CWE-319: CWE-319

172
Total CVEs
24
Critical
95
High
7.4
Avg CVSS

Yearly Trend

2026
19
2025
57
2024
33
2023
29
2022
13

Top Affected Vendors

1 Ibm 10
2 Moxa 4
3 Gotenna 4
4 Dell 4
5 Sick 4
6 Netgear 4
7 Loytec 2
8 Netapp 2
9 Sauter Controls 2
10 Microsoft 2

All CWE-319 CVEs (172)

CVE-2021-34825
7.5

Quassel IRC client versions through 0.13.1 fail to enforce SSL/TLS when started with the --require-ssl flag if a valid X.509 certificate is not availa...

Jun 17, 2021
CVE-2020-27185
7.5

CVE-2020-27185 allows attackers to intercept authentication data, device configurations, and other sensitive information transmitted in cleartext via ...

May 14, 2021
CVE-2021-31671
7.5

CVE-2021-31671 is an information disclosure vulnerability in pgsync that can expose sensitive database connection parameters. When using --schema-firs...

Apr 27, 2021
CVE-2019-18231
7.5

This vulnerability in Advantech Spectre RT ERT351 routers allows attackers to intercept login credentials transmitted in clear text. Affected systems ...

Mar 17, 2021
CVE-2020-4695
7.5

IBM API Connect V10 uses unencrypted database replication traffic, allowing attackers to intercept and view sensitive data. This affects organizations...

Mar 8, 2021
CVE-2025-41708
7.4

This vulnerability allows unauthenticated attackers on the same network to intercept sensitive data transmitted to the web interface due to HTTP being...

Sep 8, 2025
CVE-2025-27720
7.4

The Pixmeo Osirix MD Web Portal transmits user credentials in cleartext without encryption, allowing attackers to intercept and steal login informatio...

May 8, 2025
CVE-2023-2754
7.4

The Cloudflare WARP client for Windows incorrectly assigns Unique Local IPv6 addresses instead of loopback addresses for DNS servers when connected ov...

Aug 3, 2023
CVE-2022-1524
7.4

CVE-2022-1524 affects LRM (Logistics Resource Management) versions 2.4 and lower, which lack TLS encryption for data transmission. This allows attacke...

Jun 24, 2022
CVE-2021-45104
7.4

This vulnerability in HTCondor allows attackers who can intercept network traffic to interfere with user jobs and data. It affects HTCondor installati...

Apr 6, 2022
CVE-2021-3774
7.4

The Meross Smart Wi-Fi 2 Way Wall Switch (MSS550X) creates an open Wi-Fi access point without encryption during initial setup, allowing remote attacke...

Nov 5, 2021
CVE-2021-23018
7.4

CVE-2021-23018 is a cleartext communication vulnerability in NGINX Controller where intra-cluster services communicate without TLS encryption. This al...

Jun 1, 2021
CVE-2024-44276
7.3

This vulnerability allows attackers on the same network to intercept and view sensitive information transmitted by affected Apple devices. It affects ...

Mar 17, 2025
CVE-2024-25960
7.3

Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x transmit sensitive information in cleartext, allowing a local low-privileged attacker to interc...

Mar 28, 2024
CVE-2023-36673
7.3

This vulnerability in Avira Phantom VPN for macOS allows attackers to bypass VPN encryption and redirect traffic to arbitrary IP addresses in plaintex...

Aug 9, 2023
CVE-2026-1777
7.2

The Amazon SageMaker Python SDK before v3.2.0 and v2.256.0 exposes the ModelBuilder HMAC signing key in cleartext via the DescribeTrainingJob API. Thi...

Feb 2, 2026
CVE-2025-64769
7.1

The Process Optimization application suite uses unencrypted communication channels by default, allowing attackers to intercept, modify, or steal sensi...

Jan 16, 2026
CVE-2025-32887
7.1

This vulnerability in goTenna v1 devices allows attackers to intercept command channels containing next-hop information, which can be used to break fr...

May 1, 2025
CVE-2025-24849
7.1

This vulnerability involves cloud infrastructure transmitting sensitive data without encryption, allowing attackers to intercept, manipulate, or expos...

Feb 28, 2025
CVE-2025-52586
6.9

This CVE describes a cleartext transmission vulnerability in MOD3 command traffic between monitoring applications and inverters. Attackers on the loca...

Aug 8, 2025
CVE-2026-0714
6.8

This CVE describes a physical attack vulnerability in Moxa industrial computers where an attacker with invasive physical access can capture TPM commun...

Feb 5, 2026
CVE-2024-32384
6.8

Kerlink gateways running KerOS versions before 5.10 expose their web interface over unencrypted HTTP only, without HTTPS support. This allows man-in-t...

Dec 1, 2025
CVE-2025-26654
6.8

SAP Commerce Cloud (Public Cloud) has a vulnerability where HTTP port 80 cannot be fully disabled, only redirected to HTTPS port 443. This exposes the...

Apr 8, 2025
CVE-2024-45102
6.8

This privilege escalation vulnerability allows authenticated Lenovo XClarity Administrator (LXCA) users to gain elevated permissions on connected XCla...

Jan 14, 2025
CVE-2024-45101
6.8

This privilege escalation vulnerability in Lenovo XClarity Controller Administrator (LXCA) with Single Sign-On enabled allows attackers to hijack auth...

Sep 13, 2024
CVE-2025-65855
6.6

This vulnerability allows attackers with brief physical access to Netun Solutions HelpFlash IoT devices to execute arbitrary code by exploiting the in...

Dec 17, 2025
CVE-2026-23564
6.5

A vulnerability in TeamViewer DEX Client's Content Distribution Service (NomadBranch.exe) allows attackers on adjacent networks to force encrypted UDP...

Jan 29, 2026
CVE-2026-22274
6.5

Dell ECS and ObjectScale systems transmit sensitive information in cleartext via Fabric Syslog, allowing unauthenticated attackers with network access...

Jan 23, 2026
CVE-2026-0767
6.5

Open WebUI transmits credentials in plaintext, allowing network-adjacent attackers to intercept authentication data without authentication. This affec...

Jan 23, 2026
CVE-2025-27457
6.5

CVE-2025-27457 is a cleartext transmission vulnerability in VNC communications that allows attackers to intercept unencrypted traffic between VNC serv...

Jul 3, 2025
CVE-2024-11946
6.5

This vulnerability allows network-adjacent attackers to intercept and tamper with TrueNAS firmware update files transmitted in cleartext. Attackers ca...

Dec 30, 2024
CVE-2024-38167
6.5

This vulnerability in .NET and Visual Studio allows attackers to read sensitive information from memory that should be protected. It affects applicati...

Aug 13, 2024
CVE-2024-6972
6.5

Octopus Server versions before 2024.2.10998 may expose sensitive variables like passwords and API keys in task logs in clear-text under certain circum...

Jul 25, 2024
CVE-2023-27927
6.5

This vulnerability allows authenticated malicious users to retrieve SMTP passwords in cleartext from systems where passwords are masked with asterisks...

Mar 27, 2023
CVE-2022-41545
6.4

This vulnerability exposes Netgear C7800 router administrative credentials to eavesdropping attacks. Attackers can intercept base64-encoded credential...

Feb 18, 2025
CVE-2024-32864
6.4

CVE-2024-32864 is a security misconfiguration vulnerability in exacqVision Web Services where HTTPS enforcement fails under certain circumstances, all...

Aug 1, 2024
CVE-2024-37163
6.4

SkyScrape version 1.0.0 transmits API requests over unsecured HTTP instead of HTTPS, exposing temporary AWS credentials and sensitive infrastructure d...

Jun 7, 2024
CVE-2025-59406
6.2

The Flock Safety Pisco Android application contains a hardcoded Auth0 client secret in its codebase, allowing attackers to extract this credential thr...

Oct 2, 2025
CVE-2025-13490
5.9

IBM App Connect Enterprise Certified Container transmits sensitive data in clear text without encryption, allowing attackers to intercept information ...

Mar 3, 2026
CVE-2025-62330
5.9

HCL DevOps Deploy transmits sensitive information in cleartext over HTTP instead of redirecting to HTTPS as intended. This allows attackers with netwo...

Dec 16, 2025
CVE-2025-13489
5.9

IBM DevOps Deploy versions 8.1 through 8.1.2.3 transmit sensitive data in unencrypted plain text, allowing attackers to intercept and read confidentia...

Dec 15, 2025
CVE-2024-48894
5.9

This CVE describes a cleartext transmission vulnerability in Socomec DIRIS Digiware M-70's WEBVIEW-M functionality, allowing attackers to intercept un...

Dec 1, 2025
CVE-2025-36020
5.9

IBM Guardium Data Protection transmits sensitive credential information in cleartext, allowing remote attackers to intercept and obtain authentication...

Aug 6, 2025
CVE-2024-43187
5.9

IBM Security Verify Access Appliance and Container versions 10.0.0 through 10.0.8 transmit sensitive data in cleartext over network channels, allowing...

Feb 4, 2025
CVE-2023-35017
5.9

IBM Security Verify Governance 10.0.2 Identity Manager transmits user credentials in clear text during communication, allowing attackers to intercept ...

Jan 29, 2025
CVE-2021-29892
5.9

CVE-2021-29892 is an information disclosure vulnerability in IBM Cognos Controller where HTTP Strict Transport Security (HSTS) is not properly enabled...

Dec 3, 2024
CVE-2024-37183
5.7

CVE-2024-37183 allows attackers to capture plain text credentials and session IDs using network sniffing tools. This affects industrial control system...

Jun 20, 2024
CVE-2026-20801
5.6

This vulnerability allows unprivileged users on the local network to view live video streams transmitted in cleartext. It affects Gallagher NxWitness ...

Mar 3, 2026
CVE-2025-22493
5.6

This vulnerability in Foreseer Reporting Software (FRS) allows session cookies to be transmitted over unencrypted HTTP connections due to missing Secu...

Mar 5, 2025
CVE-2025-13454
5.5

This vulnerability in ThinkPlus configuration software allows local authenticated users to access sensitive device information they shouldn't normally...

Jan 14, 2026

About CWE-319 (CWE-319)

Our database tracks 172 CVEs classified as CWE-319, with 24 rated critical and 95 rated high severity. The average CVSS score for CWE-319 vulnerabilities is 7.4.

External reference: View CWE-319 on MITRE CWE →

Monitor CWE-319 Vulnerabilities

Get alerted when new CWE-319 CVEs affect your infrastructure.

Start Monitoring Free