentia
Frequently Asked Questions
What is CWE-319?
CWE-319 (CWE-319) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-319?
There are 1,101 CVE records associated with CWE-319 in our database. Of these, 79 are critical severity, 341 are high severity, and 407 are medium severity.
How can I protect against CWE-319 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-319 using AI-powered security agents.
Detect CWE-319 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-319 vulnerabilities across your infrastructure.
Get Started