CWE-319

High likelihood

Cleartext Transmission of Sensitive Information

Parent: CWE-311 - Missing Encryption of Sensitive Data

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

898 vulnerabilities with CWE-319
CVE-2026-64742 MEDIUM
Apple Ios And iPadOS - Denial of Service
CVSS 6.5
CVE-2026-3182 MEDIUM
Zohocorp ManageEngine Endpoint Central - Sensitive Data Exposure
CVSS 4.3
CVE-2026-47255 HIGH
AgenticMail API/storage and outbound relay hardening
CVSS 8.2
CVE-2026-48022 MEDIUM
@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects
CVSS 6.5
CVE-2026-48978 LOW
oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens
CVE-2026-34346 MEDIUM
Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability
CVSS 5.5
CVE-2026-53624 MEDIUM
Fiber: HSTS header never set in helmet middleware due to incorrect protocol check
CVSS 4.8
CVE-2026-55844 HIGH
Home Assistant: iOS Companion App ignores internal SSID allowlist for connections – possible leak of access token and sensor data
CVSS 7.5
CVE-2026-49486 HIGH
Apache Airflow FTP provider: FTP Provider does not protect FTPS data channel (missing PROT_P)
CVSS 7.5
CVE-2026-44726 HIGH
Deno: TLS retry copies stale upgrade hook, risking plaintext traffic
CVSS 7.4
CVE-2026-55568 MEDIUM
Guzzle: Silent HTTPS-Proxy Downgrade to Cleartext
CVSS 5.9
CVE-2026-11833 HIGH
Yokogawa Electric Corporation Fast/tools - Cleartext Transmission of Sensitive Information
CVE-2026-50034 MEDIUM
Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT Cleartext Transmission of Sensitive Information
CVSS 6.5
CVE-2026-50200 HIGH
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
CVSS 7.5
CVE-2026-9741 MEDIUM
Client side encryption fails to encrypt values in a $vectorSearch
CVSS 6.5
CVE-2026-45432 HIGH
GX Earth ONT Models - Cleartext Credential Transmission
CVE-2026-8874 HIGH
Securly Chrome Extension < 3.0.7 - Unencrypted HTTP Download of Crisis Alert Keywords
CVSS 7.1
CVE-2026-36610 MEDIUM
Mercusys AC12G (EU) V1 Firmware AC12G(EU)_V1_200909 - Unauthenticated DDNS Credential Exposure via Plaintext HTTP
CVSS 5.9
CVE-2026-7666 LOW
Potential unencrypted email transmission via STARTTLS in the SMTP backend
CVSS 3.1
CVE-2026-10584 MEDIUM
HTTPS Fallback to HTTP in Graph Explorer
CVSS 5.9
CVE-2026-43625 MEDIUM
CodexBar < 0.32.0 - Cleartext Transmission of Sensitive Information via HTTP Redirect
CVSS 5.9
CVE-2026-25599 MEDIUM
Missing authentication and clear‑text data transmission affecting Orca heat pumps
CVSS 6.3
CVE-2026-34126 HIGH
Bluetooth Communication Uses Unencrypted Transmission During Initial Setup on TP-Link's Tapo L535E, P300 and D100C
CVSS 7.5
CVE-2026-48902 CRITICAL
Joomla! Core - [20260518] - Transport encryption downgrade for password and username reset links
CVSS 9.8
CVE-2026-24212 HIGH
Nvidia Isaac Launchable - Cleartext Transmission of Sensitive Information
CVSS 7.5
Details
Vulnerabilities 898
Exploit Likelihood High