Jenkins Azure Key Vault Plugin 187.va_cd5fecd198a_ and earlier does not properly mask (i.e., replace with asterisks) cre
Jenkins Thycotic DevOps Secrets Vault Plugin 1.0.0 and earlier does not properly mask (i.e., replace with asterisks) cre
The myMail app through 14.30 for iOS sends cleartext credentials in a situation where STARTTLS is expected by a server.
In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a work
Snap One OvrC Pro versions prior to 7.3 use HTTP connections when downloading a program from their servers.
OpenProject is web-based project management software. For any OpenProject installation, a `robots.txt` file is generated
Hitron Technologies CODA-5310’s Telnet function transfers sensitive data in plaintext. An unauthenticated remote attacke
SolarWinds Serv-U is submitting an HTTP request when changing or updating the attributes for File Share or File request.
there is a possible use of unencrypted transport over cellular networks due to an insecure default value. This could lea
there is a possible use of unencrypted transport over cellular networks due to an insecure default value. This could lea
Cleartext Transmission of Sensitive Information in the SICK ICR890-4 could allow a remote attacker to gather sensitive i
An issue found in Marui Co Marui Official app v.13.6.1 allows a remote attacker to gain access to sensitive information
ASUS RT-AC66U B1 3.0.0.4.286_51665 was discovered to transmit sensitive information in cleartext.
An issue in CloudExplorer Lite 1.3.1 allows an attacker to obtain sensitive information via the login key component.
bcrypt password hashing in Botan before 2.1.0 does not correctly handle passwords with a length between 57 and 72 charac
LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) sen
LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) use
LOYTEC electronics GmbH LINX Configurator (all versions) uses HTTP Basic Authentication, which transmits usernames and p
LOYTEC electronics GmbH LINX Configurator (all versions) is vulnerable to Insecure Permissions. An admin credential is p
An issue was discovered in Stormshield Network Security (SNS) before 4.3.17, 4.4.x through 4.6.x before 4.6.4, and 4.7.x
An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attacker
An issue was discovered in Faronics Insight 10.0.19045 on Windows. A suitably positioned attacker could perform a man-in
The Cloudflare WARP client for Windows assigns loopback IPv4 addresses for the DNS Servers, since WARP acts as local DNS
Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing K
An issue was discovered in Avira Phantom VPN through 2.23.1 for macOS. The VPN client insecurely configures the operatin
A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application lacks security c
Mattermost fails to redact from audit logs the user password during user creation and the user password hash in other op
Cleartext Transmission of Sensitive Information vulnerability in ABB Terra AC wallbox (UL40/80A), ABB Terra AC wallbox (
BIG-IP APM clients may send IP traffic outside of the VPN tunnel. Note: Software versions which have reached End of Te
Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05 contains a cleartext transmission vulnerability
There is no check to see if slot 0 is being uploaded from the device to the host. When using encrypted images this means
InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r
A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functional
A cleartext transmission vulnerability exists in the Remote Management functionality of Netgear Orbi Router RBR750 4.6.8
An authenticated malicious user could acquire the simple mail transfer protocol (SMTP) Password in cleartext format, des
Cleartext transmission of sensitive information exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier. If the
An issue was discovered in YSoft SAFEQ 6 Server before 6.0.82. When modifying the URL of the LDAP server configuration f
Improper usage of insecure protocol (i.e. HTTP) in SogouSDK of Chinese Samsung Keyboard prior to versions 5.3.70.1 in An
journalpump is a daemon that takes log messages from journald and pumps them to a given output. A logging vulnerability
Incorrect access control in TP-Link Tapo before v3.1.315 allows attackers to access user credentials in plaintext.
An issue was discovered in the Clario VPN client through 5.9.1.1662 for macOS. The VPN client insecurely configures the
The affected product is vulnerable to a cleartext transmission of sensitive information vulnerability, which
An attacker with network access could perform a man-in-the-middle (MitM) attack and capture sensitive information to ga
An information exposure vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local syste
Baremetal Operator (BMO) is a bare metal host provisioning integration for Kubernetes. Prior to version 0.3.0, ironic an
IBM Robotic Process Automation 20.12.0 through 21.0.2 defaults to HTTP in some RPA commands when the prefix is not expli
Connectwise Automate 2022.11 is vulnerable to Cleartext authentication. Authentication is being done via HTTP (cleartext
The Samba AD DC administration tool, when operating against a remote LDAP server, will by default send new or reset pass
In Docker Desktop 4.17.x the Artifactory Integration falls back to sending registry credentials over plain HTTP if the H
An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.
Frequently Asked Questions
What is CWE-319?
CWE-319 (CWE-319) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-319?
There are 1,101 CVE records associated with CWE-319 in our database. Of these, 79 are critical severity, 341 are high severity, and 407 are medium severity.
How can I protect against CWE-319 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-319 using AI-powered security agents.
Detect CWE-319 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-319 vulnerabilities across your infrastructure.
Get Started