CWE-319: CWE-319

172
Total CVEs
24
Critical
95
High
7.4
Avg CVSS

Yearly Trend

2026
19
2025
57
2024
33
2023
29
2022
13

Top Affected Vendors

1 Ibm 10
2 Moxa 4
3 Gotenna 4
4 Dell 4
5 Sick 4
6 Netgear 4
7 Loytec 2
8 Netapp 2
9 Sauter Controls 2
10 Microsoft 2

All CWE-319 CVEs (172)

CVE-2024-0098
5.5

NVIDIA ChatRTX for Windows transmits sensitive information in clear text, allowing attackers on the same network to sniff data. This affects all ChatR...

May 14, 2024
CVE-2024-28169
5.4

BigDL software versions before 2.5.0 transmit sensitive information in cleartext, allowing authenticated attackers on adjacent networks to potentially...

Nov 13, 2024
CVE-2025-66604
5.3

This vulnerability in Yokogawa's FAST/TOOLS industrial control system software exposes library version information on web pages, potentially enabling ...

Feb 9, 2026
CVE-2025-36034
5.3

IBM InfoSphere DataStage Flow Designer in IBM InfoSphere Information Server 11.7 transmits sensitive user information in unencrypted API requests, all...

Jun 26, 2025
CVE-2024-53246
5.3

This CVE describes an information disclosure vulnerability in Splunk Enterprise and Splunk Cloud Platform where SPL commands can potentially expose se...

Dec 10, 2024
CVE-2024-43432
5.3

This vulnerability in Moodle's cURL wrapper could leak HTTP authorization credentials during redirects. When Moodle follows redirects, it strips HTTPA...

Nov 11, 2024
CVE-2024-9620
5.3

This vulnerability in Ansible Automation Platform's Event-Driven Automation component exposes sensitive information transmitted between EDA and AAP wi...

Oct 8, 2024
CVE-2025-59448
4.7

YoSmart YoLink ecosystem uses unencrypted MQTT for internet communication, allowing attackers monitoring network traffic to intercept sensitive data o...

Oct 6, 2025
CVE-2025-57727
4.7

This vulnerability in JetBrains IntelliJ IDEA allows attackers to potentially access sensitive credentials through remote references. It affects users...

Aug 20, 2025
CVE-2025-43704
4.7

Arctera/Veritas Data Insight versions before 7.1.2 transmit credentials in cleartext when configured to use HTTP Basic Authentication with Dell Isilon...

Apr 16, 2025
CVE-2025-40583
4.4

SCALANCE LPE9403 devices with SINEMA Remote Connect Edge Client transmit sensitive information in cleartext, allowing privileged local attackers to in...

May 13, 2025
CVE-2025-32884
4.3

goTenna Mesh devices with vulnerable app/firmware versions transmit user phone numbers unencrypted in messages by default. This allows attackers inter...

May 1, 2025
CVE-2025-32881
4.3

This vulnerability exposes users' phone numbers in goTenna v1 devices by transmitting them unencrypted as Group IDs (GIDs) in messages. Anyone using g...

May 1, 2025
CVE-2024-40090
4.3

The Vilo 5 Mesh WiFi System running firmware version 5.16.1.33 or earlier contains an information disclosure vulnerability in its Boa webserver. Remot...

Oct 21, 2024
CVE-2024-45838
4.3

The goTenna Pro ATAK Plugin fails to encrypt callsigns in messages, potentially exposing sensitive information to unauthorized observers. This affects...

Sep 26, 2024
CVE-2024-8059
4.3

This vulnerability exposes IPMI credentials in XCC audit logs when usernames are exactly 16 characters long. It affects Lenovo servers with XCC firmwa...

Sep 13, 2024
CVE-2025-63292
3.5

This vulnerability exposes subscribers' IMSI identifiers in plaintext during EAP-SIM authentication on Freebox devices' FreeWifi_secure network. An at...

Nov 17, 2025
CVE-2026-24441
N/A

Tenda AC7 routers with firmware V03.03.03.01_cn and earlier transmit administrator credentials in plaintext within HTTP responses. This allows attacke...

Feb 3, 2026
CVE-2026-22080
N/A

This vulnerability allows attackers on the same network to intercept and decode administrative credentials from Tenda wireless routers. Attackers can ...

Jan 9, 2026
CVE-2026-22079
N/A

This vulnerability allows attackers on the same network to intercept login credentials transmitted in plaintext during initial setup of Tenda wireless...

Jan 9, 2026
CVE-2026-22544
N/A

This vulnerability allows attackers with network access to intercept credentials transmitted in clear text, affecting systems that transmit authentica...

Jan 7, 2026
CVE-2025-61738
N/A

This vulnerability allows attackers to capture the PowerG network key and read or write encrypted packets on PowerG wireless networks. It affects John...

Dec 22, 2025

About CWE-319 (CWE-319)

Our database tracks 172 CVEs classified as CWE-319, with 24 rated critical and 95 rated high severity. The average CVSS score for CWE-319 vulnerabilities is 7.4.

External reference: View CWE-319 on MITRE CWE →

Monitor CWE-319 Vulnerabilities

Get alerted when new CWE-319 CVEs affect your infrastructure.

Start Monitoring Free