CWE-319

High likelihood

Cleartext Transmission of Sensitive Information

Parent: CWE-311 - Missing Encryption of Sensitive Data

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

898 vulnerabilities with CWE-319
CVE-2026-25608 LOW
Lack of traffic encryption in STER
CVE-2026-38740 MEDIUM
Foscam VD1 <V5.3.13_1072 - Info Disclosure
CVSS 5.3
CVE-2026-41281 MEDIUM
Kddi Corporation あんしんフィルター For AU - Cleartext Transmission of Sensitive Information
CVSS 4.8
CVE-2026-6276 HIGH
curl 8.7.0-8.19.0 - Sensitive Cookie Leak via Stale Host Header
CVSS 7.5
CVE-2026-4873 MEDIUM
curl 8.7.0-8.19.0 - TLS Bypass via Connection Pool Reuse
CVSS 5.9
CVE-2026-45180 HIGH
Catalyst::Plugin::Statsd versions through 0.10.0 for Perl may leak session ids
CVSS 7.5
CVE-2026-45179 MEDIUM
Plack::Middleware::Statsd versions before 0.9.0 for Perl may leak user IP addresses
CVSS 5.3
CVE-2026-32683 MEDIUM
EZVIZ APP - Information Disclosure
CVSS 5.3
CVE-2026-7610 LOW
TRENDnet TEW-821DAP Firmware Update ssi cleartext transmission
CVSS 3.7
CVE-2026-42514 HIGH
Sensitive Data Exposure Vulnerability in e-Sushrut HMIS
CVE-2026-40431 MEDIUM
SenseLive X3050 Cleartext transmission of sensitive information
CVSS 5.3
CVE-2026-41275 HIGH
Flowise: Password Reset Link Sent Over Unsecured HTTP
CVSS 7.5
CVE-2026-40045 MEDIUM
OpenClaw < 2026.4.2 - Cleartext Credential Transmission via Unencrypted WebSocket Gateway Endpoints
CVSS 5.7
CVE-2026-6066 HIGH
Unencrypted Client‑Server Communication in ConnectWise Automate™ Solution Center
CVSS 7.1
CVE-2026-33569 MEDIUM
Anviz Products Cleartext Transmission of Sensitive Information
CVSS 6.5
CVE-2026-33472 MEDIUM
Cryptomator 1.19.1 - OAuth Token Exchange HTTP Downgrade
CVSS 4.8
CVE-2026-22155 MEDIUM
FortiSOAR 7.3-7.6 - Cleartext Transmission of Sensitive Information
CVSS 6.5
CVE-2026-21742 MEDIUM
Fortinet FortiSOAR PaaS <7.6.2 - Info Disclosure
CVSS 5.7
CVE-2026-31924 MEDIUM
Apache APISIX: Plugin tencent-cloud-cls log export uses plaintext HTTP
CVSS 5.3
CVE-2026-31923 HIGH
Apache APISIX: Openid-connect `tls_verify` field is disabled by default
CVSS 7.5
CVE-2026-4820 MEDIUM
IBM Maximo Application Suite was vulnerable to because Cookie ltpatoken2_<workspace_name> was not set with secure flag
CVSS 4.3
CVE-2026-5115 HIGH
Session hijacking in PaperCut NG/MF embedded application for Konica Minolta devices
CVSS 7.5
CVE-2026-5119 MEDIUM
Libsoup: libsoup: information disclosure via cleartext transmission of cookies during https tunnel establishment
CVSS 5.9
CVE-2026-1014 MEDIUM
IBM InfoSphere Information Server is vulnerable due to disclosure of sensitive information
CVSS 6.5
CVE-2026-20115 MEDIUM
Cisco IOS XE Software <17.14.1 - Info Disclosure
CVSS 6.1
Details
Vulnerabilities 898
Exploit Likelihood High