CWE-319— Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.— MITRE CWE catalog
913 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-319page 18 of 19
- CVE-2026-22080HIGHCVSS 8.7EG 8.72026-01-09
This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the transmission of credentials encoded using reversible Base64 encoding through the web-based administrative interface. An …
- CVE-2026-22155HIGHCVSS 7.5EG 7.52026-04-14
A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.…
- CVE-2026-22271HIGHCVSS 7.5EG 7.52026-01-23
Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Transmission of Sensitive Information vulnerability. An unauthenticated attacker with remote access could potentially exploit …
- CVE-2026-22274MEDIUMCVSS 6.5EG 6.52026-01-23
Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Transmission of Sensitive Information vulnerability in the Fabric Syslog. An unauthenticated attacker with remote access could…
- CVE-2026-22544HIGHCVSS 8.7EG 8.72026-01-07
An attacker with a network connection could detect credentials in clear text.
- CVE-2026-23564MEDIUMCVSS 6.5EG 6.52026-01-29
A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an attacker on the adjacent network to cause normally encrypted UDP traffic to be sent in cl…
- CVE-2026-23661HIGHCVSS 7.5EG 7.52026-03-10
Cleartext transmission of sensitive information in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.
- CVE-2026-23662HIGHCVSS 7.5EG 7.52026-03-10
Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.
- CVE-2026-24060CRITICALCVSS 9.1EG 9.12026-03-21
Service information is not encrypted when transmitted as BACnet packets over the wire, and can be sniffed, intercepted, and modified by an attacker. Valuable information such as the File Start Position and File Data can be sniffed from …
- CVE-2026-24212CRITICALCVSS 9.8EG 9.82026-05-26
NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is transmitted in clear text. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure,…
- CVE-2026-24441MEDIUMCVSS 5.9EG 5.92026-02-03
Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior expose account credentials in plaintext within HTTP responses, allowing an on-path attacker to obtain sensitive authentication material.
- CVE-2026-24455HIGHCVSS 7.5EG 7.52026-02-20
The embedded web interface of the device does not support HTTPS/TLS for authentication and uses HTTP Basic Authentication. Traffic is encoded but not encrypted, exposing user credentials to passive interception by attackers on the same …
- CVE-2026-2539MEDIUMCVSS 5.7EG 5.72026-02-15
The RF communication protocol in the Micca KE700 car alarm system does not encrypt its data frames. An attacker with a radio interception tool (e.g., SDR) can capture the random number and counters transmitted in cleartext, which is sensi…
- CVE-2026-25599MEDIUMCVSS 6.3EG 6.32026-06-01
Missing authentication and clear‑text transmission of data from the heat pumps to the control server, combined with the absence of input validation on aggregated data, can lead to stored XSS that enables theft of cookies from the pump’…
- CVE-2026-25608LOWCVSS 2.3EG 2.32026-05-22
STER uses unencrypted TCP traffic to transmit data over the network. It allows an attacker to conduct a Man-In-The-Middle attack and obtain sensitive data such as passwords, personal data, or authentication tokens. This issue was fixed …
- CVE-2026-2671LOWCVSS 3.1EG 3.12026-03-07
A vulnerability was detected in Mendi Neurofeedback Headset V4. Affected by this vulnerability is an unknown functionality of the component Bluetooth Low Energy Handler. Performing a manipulation results in cleartext transmission of sensit…
- CVE-2026-27752MEDIUMCVSS 5.9EG 5.92026-02-27
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 transmit authentication credentials over unencrypted HTTP, allowing attackers to capture credentials. An attacker positioned to observe network traffic between a user and the devic…
- CVE-2026-30795HIGHCVSS 7.5EG 7.52026-03-05
Cleartext Transmission of Sensitive Information vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Heartbeat sync loop modules) allows Sniffing Attacks. This vulnerability is associated…
- CVE-2026-30796HIGHCVSS 7.5EG 7.52026-03-05
Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Address book sync, Heartbeat sync loop modules) …
- CVE-2026-3182MEDIUMCVSS 4.3EG 4.32026-07-21
Zohocorp ManageEngine Endpoint Central versions before 11.4.2528.34 are affected by cleartext transmission of sensitive information vulnerability.
