CWE-319: CWE-319
Yearly Trend
Top Affected Vendors
All CWE-319 CVEs (172)
Quassel IRC client versions through 0.13.1 fail to enforce SSL/TLS when started with the --require-ssl flag if a valid X.509 certificate is not availa...
Jun 17, 2021CVE-2020-27185 allows attackers to intercept authentication data, device configurations, and other sensitive information transmitted in cleartext via ...
May 14, 2021CVE-2021-31671 is an information disclosure vulnerability in pgsync that can expose sensitive database connection parameters. When using --schema-firs...
Apr 27, 2021This vulnerability in Advantech Spectre RT ERT351 routers allows attackers to intercept login credentials transmitted in clear text. Affected systems ...
Mar 17, 2021IBM API Connect V10 uses unencrypted database replication traffic, allowing attackers to intercept and view sensitive data. This affects organizations...
Mar 8, 2021This vulnerability allows unauthenticated attackers on the same network to intercept sensitive data transmitted to the web interface due to HTTP being...
Sep 8, 2025The Pixmeo Osirix MD Web Portal transmits user credentials in cleartext without encryption, allowing attackers to intercept and steal login informatio...
May 8, 2025The Cloudflare WARP client for Windows incorrectly assigns Unique Local IPv6 addresses instead of loopback addresses for DNS servers when connected ov...
Aug 3, 2023CVE-2022-1524 affects LRM (Logistics Resource Management) versions 2.4 and lower, which lack TLS encryption for data transmission. This allows attacke...
Jun 24, 2022This vulnerability in HTCondor allows attackers who can intercept network traffic to interfere with user jobs and data. It affects HTCondor installati...
Apr 6, 2022The Meross Smart Wi-Fi 2 Way Wall Switch (MSS550X) creates an open Wi-Fi access point without encryption during initial setup, allowing remote attacke...
Nov 5, 2021CVE-2021-23018 is a cleartext communication vulnerability in NGINX Controller where intra-cluster services communicate without TLS encryption. This al...
Jun 1, 2021This vulnerability allows attackers on the same network to intercept and view sensitive information transmitted by affected Apple devices. It affects ...
Mar 17, 2025Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x transmit sensitive information in cleartext, allowing a local low-privileged attacker to interc...
Mar 28, 2024This vulnerability in Avira Phantom VPN for macOS allows attackers to bypass VPN encryption and redirect traffic to arbitrary IP addresses in plaintex...
Aug 9, 2023The Amazon SageMaker Python SDK before v3.2.0 and v2.256.0 exposes the ModelBuilder HMAC signing key in cleartext via the DescribeTrainingJob API. Thi...
Feb 2, 2026The Process Optimization application suite uses unencrypted communication channels by default, allowing attackers to intercept, modify, or steal sensi...
Jan 16, 2026This vulnerability in goTenna v1 devices allows attackers to intercept command channels containing next-hop information, which can be used to break fr...
May 1, 2025This vulnerability involves cloud infrastructure transmitting sensitive data without encryption, allowing attackers to intercept, manipulate, or expos...
Feb 28, 2025This CVE describes a cleartext transmission vulnerability in MOD3 command traffic between monitoring applications and inverters. Attackers on the loca...
Aug 8, 2025This CVE describes a physical attack vulnerability in Moxa industrial computers where an attacker with invasive physical access can capture TPM commun...
Feb 5, 2026Kerlink gateways running KerOS versions before 5.10 expose their web interface over unencrypted HTTP only, without HTTPS support. This allows man-in-t...
Dec 1, 2025SAP Commerce Cloud (Public Cloud) has a vulnerability where HTTP port 80 cannot be fully disabled, only redirected to HTTPS port 443. This exposes the...
Apr 8, 2025This privilege escalation vulnerability allows authenticated Lenovo XClarity Administrator (LXCA) users to gain elevated permissions on connected XCla...
Jan 14, 2025This privilege escalation vulnerability in Lenovo XClarity Controller Administrator (LXCA) with Single Sign-On enabled allows attackers to hijack auth...
Sep 13, 2024This vulnerability allows attackers with brief physical access to Netun Solutions HelpFlash IoT devices to execute arbitrary code by exploiting the in...
Dec 17, 2025A vulnerability in TeamViewer DEX Client's Content Distribution Service (NomadBranch.exe) allows attackers on adjacent networks to force encrypted UDP...
Jan 29, 2026Dell ECS and ObjectScale systems transmit sensitive information in cleartext via Fabric Syslog, allowing unauthenticated attackers with network access...
Jan 23, 2026Open WebUI transmits credentials in plaintext, allowing network-adjacent attackers to intercept authentication data without authentication. This affec...
Jan 23, 2026CVE-2025-27457 is a cleartext transmission vulnerability in VNC communications that allows attackers to intercept unencrypted traffic between VNC serv...
Jul 3, 2025This vulnerability allows network-adjacent attackers to intercept and tamper with TrueNAS firmware update files transmitted in cleartext. Attackers ca...
Dec 30, 2024This vulnerability in .NET and Visual Studio allows attackers to read sensitive information from memory that should be protected. It affects applicati...
Aug 13, 2024Octopus Server versions before 2024.2.10998 may expose sensitive variables like passwords and API keys in task logs in clear-text under certain circum...
Jul 25, 2024This vulnerability allows authenticated malicious users to retrieve SMTP passwords in cleartext from systems where passwords are masked with asterisks...
Mar 27, 2023This vulnerability exposes Netgear C7800 router administrative credentials to eavesdropping attacks. Attackers can intercept base64-encoded credential...
Feb 18, 2025CVE-2024-32864 is a security misconfiguration vulnerability in exacqVision Web Services where HTTPS enforcement fails under certain circumstances, all...
Aug 1, 2024SkyScrape version 1.0.0 transmits API requests over unsecured HTTP instead of HTTPS, exposing temporary AWS credentials and sensitive infrastructure d...
Jun 7, 2024The Flock Safety Pisco Android application contains a hardcoded Auth0 client secret in its codebase, allowing attackers to extract this credential thr...
Oct 2, 2025IBM App Connect Enterprise Certified Container transmits sensitive data in clear text without encryption, allowing attackers to intercept information ...
Mar 3, 2026HCL DevOps Deploy transmits sensitive information in cleartext over HTTP instead of redirecting to HTTPS as intended. This allows attackers with netwo...
Dec 16, 2025IBM DevOps Deploy versions 8.1 through 8.1.2.3 transmit sensitive data in unencrypted plain text, allowing attackers to intercept and read confidentia...
Dec 15, 2025This CVE describes a cleartext transmission vulnerability in Socomec DIRIS Digiware M-70's WEBVIEW-M functionality, allowing attackers to intercept un...
Dec 1, 2025IBM Guardium Data Protection transmits sensitive credential information in cleartext, allowing remote attackers to intercept and obtain authentication...
Aug 6, 2025IBM Security Verify Access Appliance and Container versions 10.0.0 through 10.0.8 transmit sensitive data in cleartext over network channels, allowing...
Feb 4, 2025IBM Security Verify Governance 10.0.2 Identity Manager transmits user credentials in clear text during communication, allowing attackers to intercept ...
Jan 29, 2025CVE-2021-29892 is an information disclosure vulnerability in IBM Cognos Controller where HTTP Strict Transport Security (HSTS) is not properly enabled...
Dec 3, 2024CVE-2024-37183 allows attackers to capture plain text credentials and session IDs using network sniffing tools. This affects industrial control system...
Jun 20, 2024This vulnerability allows unprivileged users on the local network to view live video streams transmitted in cleartext. It affects Gallagher NxWitness ...
Mar 3, 2026This vulnerability in Foreseer Reporting Software (FRS) allows session cookies to be transmitted over unencrypted HTTP connections due to missing Secu...
Mar 5, 2025This vulnerability in ThinkPlus configuration software allows local authenticated users to access sensitive device information they shouldn't normally...
Jan 14, 2026About CWE-319 (CWE-319)
Our database tracks 172 CVEs classified as CWE-319, with 24 rated critical and 95 rated high severity. The average CVSS score for CWE-319 vulnerabilities is 7.4.
External reference: View CWE-319 on MITRE CWE →
Monitor CWE-319 Vulnerabilities
Get alerted when new CWE-319 CVEs affect your infrastructure.
Start Monitoring Free