CWE-319— Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.— MITRE CWE catalog
913 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-319page 14 of 19
- CVE-2024-26155MEDIUMCVSS 6.8EG 6.82025-01-17
All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 expose clear text credentials in the web portal. An attacker can access the ETIC RAS web portal and view the HTML code, which is configured to be hidden, thus allowi…
- CVE-2024-26288HIGHCVSS 8.7EG 8.72024-03-12
An unauthenticated remote attacker can influence the communication due to the lack of encryption of sensitive data via a MITM. Charging is not affected.
- CVE-2024-27163MEDIUMCVSS 6.5EG 6.52024-06-14
Toshiba printers will display the password of the admin user in clear-text and additional passwords when sending 2 specific HTTP requests to the internal API. An attacker stealing the cookie of an admin or abusing a XSS vulnerability can r…
- CVE-2024-27166HIGHCVSS 7.4EG 7.42024-06-14
Coredump binaries in Toshiba printers have incorrect permissions. A local attacker can steal confidential information. As for the affected products/models/versions, see the reference URL.
- CVE-2024-28134HIGHCVSS 7.0EG 7.02024-05-14
An unauthenticated remote attacker can extract a session token with a MitM attack and gain web-based management access with the privileges of the currently logged in user due …
- CVE-2024-28169MEDIUMCVSS 5.4EG 5.42024-11-13
Cleartext transmission of sensitive information for some BigDL software maintained by Intel(R) before version 2.5.0 may allow an authenticated user to potentially enable denial of service via adjacent access.
- CVE-2024-28249MEDIUMCVSS 6.1EG 6.12024-03-18
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.13.13, 1.14.8, and 1.15.2, in Cilium clusters with IPsec enabled and traffic matching Layer 7 policies, IPsec-eligible traffic b…
- CVE-2024-28250MEDIUMCVSS 6.1EG 6.12024-03-18
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.14.0 and prior to versions 1.14.8 and 1.15.2, In Cilium clusters with WireGuard enabled and traffic matching Layer 7 policies …
- CVE-2024-28275MEDIUMCVSS 6.5EG 6.52024-04-03
Puwell Cloud Tech Co, Ltd 360Eyes Pro v3.9.5.16(3090516) was discovered to transmit sensitive information in cleartext. This vulnerability allows attackers to intercept and access sensitive information, including users' credentials and pas…
- CVE-2024-28786MEDIUMCVSS 6.5EG 6.52025-01-28
IBM QRadar SIEM 7.5 transmits sensitive or security-critical data in cleartext in a communication channel that could be obtained by an unauthorized actor using man in the middle techniques.
- CVE-2024-30209CRITICALCVSS 9.6EG 9.62024-05-14
A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA20) (All ver…
- CVE-2024-31206HIGHCVSS 8.2EG 8.22024-04-04
dectalk-tts is a Node package to interact with the aeiou Dectalk web API. In `[email protected]`, network requests to the third-party API are sent over HTTP, which is unencrypted. Unencrypted traffic can be easily intercepted and modified …
- CVE-2024-31799MEDIUMCVSS 4.6EG 4.62024-08-15
Information Disclosure in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to read the WiFi passphrase via the UART Debugging Port.
- CVE-2024-31840MEDIUMCVSS 6.5EG 6.52024-05-21
An issue was discovered in Italtel Embrace 1.6.4. The web application inserts cleartext passwords in the HTML source code. An authenticated user is able to edit the configuration of the email server. Once the user access the edit function,…
- CVE-2024-31905MEDIUMCVSS 5.9EG 5.92024-08-15
IBM QRadar Network Packet Capture 7.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive …
- CVE-2024-32384MEDIUMCVSS 6.8EG 6.82025-12-01
Kerlink gateways running KerOS prior to version 5.10 expose their web interface exclusively over HTTP, without HTTPS support. This lack of transport layer security allows a man-in-the-middle attacker to intercept and modify traffic between…
- CVE-2024-32864MEDIUMCVSS 6.4EG 6.42024-08-01
Under certain circumstances exacqVision Web Services will not enforce secure web communications (HTTPS)
- CVE-2024-32946MEDIUMCVSS 5.9EG 5.92024-10-30
A vulnerability in the LevelOne WBR-6012 router's firmware version R0.40e6 allows sensitive information to be transmitted in cleartext via Web and FTP services, exposing it to network sniffing attacks.
- CVE-2024-35057HIGHCVSS 7.5EG 7.52024-05-21
An issue in NASA AIT-Core v2.5.2 allows attackers to execute arbitrary code via a crafted packet.
- CVE-2024-35058HIGHCVSS 7.5EG 7.52024-05-21
An issue in the API wait function of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary code via supplying a crafted string.
- CVE-2024-35059CRITICALCVSS 7.5EG 9.82024-05-21
An issue in the Pickle Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands.
- CVE-2024-35060HIGHCVSS 7.5EG 7.52024-05-21
An issue in the YAML Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands via supplying a crafted YAML file.
- CVE-2024-35210MEDIUMCVSS 5.1EG 6.52024-06-11
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server is not enforcing HSTS. This could allow an attacker to perform downgrade attacks exposing confidential inform…
- CVE-2024-35495MEDIUMCVSS 4.3EG 4.32024-09-30
An Information Disclosure vulnerability in the Telemetry component in TP-Link Kasa KP125M V1.0.0 and Tapo P125M 1.0.0 Build 220930 Rel.143947 allows attackers to observe device state via observing network traffic.
- CVE-2024-36426HIGHCVSS 7.5EG 7.52024-05-27
In TARGIT Decision Suite 23.2.15007.0 before Autumn 2023, the session token is part of the URL and may be sent in a cleartext HTTP session.
- CVE-2024-36558HIGHCVSS 7.5EG 7.52025-02-06
Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h suffers from Cleartext Transmission of Sensitive Information due to lack of encryption in device-server communication.
- CVE-2024-37163MEDIUMCVSS 6.4EG 6.42024-06-07
SkyScrape is a GUI Dashboard for AWS Infrastructure and Managing Resources and Usage Costs. SkyScrape's API requests are currently unsecured HTTP requests, leading to potential vulnerabilities for the user's temporary credentials and data…
- CVE-2024-37183MEDIUMCVSS 5.7EG 5.72024-06-20
Plain text credentials and session ID can be captured with a network sniffer.
- CVE-2024-37393HIGHCVSS 7.5EG 7.52024-06-10
Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-supplied input. An unauthenticated remote attacker could exfiltrate data from Active Directory through blind LDAP injection …
- CVE-2024-38167MEDIUMCVSS 6.5EG 6.52024-08-13
.NET and Visual Studio Information Disclosure Vulnerability
- CVE-2024-38891CRITICALCVSS 7.5EG 9.12024-08-02
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Sniffing Network Traffic attack due to the cleartext transmission of sensitive informat…
- CVE-2024-39746MEDIUMCVSS 5.9EG 5.92024-08-22
IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerab…
- CVE-2024-40090MEDIUMCVSS 4.3EG 4.32024-10-21
Vilo 5 Mesh WiFi System <= 5.16.1.33 is vulnerable to Information Disclosure. An information leak in the Boa webserver allows remote, unauthenticated attackers to leak memory addresses of uClibc and the stack via sending a GET request to t…
- CVE-2024-40595MEDIUMCVSS 5.3EG 5.32024-10-24
An authentication-bypass issue in the RDP component of One Identity Safeguard for Privileged Sessions (SPS) On Premise before 7.5.1 (and LTS before 7.0.5.1) allows man-in-the-middle attackers to obtain access to privileged sessions on targ…
- CVE-2024-41124MEDIUMCVSS 6.3EG 6.32024-07-19
Puncia is the Official CLI utility for Subdomain Center & Exploit Observer. `API_URLS` is utilizing HTTP instead of HTTPS for communication that can lead to issues like Eavesdropping, Data Tampering, Unauthorized Data Access & MITM Attacks…
- CVE-2024-41262HIGHCVSS 7.4EG 7.42024-07-31
mmudb v1.9.3 was discovered to use the HTTP protocol in the ShowMetricsRaw and ShowMetricsAsText functions, possibly allowing attackers to intercept communications via a man-in-the-middle attack.
- CVE-2024-4161HIGHCVSS 8.6EG 8.62024-04-25
In Brocade SANnav, before Brocade SANnav v2.3.0, syslog traffic received clear text. This could allow an unauthenticated, remote attacker to capture sensitive information.
- CVE-2024-41687HIGHCVSS 7.5EG 7.52024-07-26
This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to transmission of password in plain text. A remote attacker could exploit this vulnerability by intercepting transmission within an HTTP session on the vulnerable system.…
- CVE-2024-41757MEDIUMCVSS 5.9EG 5.92025-01-24
IBM Concert Software 1.0.0 and 1.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive i…
- CVE-2024-41927MEDIUMCVSS 4.6EG 4.62024-09-04
Cleartext transmission of sensitive information vulnerability exists in multiple IDEC PLCs. If an attacker sends a specific command to PLC's serial communication port, user credentials may be obtained. As a result, the program of the PLC m…
- CVE-2024-42181LOWCVSS 1.6EG 1.62025-01-12
HCL MyXalytics is affected by a cleartext transmission of sensitive information vulnerability. The application transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actor…
- CVE-2024-43180MEDIUMCVSS 4.3EG 4.32024-09-13
IBM Concert 1.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cooki…
- CVE-2024-43187MEDIUMCVSS 5.9EG 5.92025-02-04
IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
- CVE-2024-43432MEDIUMCVSS 5.3EG 5.32024-11-11
A flaw was found in moodle. The cURL wrapper in Moodle strips HTTPAUTH and USERPWD headers during emulated redirects, but retains other original request headers, so HTTP authorization header information could be unintentionally sent in req…
- CVE-2024-43766MEDIUMCVSS 6.5EG 6.52026-03-02
In multiple functions of btm_ble_sec.cc, there is a possible unencrypted communication due to Invalid error handling. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User…
- CVE-2024-44105HIGHCVSS 8.2EG 8.22024-09-10
Cleartext transmission of sensitive information in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to obtain OS credentials.
- CVE-2024-44276HIGHCVSS 7.3EG 7.32025-03-17
This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in iOS 18.2 and iPadOS 18.2. A user in a privileged network position may be able to leak sensitive information.
- CVE-2024-45101MEDIUMCVSS 6.8EG 6.82024-09-13
A privilege escalation vulnerability was discovered when Single Sign On (SSO) is enabled that could allow an attacker to intercept a valid, authenticated LXCA user’s XCC session if they can convince the user to click on a specially craft…
- CVE-2024-45102MEDIUMCVSS 6.8EG 6.82025-01-14
A privilege escalation vulnerability was discovered that could allow a valid, authenticated LXCA user to escalate their permissions for a connected XCC instance when using LXCA as a Single Sign On (SSO) provider for XCC instances.
- CVE-2024-45361MEDIUMCVSS 6.5EG 6.52025-03-27
A protocol flaw vulnerability exists in the Xiaomi Mi Connect Service APP. The vulnerability is caused by the validation logic is flawed and can be exploited by attackers to leak sensitive user information.
Map vulnerabilities like CWE-319 to your infrastructure
EchelonGraph correlates every CVE — across CWE-319 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →