CWE-319— Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.— MITRE CWE catalog
913 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-319page 17 of 19
- CVE-2025-53703HIGHCVSS 7.5EG 7.52025-07-22
DuraComm SPM-500 DP-10iN-100-MU transmits sensitive data without encryption over a channel that could be intercepted by attackers.
- CVE-2025-53756HIGHCVSS 8.7EG 8.72025-07-16
This vulnerability exists in Digisol DG-GR6821AC Router due to cleartext transmission of credentials in its web management interface. A remote attacker could exploit this vulnerability by intercepting the network traffic and capturing clea…
- CVE-2025-53861LOWCVSS 3.1EG 3.12025-07-11
A flaw was found in Ansible. Sensitive cookies without security flags over non-encrypted channels can lead to Man-in-the-Middle (MitM) and Cross-site scripting (XSS) attacks allowing attackers to read transmitted data.
- CVE-2025-54156HIGHCVSS 7.4EG 7.42025-08-18
The Sante PACS Server Web Portal sends credential information without encryption.
- CVE-2025-54799LOWCVSS 2.3EG 2.32025-08-07
Let's Encrypt client and ACME library written in Go (Lego). In versions 4.25.1 and below, the github.com/go-acme/lego/v4/acme/api package (thus the lego library and the lego cli as well) don't enforce HTTPS when talking to CAs as an ACME c…
- CVE-2025-54818HIGHCVSS 8.0EG 8.02025-09-18
Cognex In-Sight Explorer and In-Sight Camera Firmware expose a proprietary protocol on TCP port 1069 to perform management operations such as modifying system properties. The user management functionality handles sensitive data such as…
- CVE-2025-55976HIGHCVSS 8.4EG 8.42025-09-10
Intelbras IWR 3000N 1.9.8 exposes the Wi-Fi password in plaintext via the /api/wireless endpoint. Any unauthenticated user on the local network can directly obtain the Wi-Fi network password by querying this endpoint.
- CVE-2025-56447CRITICALCVSS 9.8EG 9.82025-10-22
TM2 Monitoring v3.04 contains an authentication bypass and plaintext credential disclosure.
- CVE-2025-57727MEDIUMCVSS 4.7EG 4.72025-08-20
In JetBrains IntelliJ IDEA before 2025.2 credentials disclosure was possible via remote reference
- CVE-2025-58107HIGHCVSS 7.5EG 7.52026-03-02
In Microsoft Exchange through 2019, Exchange ActiveSync (EAS) configurations on on-premises servers may transmit sensitive data from Samsung mobile devices in cleartext, including the user's name, e-mail address, device ID, bearer token, a…
- CVE-2025-59406MEDIUMCVSS 6.2EG 6.22025-10-02
The Flock Safety Pisco com.flocksafety.android.pisco application 6.21.11 for Android (installed on Falcon and Sparrow License Plate Readers and Bravo Edge AI Compute Devices) has a cleartext Auth0 client secret in its codebase. Because app…
- CVE-2025-59448MEDIUMCVSS 4.7EG 4.72025-10-06
Components of the YoSmart YoLink ecosystem through 2025-10-02 leverage unencrypted MQTT to communicate over the internet. An attacker with the ability to monitor network traffic could therefore obtain sensitive information or tamper with t…
- CVE-2025-59852LOWCVSS 3.7EG 3.72026-05-06
HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability where data is transmitted over the network without encryption, which could allow an attacker to compromise the confidentiality, integrity, and authe…
- CVE-2025-61481CRITICALCVSS 10.0EG 10.02025-10-27
An issue in MikroTik RouterOS v.7.14.2 and SwOS v.2.18 exposes the WebFig management interface over cleartext HTTP by default, allowing an on-path attacker to execute injected JavaScript in the administrator’s browser and intercept crede…
- CVE-2025-61738LOWCVSS 2.3EG 2.32025-12-22
Under certain circumstances, attacker can capture the network key, read or write encrypted packets on the PowerG network.
- CVE-2025-6180HIGHCVSS 8.5EG 8.52025-08-20
The StrongDM Client insufficiently protected a pre-authentication token. Attackers could exploit this to intercept and reuse the token, potentially redeeming valid authentication credentials through a race condition.
- CVE-2025-62310MEDIUMCVSS 5.4EG 5.42026-05-14
HCL AION is affected by a vulnerability where encryption is not enforced for certain data transmissions or operations. This may expose sensitive information to potential interception or unauthorized access under specific conditions.
- CVE-2025-62311MEDIUMCVSS 4.3EG 4.32026-05-14
HCL AION is affected by a vulnerability where backend service details may be transmitted over insecure HTTP channels. This may expose sensitive information to potential interception or unauthorized access during transmission under certain …
- CVE-2025-62330MEDIUMCVSS 5.9EG 5.92025-12-16
HCL DevOps Deploy is susceptible to a cleartext transmission of sensitive information because the HTTP port remains accessible and does not redirect to HTTPS as intended. As a result, an attacker with network access could intercept or mod…
- CVE-2025-62578HIGHCVSS 7.5EG 7.52025-12-26
DVP-12SE - Modbus/TCP Cleartext Transmission of Sensitive Information
- CVE-2025-62643HIGHCVSS 8.6EG 8.62025-10-17
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 transmits passwords of user accounts in cleartext e-mail messages.
- CVE-2025-62765HIGHCVSS 7.5EG 7.52025-11-15
General Industrial Controls Lynx+ Gateway is vulnerable to a cleartext transmission vulnerability that could allow an attacker to observe network traffic to obtain sensitive information, including plaintext credentials.
- CVE-2025-63292LOWCVSS 3.5EG 3.52025-11-17
Freebox v5 HD (firmware = 1.7.20), Freebox v5 Crystal (firmware = 1.7.20), Freebox v6 Révolution r1–r3 (firmware = 4.7.x), Freebox Mini 4K (firmware = 4.7.x), and Freebox One (firmware = 4.7.x) were discovered to expose subscribers' IMS…
- CVE-2025-63364HIGHCVSS 7.5EG 7.52025-12-04
Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.002880.0301 was discovered to transmit Administrator credentials in plaintext.
- CVE-2025-64389HIGHCVSS 8.3EG 8.32025-10-31
The web server of the device performs exchanges of sensitive information in clear text through an insecure protocol.
- CVE-2025-64648MEDIUMCVSS 5.9EG 5.92026-03-25
IBM Concert 1.0.0 through 2.2.0 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.
- CVE-2025-64769HIGHCVSS 7.1EG 7.12026-01-16
The Process Optimization application suite leverages connection channels/protocols that by-default are not encrypted and could become subject to hijacking or data leakage in certain man-in-the-middle or passive inspection scenarios.
- CVE-2025-65827CRITICALCVSS 9.1EG 9.12025-12-10
The mobile application is configured to allow clear text traffic to all domains and communicates with an API server over HTTP. As a result, an adversary located "upstream" can intercept the traffic, inspect its contents, and modify the req…
- CVE-2025-65855MEDIUMCVSS 6.6EG 6.62025-12-17
The OTA firmware update mechanism in Netun Solutions HelpFlash IoT (firmware v18_178_221102_ASCII_PRO_1R5_50) uses hard-coded WiFi credentials identical across all devices and does not authenticate update servers or validate firmware signa…
- CVE-2025-66573HIGHCVSS 6.9EG 7.52025-12-04
Solstice Pod API (version 5.5, 6.2) contains an unauthenticated API endpoint (`/api/config`) that exposes sensitive information such as the session key, server version, product details, and display name. Unauthorized users can extract live…
- CVE-2025-66604MEDIUMCVSS 5.3EG 5.32026-02-09
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The library version could be displayed on the web page. This information could be exploited by an attacker for other attacks. The affected produc…
- CVE-2025-67159HIGHCVSS 7.5EG 7.52026-01-02
Vatilon v1.12.37-20240124 was discovered to transmit user credentials in plaintext.
- CVE-2025-69272HIGHCVSS 7.5EG 7.52026-01-12
Cleartext Transmission of Sensitive Information vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Sniffing Attacks.This issue affects DX NetOps Spectrum: 21.2.1 and earlier.
- CVE-2025-69969CRITICALCVSS 9.6EG 9.62026-03-04
A lack of authentication and authorization mechanisms in the Bluetooth Low Energy (BLE) communication protocol of SRK Powertech Pvt Ltd Pebble Prism Ultra v2.9.2 allows attackers to reverse engineer the protocol and execute arbitrary comma…
- CVE-2025-70048HIGHCVSS 7.5EG 7.52026-03-09
An issue pertaining to CWE-319: Cleartext Transmission of Sensitive Information was discovered in Nexusoft NexusInterface v3.2.0-beta.2.
- CVE-2025-7731HIGHCVSS 7.5EG 7.52025-09-01
Cleartext Transmission of Sensitive Information vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU module allows a remote unauthenticated attacker to obtain credential information by intercepting SLMP communication mes…
- CVE-2025-7743CRITICALCVSS 9.6EG 9.62025-09-16
Cleartext Transmission of Sensitive Information vulnerability in Dolusoft Omaspot allows Interception, Privilege Escalation. This issue affects Omaspot: before 12.09.2025.
- CVE-2025-8205LOWCVSS 3.7EG 3.72025-07-26
A vulnerability, which was classified as problematic, has been found in Comodo Dragon up to 134.0.6998.179. Affected by this issue is some unknown functionality of the component IP DNS Leakage Detector. The manipulation leads to cleartext …
- CVE-2025-8741MEDIUMCVSS 5.9EG 5.92025-08-08
A vulnerability was found in macrozheng mall up to 1.0.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/login. The manipulation leads to cleartext transmission of sensiti…
- CVE-2025-8863HIGHCVSS 7.0EG 7.02025-08-11
YugabyteDB diagnostic information was transmitted over HTTP, which could expose sensitive data during transmission
- CVE-2026-0714MEDIUMCVSS 6.8EG 6.82026-02-05
A physical attack vulnerability exists in certain Moxa industrial computers using TPM-backed LUKS full-disk encryption on Moxa Industrial Linux 3, where the discrete TPM is connected to the CPU via an SPI bus. Exploitation requires invasi…
- CVE-2026-0767MEDIUMCVSS 6.5EG 6.52026-01-23
Open WebUI Cleartext Transmission of Credentials Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Open WebUI. Authentication is not re…
- CVE-2026-1014MEDIUMCVSS 6.5EG 6.52026-03-25
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to exposure of sensitive information via JSON server response manipulation.
- CVE-2026-10584MEDIUMCVSS 5.9EG 5.92026-06-02
Proxy server in Graph Explorer before 3.0.1 falls back to HTTP when certificate files are missing, which might allow remote threat actors to obtain sensitive information via interception of requests intended to be sent over HTTPS. To re…
- CVE-2026-11833HIGHCVSS 8.2EG 8.22026-06-23
Overview: A vulnerability has been found in FAST/TOOLS and CI Server. The web server may return a response containing the CI Server setting information. This information could be exploited by an attacker for other attacks. The affected…
- CVE-2026-1777HIGHCVSS 7.2EG 7.22026-02-02
The Amazon SageMaker Python SDK before v3.2.0 and v2.256.0 includes the ModelBuilder HMAC signing key in the cleartext response elements of the DescribeTrainingJob function. A third party with permissions to both call this API and permissi…
- CVE-2026-20115MEDIUMCVSS 6.1EG 6.12026-03-25
A vulnerability in Cisco IOS XE Software for Cisco Meraki could allow a remote, unauthenticated attacker to view confidential device information. This vulnerability is due to a device configuration upload being performed over an insecur…
- CVE-2026-20801MEDIUMCVSS 5.6EG 5.62026-03-03
Cleartext Transmission of Sensitive Information (CWE-319) in a component used in the Gallagher Hanwha VMS and Gallagher NxWitness VMS integrations allows unprivileged users with local network access to view live video streams. This …
- CVE-2026-21742MEDIUMCVSS 6.5EG 6.52026-04-14
A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.…
- CVE-2026-22079HIGHCVSS 8.7EG 8.72026-01-09
This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the plaintext transmission of login credentials during the initial login or post-factory reset setup through the web-based a…
Map vulnerabilities like CWE-319 to your infrastructure
EchelonGraph correlates every CVE — across CWE-319 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →