Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-319

MITRE ↗

CWE-319

79
CRITICAL
341
HIGH
407
MEDIUM
50
LOW
905 CVEs · Page 8/19
7.5
CVE-2023-30514

Jenkins Azure Key Vault Plugin 187.va_cd5fecd198a_ and earlier does not properly mask (i.e., replace with asterisks) cre

7.5
CVE-2023-30515

Jenkins Thycotic DevOps Secrets Vault Plugin 1.0.0 and earlier does not properly mask (i.e., replace with asterisks) cre

7.5
CVE-2023-32290

The myMail app through 14.30 for iOS sends cleartext credentials in a situation where STARTTLS is expected by a server.

7.5
CVE-2023-32784

In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a work

7.5
CVE-2023-31193

Snap One OvrC Pro versions prior to 7.3 use HTTP connections when downloading a program from their servers.

7.5
CVE-2023-33960

OpenProject is web-based project management software. For any OpenProject installation, a `robots.txt` file is generated

7.5
CVE-2023-30602

Hitron Technologies CODA-5310’s Telnet function transfers sensitive data in plaintext. An unauthenticated remote attacke

7.5
CVE-2023-23841

SolarWinds Serv-U is submitting an HTTP request when changing or updating the attributes for File Share or File request.

7.5
CVE-2023-21219

there is a possible use of unencrypted transport over cellular networks due to an insecure default value. This could lea

7.5
CVE-2023-21220

there is a possible use of unencrypted transport over cellular networks due to an insecure default value. This could lea

7.5
CVE-2023-3272

Cleartext Transmission of Sensitive Information in the SICK ICR890-4 could allow a remote attacker to gather sensitive i

7.5
CVE-2023-31823

An issue found in Marui Co Marui Official app v.13.6.1 allows a remote attacker to gain access to sensitive information

7.5
CVE-2023-39086

ASUS RT-AC66U B1 3.0.0.4.286_51665 was discovered to transmit sensitive information in cleartext.

7.5
CVE-2023-42147

An issue in CloudExplorer Lite 1.3.1 allows an attacker to obtain sensitive information via the login key component.

7.5
CVE-2017-7252

bcrypt password hashing in Botan before 2.1.0 does not correctly handle passwords with a length between 57 and 72 charac

7.5
CVE-2023-46380

LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) sen

7.5
CVE-2023-46382

LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) use

7.5
CVE-2023-46383

LOYTEC electronics GmbH LINX Configurator (all versions) uses HTTP Basic Authentication, which transmits usernames and p

7.5
CVE-2023-46385

LOYTEC electronics GmbH LINX Configurator (all versions) is vulnerable to Insecure Permissions. An admin credential is p

7.5
CVE-2023-28616

An issue was discovered in Stormshield Network Security (SNS) before 4.3.17, 4.4.x through 4.6.x before 4.6.4, and 4.7.x

7.5
CVE-2023-31300

An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attacker

7.4
CVE-2023-28348

An issue was discovered in Faronics Insight 10.0.19045 on Windows. A suitably positioned attacker could perform a man-in

7.4
CVE-2023-2754

The Cloudflare WARP client for Windows assigns loopback IPv4 addresses for the DNS Servers, since WARP acts as local DNS

7.3
CVE-2022-23509

Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing K

7.3
CVE-2023-36673

An issue was discovered in Avira Phantom VPN through 2.23.1 for macOS. The VPN client insecurely configures the operatin

7.3
CVE-2023-40729

A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application lacks security c

7.2
CVE-2023-1831

Mattermost fails to redact from audit logs the user password during user creation and the user password hash in other op

7.1
CVE-2023-0864

Cleartext Transmission of Sensitive Information vulnerability in ABB Terra AC wallbox (UL40/80A), ABB Terra AC wallbox (

6.8
CVE-2023-43125

BIG-IP APM clients may send IP traffic outside of the VPN tunnel.  Note: Software versions which have reached End of Te

6.8
CVE-2023-34441

Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05 contains a cleartext transmission vulnerability

6.5
CVE-2022-0553

There is no check to see if slot 0 is being uploaded from the device to the host. When using encrypted images this means

6.5
CVE-2023-22597

InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r

6.5
CVE-2023-23915

A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functional

6.5
CVE-2022-38458

A cleartext transmission vulnerability exists in the Remote Management functionality of Netgear Orbi Router RBR750 4.6.8

6.5
CVE-2023-27927

An authenticated malicious user could acquire the simple mail transfer protocol (SMTP) Password in cleartext format, des

6.5
CVE-2023-25070

Cleartext transmission of sensitive information exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier. If the

6.5
CVE-2023-35833

An issue was discovered in YSoft SAFEQ 6 Server before 6.0.82. When modifying the URL of the LDAP server configuration f

6.5
CVE-2023-42579

Improper usage of insecure protocol (i.e. HTTP) in SogouSDK of Chinese Samsung Keyboard prior to versions 5.3.70.1 in An

6.5
CVE-2023-51390

journalpump is a daemon that takes log messages from journald and pumps them to a given output. A logging vulnerability

6.5
CVE-2023-34829

Incorrect access control in TP-Link Tapo before v3.1.315 allows attackers to access user credentials in plaintext.

6.3
CVE-2023-36671

An issue was discovered in the Clario VPN client through 5.9.1.1662 for macOS. The VPN client insecurely configures the

6.3
CVE-2023-41088

The affected product is vulnerable to a cleartext transmission of sensitive information vulnerability, which

6.3
CVE-2023-50703

An attacker with network access could perform a man-in-the-middle (MitM) attack and capture sensitive information to ga

6.0
CVE-2023-0001

An information exposure vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local syste

6.0
CVE-2023-30841

Baremetal Operator (BMO) is a bare metal host provisioning integration for Kubernetes. Prior to version 0.3.0, ironic an

5.9
CVE-2023-22863

IBM Robotic Process Automation 20.12.0 through 21.0.2 defaults to HTTP in some RPA commands when the prefix is not expli

5.9
CVE-2023-23130

Connectwise Automate 2022.11 is vulnerable to Cleartext authentication. Authentication is being done via HTTP (cleartext

5.9
CVE-2023-0922

The Samba AD DC administration tool, when operating against a remote LDAP server, will by default send new or reset pass

5.9
CVE-2023-1802

In Docker Desktop 4.17.x the Artifactory Integration falls back to sending registry credentials over plain HTTP if the H

5.9
CVE-2019-14942

An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.

Frequently Asked Questions

What is CWE-319?

CWE-319 (CWE-319) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-319?

There are 1,101 CVE records associated with CWE-319 in our database. Of these, 79 are critical severity, 341 are high severity, and 407 are medium severity.

How can I protect against CWE-319 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-319 using AI-powered security agents.

Detect CWE-319 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-319 vulnerabilities across your infrastructure.

Get Started