- CVE-2026-31923HIGHCVSS 7.5EG 7.52026-04-14
Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. This can occur due to `ssl_verify` in openid-connect plugin configuration being set to false by default. This issue affects Apache APISIX: from 0.7 through 3.…
- CVE-2026-31924MEDIUMCVSS 5.3EG 5.32026-04-14
Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. tencent-cloud-cls log export uses plaintext HTTP This issue affects Apache APISIX: from 2.99.0 through 3.15.0. Users are recommended to upgrade to version 3.…
- CVE-2026-32309HIGHCVSS 7.5EG 7.52026-03-20
Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, the Hub-based unlock flow explicitly supports hub+http and consumes Hub endpoints from vault metadata without enforcing HTTPS. As a result, a vault co…
- CVE-2026-32683MEDIUMCVSS 5.3EG 5.32026-05-09
Some EZVIZ products utilize older versions of cloud feature modules with legacy API interfaces, which pose a data transmission risk. Attackers can exploit this by eavesdropping on network requests to obtain data.Users are advised to upgrad…
- CVE-2026-32745MEDIUMCVSS 5.7EG 6.32026-03-13
In JetBrains Datalore before 2026.1 session hijacking was possible due to missing secure attribute for cookie settings
- CVE-2026-32838HIGHCVSS 5.9EG 7.52026-03-17
Edimax GS-5008PL firmware version 1.00.54 and prior use cleartext HTTP for the web management interface without implementing TLS or SSL encryption. Attackers on the same network can intercept management traffic to capture administrator cre…
- CVE-2026-33472MEDIUMCVSS 4.8EG 4.82026-04-16
Cryptomator is an open-source client-side encryption application for cloud storage. Version 1.19.1 contains a logic flaw in CheckHostTrustController.getAuthority() that allows an attacker to bypass the security fix for CVE-2026-32303. The …
- CVE-2026-33569MEDIUMCVSS 6.5EG 6.52026-04-17
Anviz CX2 Lite and CX7 administrative sessions occur over HTTP, enabling on‑path attackers to sniff credentials and session data, which can be used to compromise the device.
- CVE-2026-34126HIGHCVSS 7.5EG 7.52026-05-28
TP-Link has identified a vulnerability in Tapo L535E v1.0 and v3.0, Tapo P300 v1.0, and Tapo D100C v1.0, where Bluetooth communication during the initial setup phase is transmitted in cleartext without encryption. Bluetooth is only used d…
- CVE-2026-34346MEDIUMCVSS 5.5EG 5.52026-07-14
Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.
- CVE-2026-36610MEDIUMCVSS 5.9EG 5.92026-06-03
Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 transmits DDNS credentials over plaintext HTTP with only Base64 encoding. The firmware contains no TLS implementation, allowing man-in-the-middle interception of DDNS service credent…
- CVE-2026-38740MEDIUMCVSS 5.3EG 5.32026-05-14
Foscam VD1 Video Doorbell before V5.3.13_1072 is vulnerable to Cleartext Transmission of Sensitive Information. The device transmits sensitive Session Description Protocol (SDP), including ICE credentials and candidates, in cleartext over …
- CVE-2026-40045MEDIUMCVSS 5.7EG 5.72026-04-21
OpenClaw before 2026.4.2 accepts non-loopback cleartext ws:// gateway endpoints and transmits stored gateway credentials over unencrypted connections. Attackers can forge discovery results or craft setup codes to redirect clients to malici…
- CVE-2026-40431MEDIUMCVSS 5.3EG 5.32026-04-24
A vulnerability exists in SenseLive X3050’s web management interface due to its reliance on unencrypted HTTP for all administrative communication. Because management traffic, including authentication attempts and configuration data, is…
- CVE-2026-41275HIGHCVSS 7.5EG 7.52026-04-23
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the password reset functionality on cloud.flowiseai.com sends a reset password link over the unsecured HTTP protocol instead of HTTPS.…
- CVE-2026-41281MEDIUMCVSS 4.8EG 4.82026-05-14
