CWE-319

High likelihood

Cleartext Transmission of Sensitive Information

Parent: CWE-311 - Missing Encryption of Sensitive Data

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

898 vulnerabilities with CWE-319
CVE-2022-23509 HIGH
Weave GitOps < 0.12.0 - Cleartext Transmission of Sensitive Information via Local S3 Bucket
CVSS 7.3
CVE-2022-3929 HIGH
HitachiEnergy FOXMAN-UN and UNEM - Cleartext Transmission of Sensitive Information via CORBA
CVSS 8.3
CVE-2022-43551 HIGH
curl < 7.87.0 - Cleartext Transmission of Sensitive Information via HSTS Bypass
CVSS 7.5
CVE-2022-22457 MEDIUM
IBM Security Verify Governance 10.0.1 - Cleartext Transmission of Sensitive Information
CVSS 5.3
CVE-2022-22758 HIGH
Firefox < 97.0 - Cleartext Transmission of Sensitive Information via USSD Code Injection in tel: Links
CVSS 8.8
CVE-2022-47895 MEDIUM
JetBrains IntelliJ IDEA < 2022.3.1 - Cleartext Transmission of Sensitive Information via JSP File Validation
CVSS 4.7
CVE-2022-42454 MEDIUM
HCL BigFix Insights for Vulnerability Remediation < 2.0 - Cleartext Transmission of Sensitive Information
CVSS 6.4
CVE-2022-43724 CRITICAL
SICAM PAS/PQS < V7.0 - SQL Injection
CVSS 9.8
CVE-2022-46685 MEDIUM
Jenkins Gitea Plugin <1.4.4 - Info Disclosure
CVSS 4.3
CVE-2022-40939 MEDIUM
Secustation <various> - Info Disclosure
CVSS 4.9
CVE-2022-45877 HIGH
OpenHarmony 3.1-3.1.4 - Cleartext Transmission of Sensitive Information via Cross-Device Authentication
CVSS 8.3
CVE-2022-45478 MEDIUM
Telepad < 1.0.7 - Unauthenticated Cleartext Transmission of Sensitive Information
CVSS 5.9
CVE-2022-45483 MEDIUM
lazy_mouse < 2.0.1 - Unauthenticated Cleartext Transmission of Sensitive Information
CVSS 5.9
CVE-2022-45480 MEDIUM
PC Keyboard WiFi & Bluetooth < 30 - Cleartext Transmission of Sensitive Information
CVSS 5.9
CVE-2022-39339 MEDIUM
nextcloud/openid_connect_user_backend < 1.2.1 - Cleartext Transmission of Sensitive Information
CVSS 4.3
CVE-2022-44411 HIGH
Web Based Quiz System v1.0 - Info Disclosure
CVSS 7.5
CVE-2022-43691 MEDIUM
Concrete CMS <8.5.10, 9.0.0-9.1.2 - Info Disclosure
CVSS 5.3
CVE-2022-38122 HIGH
UPSMON PRO - Unauthenticated Cleartext Transmission of Sensitive Information via HTTP
CVSS 7.5
CVE-2022-33321 CRITICAL
Mitsubishi Electric - Info Disclosure
CVSS 9.8
CVE-2022-42916 HIGH
curl 7.77.0-7.85.0 - Cleartext Transmission of Sensitive Information via IDN Character Bypass
CVSS 7.5
CVE-2022-41636 CRITICAL
Haas Controller <100.20.000.1110 - Info Disclosure
CVSS 9.1
CVE-2022-41627 MEDIUM
AliveCor's KardiaMobile - Info Disclosure
CVSS 4.8
CVE-2022-41983 LOW
F5 Big-ip Access Policy Manager < 13.1.5 - Cleartext Transmission
CVSS 3.7
CVE-2022-3206 MEDIUM
Passster WP <3.5.5.5.2 - Info Disclosure
CVSS 5.9
CVE-2022-39287 HIGH
tiny-csrf < 1.1.0 - Cleartext Transmission of Sensitive Information
CVSS 8.1
Details
Vulnerabilities 898
Exploit Likelihood High