IBM Maximo Application Suite - Manage Component 8.8.0 and 8.9.0 transmits sensitive information in cleartext that could
IBM Aspera Faspex 5.0.5 transmits sensitive information in cleartext which could be obtained by an attacker using man in
Cleartext Transmission of Sensitive Information in RDT400 in SICK APU allows an unprivileged remote attacker to retriev
IBM Security Verify Privilege On-Premises 11.5 could disclose sensitive information to an attacked due to the transmiss
IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in container images which could lead to
IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in environment variables which could aid
On affected platforms running Arista MOS, the configuration of a BGP password will cause the password to be logged in cl
Cleartext Transmission in set-cookie:ecos_pw: Tenda N301 v6.0, Firmware v12.02.01.61_multi allows an authenticated attac
Cleartext Transmission in cookie:ecos_pw: in Tenda N301 v6.0, firmware v12.03.01.06_pt allows an authenticated attacker
An issue was discovered in the Clario VPN client through 5.9.1.1662 for macOS. The VPN client insecurely configures the
The lack of web request control on ekorCCP and ekorRCI devices allows a potential attacker to create custom requests to
Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier transmits the private key in plain text as part of
Highlight is an open source, full-stack monitoring platform. Highlight may record passwords on customer deployments when
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository pyload/pyload prior to 0.5.0b3.dev32.
This issue was addressed with using HTTPS when sending information over the network. This issue is fixed in Apple Music
ASUS Router RT-AX3000 Firmware versions prior to 3.0.0.4.388.23403 uses sensitive cookies without 'Secure' attribute. Wh
ArcGIS Enterprise Server versions 11.0 and below have an information disclosure vulnerability where a remote, unauthoriz
BIG-IP APM clients may send IP traffic outside of the VPN tunnel. Note: Software versions which have reached End of Te
All versions of NetMan 204 could allow an unauthenticated remote attacker to read a file (config.cgi) containing sensiti
A vulnerability has been identified in OnCell G3150A-LTE Series firmware versions v1.3 and prior. The vulnerability resu
A cleartext transmission of sensitive information vulnerability has been reported to affect QVPN Device Client. If explo
A flaw was found in OpenStack. Multiple components show plain-text passwords in /var/log/messages during the OpenStack o
IBM Security Verify Governance 10.0 does not encrypt sensitive or critical information before storage or transmission.
A vulnerability was found in Intergard SGS 8.7.0 and classified as problematic. Affected by this issue is some unknown f
A vulnerability was found in Intergard SGS 8.7.0. It has been declared as problematic. This vulnerability affects unknow
A vulnerability was found in Delta Electronics WPLSoft 2.51. It has been classified as problematic. Affected is an unkno
An insecure connection between Systems Manager and CQI Reporter application could expose infusion data to an attacker.
A cleartext transmission of sensitive information vulnerability has been reported to affect QNAP operating systems. If e
A vulnerability has been identified in COMOS (All versions < V10.4.4). Caching system in the affected application leaks
A vulnerability has been identified in PT-G503 Series firmware versions prior to v5.2, where the Secure attribute for se
Concrete CMS Versions 9.0.0 through 9.0.2 and 8.5.7 and below can download zip files over HTTP and execute code from tho
Cleartext Transmission of Sensitive Information vulnerability due to the use of Basic Authentication for HTTP connection
A vulnerability has been identified in SICAM PAS/PQS (All versions < V7.0). Affected software transmits the database cre
Any attempt (good or bad) to log into AutomationDirect Stride Field I/O with a web browser may result in the device resp
The affected ThroughTek P2P products (SDKs using versions before 3.1.5, any versions with nossl tag, device firmware not
PJSIP is a free and open source multimedia communication library written in C. When processing certain packets, PJSIP ma
Communication traffic involving "Ethernet Q Commands" service of Haas Controller version 100.20.000.1110 is transmitted
Zoho ManageEngine ADAudit Plus before 7055 allows authenticated Privilege Escalation on Integrated products. This occurs
A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not encrypt web traffic with c
A flaw was found in Foreman project. A credential leak was identified which will expose Azure Compute Profile password t
When clicking on a tel: link, USSD codes, specified after a <code>\*</code> character, would be included in the phone nu
The vulnerability exists in TP-Link TL-WR841N V11 3.16.9 Build 160325 Rel.62500n wireless router due to transmission of
OpenHarmony-v3.1.4 and prior versions had an vulnerability. PIN code is transmitted to the peer device in plain text dur
SAP BusinessObjects Business Intelligence Platform (Open Document) - versions 420, 430, allows an unauthenticated attack
tiny-csrf is a Node.js cross site request forgery (CSRF) protection middleware. In versions prior to 1.1.0 cookies were
AutomationDirect DirectLOGIC is vulnerable to a specifically crafted serial message to the CPU serial port that will cau
Hitachi Vantara Pentaho Business Analytics Server versions before 9.3.0.0, 9.2.0.2 and 8.3.0.25 with the Data Lineage
In Modem EMM, there is a possible information disclosure due to a missing data encryption. This could lead to remote inf
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to use the HTTP protocol for authentication into the admin interfa
Cleartext Transmission of Sensitive Information in /northstar/Admin/login.jsp in Northstar Technologies Inc NorthStar Cl
Frequently Asked Questions
What is CWE-319?
CWE-319 (CWE-319) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-319?
There are 1,101 CVE records associated with CWE-319 in our database. Of these, 79 are critical severity, 341 are high severity, and 407 are medium severity.
How can I protect against CWE-319 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-319 using AI-powered security agents.
Detect CWE-319 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-319 vulnerabilities across your infrastructure.
Get Started