Android App "あんしんフィルター for au" provided by KDDI CORPORATION contains Cleartext Transmission of Sensitive Information (CWE-319) vulnerability. A man-in-the-middle attacker may access and modify communications transmitted i…
- CVE-2026-42514HIGHCVSS 8.8EG 8.82026-04-29
This vulnerability exists in e-Sushrut due to exposure of OTPs in plaintext within API responses. A remote attacker could exploit this vulnerability by intercepting API responses containing valid OTPs. Successful exploitation of this vuln…
- CVE-2026-43625MEDIUMCVSS 5.9EG 5.92026-06-01
CodexBar prior to 0.32.0 contains a session cookie leakage vulnerability that allows network attackers to intercept imported browser session cookies by exploiting improper redirect handling for Amp and Ollama provider sessions. Attackers c…
- CVE-2026-44726CRITICALCVSS 9.1EG 9.12026-05-27
Deno is a JavaScript, TypeScript, and WebAssembly runtime. From 2.0.0 until 2.7.8, a flaw in Deno's Node.js tls compatibility layer could cause a TLS client to transmit application data in plaintext after a connection retry. When `autoSele…
- CVE-2026-45179MEDIUMCVSS 5.3EG 5.32026-05-10
Plack::Middleware::Statsd versions before 0.9.0 for Perl may leak user IP addresses. If the communication channel to the statsd daemon is not secured (for example, by sending UDP packets to a host on another network), then users' IP addre…
- CVE-2026-45180HIGHCVSS 7.5EG 7.52026-05-10
Catalyst::Plugin::Statsd versions through 0.10.0 for Perl may leak session ids. If the communication channel to the statsd daemon is not secured (for example, by sending UDP packets to a host on another network), then users' session ids m…
- CVE-2026-45432HIGHCVSS 8.7EG 8.72026-06-04
This vulnerability exists in GX Earth ONT models due to the transmission of user credentials in plaintext over HTTP in its web management interface. A remote attacker could exploit this vulnerability by intercepting network traffic to obta…
- CVE-2026-4584LOWCVSS 3.1EG 3.12026-03-23
A flaw has been found in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. This affects an unknown part of the component Cardholder Data Handler. Executing a manipulation can lead to cleartext transmission of sensitive information. The attack …
- CVE-2026-47255HIGHCVSS 8.2EG 8.22026-05-29
AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0.9.10 had weakness related to validation and and binding of inactive-agent hour filtering;…
- CVE-2026-48022MEDIUMCVSS 6.5EG 6.52026-06-11
@hapi/wreck is an HTTP client utility. Prior to 18.1.2, Wreck strips credential headers including Authorization, Cookie, and Proxy-Authorization before following a cross-origin redirect, but the origin check compares hostnames only and ign…
- CVE-2026-4820MEDIUMCVSS 4.3EG 4.32026-04-01
IBM Maximo Application Suite 9.1, 9.0, 8.11, and 8.10 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link…
- CVE-2026-4873MEDIUMCVSS 5.9EG 5.92026-05-13
A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool. If an initial transfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request to th…
- CVE-2026-48902CRITICALCVSS 9.8EG 9.82026-05-26
The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.
- CVE-2026-48978LOWCVSS 2.1EG 2.12026-07-01
oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, auth.Client follows the realm URL from a registry's WWW-Authenticate: Bearer challenge without validating the scheme or host, allowing a malicious or compromised registry …
- CVE-2026-49486HIGHCVSS 7.5EG 7.52026-06-26
The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p()`, so although the control channel was TLS-protected the data channel was transmitted in cleartext. Any deployment usi…
Map vulnerabilities like CWE-319 to your infrastructure
EchelonGraph correlates every CVE — across CWE-319 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →