CWE-319— Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.— MITRE CWE catalog
913 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-319page 15 of 19
- CVE-2024-45838MEDIUMCVSS 4.3EG 4.32024-09-26
The goTenna Pro ATAK Plugin does not encrypt callsigns in messages. It is advised to not use sensitive information in callsigns when using this and previous versions of the plugin. Update to current plugin version which uses AES-256 enc…
- CVE-2024-46505CRITICALCVSS 9.1EG 9.12025-01-09
Infoblox BloxOne v2.4 was discovered to contain a business logic flaw due to thick client vulnerabilities.
- CVE-2024-47124MEDIUMCVSS 4.3EG 6.52024-09-26
The goTenna Pro App does not encrypt callsigns in messages. It is recommended to not use sensitive information in callsigns when using this and previous versions of the app and update your app to the current app version which uses AES-2…
- CVE-2024-47269MEDIUMCVSS 4.9EG 4.92026-05-27
Cleartext transmission of sensitive information vulnerability in Export Key functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to obtain sensitiv…
- CVE-2024-47577LOWCVSS 2.7EG 2.72024-12-10
Webservice API endpoints for Assisted Service Module within SAP Commerce Cloud has information disclosure vulnerability. When an authorized agent searches for customer to manage their accounts, the request url includes customer data and it…
- CVE-2024-47789HIGHCVSS 8.7EG 8.72024-10-04
** UNSUPPORTED WHEN ASSIGNED ** This vulnerability exists in D3D Security IP Camera D8801 due to usage of weak authentication scheme of the HTTP header protocol where authorization tag contain a Base-64 encoded username and password. A rem…
- CVE-2024-47833MEDIUMCVSS 6.5EG 6.52024-10-09
Taipy is an open-source Python library for easy, end-to-end application development for data scientists and machine learning engineers. In affected versions session cookies are served without Secure and HTTPOnly flags. This issue has been …
- CVE-2024-48121MEDIUMCVSS 6.5EG 6.52025-01-15
The HI-SCAN 6040i Hitrax HX-03-19-I was discovered to transmit user credentials in cleartext over the GIOP protocol. This allows attackers to possibly gain access to sensitive information via a man-in-the-middle attack.
- CVE-2024-48788HIGHCVSS 7.5EG 7.52024-10-11
An issue in YESCAM (com.yescom.YesCam.zwave) 1.0.2 allows a remote attacker to obtain sensitive information via the firmware update process.
- CVE-2024-48894MEDIUMCVSS 5.9EG 5.92025-12-01
A cleartext transmission vulnerability exists in the WEBVIEW-M functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted HTTP request can lead to a disclosure of sensitive information. An attacker can sniff network traffic to…
- CVE-2024-49387HIGHCVSS 7.5EG 7.52024-10-15
Cleartext transmission of sensitive information in acep-collector service. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.
- CVE-2024-49819MEDIUMCVSS 4.1EG 4.12024-12-17
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information in cleartext in a communication channel that can be sniffed by unauthorized actors.
- CVE-2024-49820LOWCVSS 3.7EG 3.72024-12-17
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit thi…
- CVE-2024-50624MEDIUMCVSS 5.9EG 5.92024-10-28
ispdbservice.cpp in KDE Kmail before 6.2.0 allows man-in-the-middle attackers to trigger use of an attacker-controlled mail server because cleartext HTTP is used for a URL such as http://autoconfig.example.com or http://example.com/.well-k…
- CVE-2024-50634HIGHCVSS 8.8EG 8.82024-11-08
A vulnerability in a weak JWT token in Watcharr v1.43.0 and below allows attackers to perform privilege escalation using a crafted JWT token. This vulnerability is not limited to privilege escalation but also affects all functions that req…
- CVE-2024-53246MEDIUMCVSS 5.3EG 5.32024-12-10
In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions below 9.3.2408.101, 9.2.2406.106, 9.2.2403.111, and 9.1.2312.206, an SPL command can potentially disclose sensitive information. The vulnerabili…
- CVE-2024-5462HIGHCVSS 7.5EG 7.52025-02-15
If Brocade Fabric OS before Fabric OS 9.2.0 configuration settings are not set to encrypt SNMP passwords, then the SNMP privsecret / authsecret fields can be exposed in plaintext. The plaintext passwords can be exposed in a configupload ca…
- CVE-2024-5631MEDIUMCVSS 6.0EG 6.02024-07-09
Longse NVR (Network Video Recorder) model NVR3608PGE2W, as well as products based on this device, are transmitting user's login and password to a remote control service without using any encryption. This enables an on-path attacker to eav…
- CVE-2024-6388MEDIUMCVSS 5.9EG 5.92024-06-27
Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivileged users by passing the token as an argument in plaintext.
- CVE-2024-6515CRITICALCVSS 9.6EG 9.62024-12-05
Web browser interface may manipulate application username/password in clear text or Base64 encoding providing a higher probability of unintended credentails exposure. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series …
- CVE-2024-6972MEDIUMCVSS 6.5EG 6.52024-07-25
In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the task log in clear-text.
- CVE-2024-7408MEDIUMCVSS 6.5EG 6.52024-08-12
This vulnerability exists in Airveda Air Quality Monitor PM2.5 PM10 due to transmission of sensitive information in plain text during AP pairing mode. An attacker in close proximity could exploit this vulnerability by capturing Wi-Fi traff…
- CVE-2024-7713HIGHCVSS 7.5EG 7.52024-09-27
The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 discloses the Open AI API Key, allowing unauthenticated users to obtain it
- CVE-2024-8013LOWCVSS 2.2EG 2.22024-10-28
A bug in query analysis of certain complex self-referential $lookup subpipelines may result in literal values in expressions for encrypted fields to be sent to the server as plaintext instead of ciphertext. Should this occur, no documents …
- CVE-2024-8059MEDIUMCVSS 4.3EG 4.32024-09-13
IPMI credentials may be captured in XCC audit log entries when the account username length is 16 characters.
- CVE-2024-9620MEDIUMCVSS 5.3EG 5.32024-10-08
A flaw was found in Event-Driven Automation (EDA) in Ansible Automation Platform (AAP), which lacks encryption of sensitive information. An attacker with network access could exploit this vulnerability by sniffing the plaintext data transm…
- CVE-2024-9834CRITICALCVSS 9.3EG 9.32024-11-14
Improper data protection on the ventilator's serial interface could allow an attacker to send and receive messages that result in unauthorized disclosure of information and/or have unintended impacts on device settings and performance.
- CVE-2025-0136MEDIUMCVSS 5.3EG 5.32025-05-14
Using the AES-128-CCM algorithm for IPSec on certain Palo Alto Networks PAN-OS® firewalls (PA-7500, PA-5400, PA-5400f, PA-3400, PA-1600, PA-1400, and PA-400 Series) leads to unencrypted data transfer to devices that are connected to the P…
- CVE-2025-0250LOWCVSS 2.2EG 2.22025-07-25
HCL IEM is affected by an authorization token sent in cookie vulnerability. A token used for authentication and authorization is being handled in a manner that may increase its exposure to security risks.
- CVE-2025-0252LOWCVSS 2.6EG 2.62025-07-25
HCL IEM is affected by a password in cleartext vulnerability. Sensitive information is transmitted without adequate protection, potentially exposing it to unauthorized access during transit.
- CVE-2025-0432MEDIUMCVSS 5.7EG 5.72025-01-28
EWON Flexy 202 transmits user credentials in clear text with no encryption when a user is added, or user credentials are changed via its webpage.
- CVE-2025-0556HIGHCVSS 8.8EG 8.82025-02-12
In Progress® Telerik® Report Server, versions prior to 2025 Q1 (11.0.25.211) when using the older .NET Framework implementation, communication of non-sensitive information between the service agent process and app host process occurs ove…
- CVE-2025-0631HIGHCVSS 8.7EG 8.72025-01-28
A Credential Exposure Vulnerability exists in the above-mentioned product and version. The vulnerability is due to using HTTP resulting in credentials being sent in clear text.
- CVE-2025-0784LOWCVSS 3.7EG 3.72025-01-28
A vulnerability has been found in Intelbras InControl up to 2.21.58 and classified as problematic. This vulnerability affects unknown code of the file /v1/usuario/ of the component Registered User Handler. The manipulation leads to clearte…
- CVE-2025-10174HIGHCVSS 8.3EG 8.32026-02-11
Cleartext Transmission of Sensitive Information vulnerability in Pan Software & Information Technologies Ltd. PanCafe Pro allows Flooding. This issue affects PanCafe Pro: from < 3.3.2 through 23092025.
- CVE-2025-10540MEDIUMCVSS 6.5EG 6.52025-09-25
iMonitor EAM 9.6394 transmits communication between the EAM client agent and the EAM server, as well as between the EAM monitor management software and the server, in plaintext without authentication or encryption. An attacker with network…
- CVE-2025-1060HIGHCVSS 7.5EG 7.52025-02-13
CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists that could result in the exposure of data when network traffic is being sniffed by an attacker.
- CVE-2025-10641HIGHCVSS 7.1EG 7.12025-10-21
All WorkExaminer Professional traffic between monitoring client, console and server is transmitted as plain text. This allows an attacker with access to the network to read the transmitted sensitive data. An attacker can also freely modify…
- CVE-2025-10776LOWCVSS 3.7EG 3.72025-09-22
A vulnerability was detected in LionCoders SalePro POS up to 5.5.0. This issue affects some unknown processing of the component Login. Performing manipulation results in cleartext transmission of sensitive information. The attack can be in…
- CVE-2025-11492CRITICALCVSS 9.6EG 9.62025-10-16
In the ConnectWise Automate Agent, communications could be configured to use HTTP instead of HTTPS. In such cases, an on-path threat actor with a man-in-the-middle network position could intercept, modify, or replay agent-server traffic. A…
- CVE-2025-11640LOWCVSS 3.1EG 3.12025-10-12
A vulnerability was found in Tomofun Furbo 360 and Furbo Mini. This affects an unknown function of the component Bluetooth Low Energy. The manipulation results in cleartext transmission of sensitive information. Access to the local network…
- CVE-2025-12508HIGHCVSS 8.4EG 8.42025-10-31
When using domain users as BRAIN2 users, communication with Active Directory services is unencrypted. This can lead to the interception of authentication data and compromise confidentiality.
- CVE-2025-12530MEDIUMCVSS 5.9EG 5.92026-06-30
IBM watsonx.data intelligence 5.2.2, 5.3.0, 5.3.1, 5.3.1 through patch-1 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.
- CVE-2025-13454MEDIUMCVSS 5.5EG 5.52026-01-14
A potential vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to gain access to sensitive device information.
- CVE-2025-13489MEDIUMCVSS 5.9EG 5.92025-12-15
IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 IBM DevOps Deploy transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.
- CVE-2025-13490MEDIUMCVSS 5.9EG 5.92026-03-03
IBM App Connect Operator versions CD 11.3.0 through 11.6.0 and 12.1.0 through 12.20.0, LTS versions 12.0.0 through 12.0.20, and IBM App Connect Enterprise Certified Containers Operands versions CD 12.0.11.2‑r1 through 12.0.12.5‑r1 and …
- CVE-2025-13718HIGHCVSS 7.5EG 7.52026-03-13
IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow a remote attacker to obtain sensitive information in cleartext in a communication channel that can be sniffed by unauthorized actors.
- CVE-2025-15619LOWCVSS 3.5EG 3.52026-06-23
HCL Connections contains a broken access control vulnerability that may allow an unauthorized user to view data in a single specific scenario.
- CVE-2025-22493MEDIUMCVSS 5.6EG 5.62025-03-05
Secure flag not set and SameSIte was set to Lax in the Foreseer Reporting Software (FRS). Absence of this secure flag could lead into the session cookie being transmitted over unencrypted HTTP connections. This security issue has been reso…
- CVE-2025-23060MEDIUMCVSS 6.6EG 6.62025-02-04
A vulnerability in HPE Aruba Networking ClearPass Policy Manager may, under certain circumstances, expose sensitive unencrypted information. Exploiting this vulnerability could allow an attacker to perform a man-in-the-middle attack, poten…
Map vulnerabilities like CWE-319 to your infrastructure
EchelonGraph correlates every CVE — across CWE-319 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →