CWE-319— Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.— MITRE CWE catalog
913 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-319page 16 of 19
- CVE-2025-2311CRITICALCVSS 9.0EG 9.02025-03-20
Incorrect Use of Privileged APIs, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in Sechard Information Technologies SecHard allows Authentication Bypass, Interface Manipulation, Authent…
- CVE-2025-24849HIGHCVSS 7.1EG 7.12025-02-28
Lack of encryption in transit for cloud infrastructure facilitating potential for sensitive data manipulation or exposure.
- CVE-2025-25046LOWCVSS 3.7EG 3.72025-04-23
IBM InfoSphere Information Server 11.7 DataStage Flow Designer transmits sensitive information via URL or query parameters that could be exposed to an unauthorized actor using man in the middle techniques.
- CVE-2025-25728MEDIUMCVSS 6.5EG 6.52025-02-28
Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 were discovered to send communications to the update API in plaintext, allowing attackers to access sensitive information via a man-in-the-middle at…
- CVE-2025-26199CRITICALCVSS 9.8EG 9.82025-06-18
CloudClassroom-PHP-Project v1.0 is affected by an insecure credential transmission vulnerability. The application transmits passwords over unencrypted HTTP during the login process, exposing sensitive credentials to potential interception …
- CVE-2025-26654MEDIUMCVSS 6.8EG 6.82025-04-08
SAP Commerce Cloud (Public Cloud) does not allow to disable unencrypted HTTP (port 80) entirely, but instead allows a redirect from port 80 to 443 (HTTPS). As a result, Commerce normally communicates securely over HTTPS. However, the confi…
- CVE-2025-27457MEDIUMCVSS 6.5EG 6.52025-07-03
All communication between the VNC server and client(s) is unencrypted. This allows an attacker to intercept the traffic and obtain sensitive data.
- CVE-2025-27594HIGHCVSS 7.5EG 7.52025-03-14
The device uses an unencrypted, proprietary protocol for communication. Through this protocol, configuration data is transmitted and device authentication is performed. An attacker can thereby intercept the authentication hash and use it t…
- CVE-2025-27720HIGHCVSS 7.4EG 7.42025-05-08
The Pixmeo Osirix MD Web Portal sends credential information without encryption, which could allow an attacker to steal credentials.
- CVE-2025-27722MEDIUMCVSS 5.9EG 5.92025-04-09
Cleartext transmission of sensitive information issue exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, a man-in-the-middle attack may allow a remote unauthenticated attacker to eavesdrop the communication and obtain the authenti…
- CVE-2025-27903MEDIUMCVSS 5.9EG 5.92026-02-17
IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 IBM Db2 Recovery Expert for Linux, UNIX and Windows transmits data in a cleartext communication channel that could allow an attacker to obtain sensitive information using man in the middl…
- CVE-2025-2818LOWCVSS 3.5EG 3.52025-07-17
A vulnerability was reported in version 1.0 of the Bluetooth Transmission Alliance protocol adopted by Motorola Smart Connect Android Application that could allow a nearby attacker within the Bluetooth interaction range to intercept files …
- CVE-2025-2861HIGHCVSS 7.5EG 7.52025-03-28
SaTECH BCU in its firmware version 2.1.3 uses the HTTP protocol. The use of the HTTP protocol for web browsing has the problem that information is exchanged in unencrypted text. Since sensitive data such as credentials are exchanged, an at…
- CVE-2025-31972MEDIUMCVSS 6.5EG 6.52025-08-28
HCL BigFix SM is affected by a Sensitive Information Exposure vulnerability where internal connections do not use TLS encryption which could allow an attacker unauthorized access to sensitive data transmitted between internal components.
- CVE-2025-31981MEDIUMCVSS 5.3EG 5.32026-04-21
HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, allowing unencrypted access. An attacker with access to the network traffic can sniff packets from the connection and u…
- CVE-2025-32793MEDIUMCVSS 4.0EG 4.02025-04-21
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.15.0 to 1.15.15, 1.16.0 to 1.16.8, and 1.17.0 to 1.17.2, are vulnerable when using Wireguard transparent encryption in a Cilium cluster, …
- CVE-2025-32880CRITICALCVSS 9.8EG 9.82025-06-20
An issue was discovered on COROS PACE 3 devices through 3.0808.0. It implements a function to connect the watch to a WLAN. With WLAN access, the COROS Pace 3 downloads firmware files via HTTP. However, the communication is not encrypted an…
- CVE-2025-32881MEDIUMCVSS 4.3EG 4.32025-05-01
An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. By default, the GID is the user's phone number unless they specifically opt out. A phone number is very sensitive information because it can be tied back to …
- CVE-2025-32884MEDIUMCVSS 4.3EG 4.32025-05-01
An issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. By default, a GID is the user's phone number unless they specifically opt out. A phone number is very sensitive information because it can be tied back to …
- CVE-2025-32887HIGHCVSS 7.1EG 7.12025-05-01
An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. A command channel includes the next hop. which can be intercepted and used to break frequency hopping.
- CVE-2025-3329LOWCVSS 3.1EG 3.12025-04-07
A vulnerability classified as problematic has been found in Consumer Comanda Mobile up to 14.9.3.2/15.0.0.8. This affects an unknown part of the component Restaurant Order Handler. The manipulation of the argument Login/Password leads to c…
- CVE-2025-34199HIGHCVSS 8.1EG 8.12025-09-19
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.1049 and Application versions prior to 20.0.2786 (VA and SaaS deployments) contain insecure defaults and code patterns that disable TLS/SSL certificate ver…
- CVE-2025-34271CRITICALCVSS 9.8EG 9.82025-10-30
Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the cluster manager component when requesting sensitive credentials from peer nodes over an unencrypted channel even when SSL/TLS is enabled in the product configur…
- CVE-2025-3480MEDIUMCVSS 6.5EG 6.52025-05-22
MedDream WEB DICOM Viewer Cleartext Transmission of Credentials Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of MedDream WEB DICOM Vi…
- CVE-2025-36020MEDIUMCVSS 5.9EG 5.92025-08-06
IBM Guardium Data Protection could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive credential information.
- CVE-2025-36034MEDIUMCVSS 5.3EG 5.32025-06-26
IBM InfoSphere DataStage Flow Designer in IBM InfoSphere Information Server 11.7 discloses sensitive user information in API requests in clear text that could be intercepted using man in the middle techniques.
- CVE-2025-36107MEDIUMCVSS 5.9EG 5.92025-07-21
IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could allow malicious actors to obtain sensitive information due to the cleartext transmission of data.
- CVE-2025-36274HIGHCVSS 7.5EG 7.52025-09-26
IBM Aspera HTTP Gateway 2.0.0 through 2.3.1 stores sensitive information in clear text in easily obtainable files which can be read by an unauthenticated user.
- CVE-2025-36336MEDIUMCVSS 5.9EG 5.92026-06-30
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.
- CVE-2025-40583MEDIUMCVSS 4.4EG 4.42025-05-13
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions with SINEMA Remote Connect Edge Client installed). Affected devices do transmit sensitive information in cleartext. This could allow a privileged l…
- CVE-2025-41708HIGHCVSS 7.4EG 7.42025-09-08
Due to an unsecure default configuration HTTP is used instead of HTTPS for the web interface. An unauthenticated attacker on the same network could exploit this to learn sensitive data during transmission.
- CVE-2025-41718HIGHCVSS 7.5EG 7.52025-10-14
A cleartext transmission of sensitive information vulnerability in the affected products allows an unauthorized remote attacker to gain login credentials and access the Web-UI.
- CVE-2025-4227LOWCVSS 3.5EG 3.52025-06-13
An improper access control vulnerability in the Endpoint Traffic Policy Enforcement https://docs.paloaltonetworks.com/globalprotect/6-0/globalprotect-app-new-features/new-features-released-in-gp-app/endpoint-traffic-policy-enforcement fe…
- CVE-2025-42603HIGHCVSS 8.7EG 8.72025-04-23
This vulnerability exists in the Meon KYC solutions due to transmission of sensitive data in plain text within the response payloads of certain API endpoints. An authenticated remote attacker could exploit this vulnerability by interceptin…
- CVE-2025-43013MEDIUMCVSS 6.9EG 6.92025-04-17
In JetBrains Toolbox App before 2.6 unencrypted credential transmission during SSH authentication was possible
- CVE-2025-43704MEDIUMCVSS 4.7EG 4.72025-04-16
Arctera/Veritas Data Insight before 7.1.2 can send cleartext credentials when configured to use HTTP Basic Authentication to a Dell Isilon OneFS server.
- CVE-2025-4378CRITICALCVSS 10.0EG 10.02025-06-24
Cleartext Transmission of Sensitive Information, Use of Hard-coded Credentials vulnerability in Ataturk University ATA-AOF Mobile Application allows Authentication Abuse, Authentication Bypass. This issue affects ATA-AOF Mobile Applicatio…
- CVE-2025-44251HIGHCVSS 7.5EG 7.52025-07-10
Ecovacs Deebot T10 1.7.2 transmits Wi-Fi credentials in cleartext during the pairing process.
- CVE-2025-44612MEDIUMCVSS 5.9EG 5.92025-05-30
Tinxy WiFi Lock Controller v1 RF was discovered to transmit sensitive information in plaintext, including control information and device credentials, allowing attackers to possibly intercept and access sensitive information via a man-in-th…
- CVE-2025-47419CRITICALCVSS 10.0EG 10.02025-05-06
Cleartext Transmission of Sensitive Information vulnerability in Crestron Automate VX allows Sniffing Network Traffic. The device allows Web UI and API access over non-secure network ports which exposes sensitive information such as user …
- CVE-2025-47698HIGHCVSS 8.6EG 8.62025-09-18
An adjacent attacker without authentication can exploit this vulnerability to retrieve a set of user-privileged credentials. These credentials are present during the firmware upgrade procedure.
- CVE-2025-49183HIGHCVSS 7.5EG 7.52025-06-12
All communication with the REST API is unencrypted (HTTP), allowing an attacker to intercept traffic between an actor and the webserver. This leads to the possibility of information gathering and downloading media files.
- CVE-2025-49194HIGHCVSS 7.5EG 7.52025-06-12
The server supports authentication methods in which credentials are sent in plaintext over unencrypted channels. If an attacker were to intercept traffic between a client and this server, the credentials would be exposed.
- CVE-2025-50110HIGHCVSS 8.8EG 8.82025-09-15
An issue was discovered in the method push.lite.avtech.com.AvtechLib.GetHttpsResponse in AVTECH EagleEyes Lite 2.0.0, the GetHttpsResponse method transmits sensitive information - including internal server URLs, account IDs, passwords, and…
- CVE-2025-5087MEDIUMCVSS 6.0EG 6.02025-06-24
Kaleris NAVIS N4 ULC (Ultra Light Client) communicates insecurely using zlib-compressed data over HTTP. An attacker capable of observing network traffic between Ultra Light Clients and N4 servers can extract sensitive information, includin…
- CVE-2025-52351HIGHCVSS 8.8EG 8.82025-08-21
Aikaan IoT management platform v3.25.0325-5-g2e9c59796 sends a newly generated password to users in plaintext via email and also includes the same password as a query parameter in the account activation URL (e.g., https://domain.com/activa…
- CVE-2025-52490HIGHCVSS 7.3EG 7.32025-07-29
An issue was discovered in Couchbase Sync Gateway before 3.2.6. In sgcollect_info_options.log and sync_gateway.log, there are cleartext passwords in redacted and unredacted output.
- CVE-2025-52586MEDIUMCVSS 6.9EG 6.92025-08-08
The MOD3 command traffic between the monitoring application and the inverter is transmitted in plaintext without encryption or obfuscation. This vulnerability may allow an attacker with access to a local network to intercept, manipulate…
- CVE-2025-5270HIGHCVSS 7.5EG 7.52025-05-27
In certain cases, SNI could have been sent unencrypted even when encrypted DNS was enabled. This vulnerability was fixed in Firefox 139 and Thunderbird 139.
- CVE-2025-53139HIGHCVSS 7.7EG 7.72025-10-14
Cleartext transmission of sensitive information in Windows Hello allows an unauthorized attacker to bypass a security feature locally.
Map vulnerabilities like CWE-319 to your infrastructure
EchelonGraph correlates every CVE — across CWE-319 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →