CWE-319 · 823 records
Cleartext Transmission of Sensitive Information
CVEs in this class
824 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
55Plan | CVE-2018-12710Proof of concept | An issue was discovered on D-Link DIR-601 2.02NA devices.dlink · dir-601 firmware · CWE-319 | High8.0 | — | 76.5% | Aug 29, 2018 |
51Plan | CVE-2024-25735Proof of concept | An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58.wyrestorm · apollo vx20 firmware · CWE-319 | Critical9.1 | — | 50.6% | Mar 26, 2024 |
46Plan | CVE-2016-5649Proof of concept | Netgear DGN2200 and DGND3700 disclose the administrator passwordnetgear · dgn2200 firmware · CWE-319 | Critical9.8 | — | 23.6% | Jul 24, 2018 |
42Plan | CVE-2018-1297Proof of concept | When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection.apache · jmeter · CWE-319 | Critical9.8 | — | 9.9% | Feb 13, 2018 |
40Plan | CVE-2021-20623No exploit | Video Insight VMS versions prior to 7.8 allows a remote attacker to execute arbitrary code with the system user privilege by sending a specipanasonic · video insight vms · CWE-319 | Critical9.8 | — | 2.8% | Feb 5, 2021 |
40Plan | CVE-2019-17393No exploit | The Customer's Tomedo Server in Version 1.7.3 communicates to the Vendor Tomedo Server via HTTP (in cleartext) that can be sniffed by unauthtomedo · server · CWE-319 | Critical9.8 | — | 1.8% | Oct 18, 2019 |
40Plan | CVE-2022-21829No exploit | Concrete CMS Versions 9.0.0 through 9.0.2 and 8.5.7 and below can download zip files over HTTP and execute code from those zip files which cconcretecms · concrete cms · CWE-319 | Critical9.8 | — | 1.8% | Jun 24, 2022 |
40Plan | CVE-2025-4378No exploit | Hardcoded Credentials in Ataturk University's ATA-AOF Mobile Applicationataturk university · ata-aof mobile application · CWE-319 | Critical10.0 | — | 0.3% | Jun 24, 2025 |
40Plan | CVE-2025-47419No exploit | Cleartext Transmission of Sensitive Information vulnerability in Crestron Automate VX allows Sniffing Network Traffic.crestron · automate vx · CWE-319 | Critical10.0 | — | 0.3% | May 6, 2025 |
40Plan | CVE-2026-22306No exploit | Critical flaw impacting OZOLS ERP's automatic update channelozols grupa · ozols · CWE-319 | Critical10.0 | — | 0.2% | Aug 19, 2026 |
39Monitor | CVE-2023-25437No exploit | An issue was discovered in vTech VCS754 version 1.1.1.A before 1.1.1.H, allows attackers to gain escalated privileges and gain sensitive infvtech · vcs754a firmware · CWE-319 | High8.8 | — | 14.1% | Apr 27, 2023 |
39Monitor | CVE-2019-18852No exploit | Certain D-Link devices have a hardcoded Alphanetworks user account with TELNET access because of /etc/config/image_sign or /etc/alpha_configdlink · dir-600 b1 firmware · CWE-319 | Critical9.8 | — | 1.6% | Nov 11, 2019 |
39Monitor | CVE-2020-5594No exploit | Mitsubishi Electric MELSEC iQ-R, iQ-F, Q, L, and FX series CPU modules all versions contain a vulnerability that allows cleartext transmissimitsubishielectric · melsec iq-r firmware · CWE-319 | Critical9.8 | — | 1.3% | Jun 23, 2020 |
39Monitor | CVE-2019-16672No exploit | An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 161weidmueller · ie-sw-pl09m-5gc-4gt firmware · CWE-319 | Critical9.8 | — | 1.3% | Dec 6, 2019 |
39Monitor | CVE-2020-9477No exploit | An issue was discovered on HUMAX HGA12R-02 BRGCAA 1.1.53 devices.humaxdigital · hga12r-02 firmware · CWE-319 | Critical9.8 | — | 1.3% | Mar 4, 2020 |
39Monitor | CVE-2023-33730Proof of concept | Privilege Escalation in the "GetUserCurrentPwd" function in Microworld Technologies eScan Management Console 14.0.1400.2281 allows any remotescanav · escan management console · CWE-319 | Critical9.8 | — | 1.2% | May 31, 2023 |
39Monitor | CVE-2020-10376No exploit | Technicolor TC7337NET 08.89.17.23.03 devices allow remote attackers to discover passwords by sniffing the network for an "Authorization: Bastechnicolor · tc7337net firmware · CWE-319 | Critical9.8 | — | 1.1% | Mar 11, 2020 |
39Monitor | CVE-2018-11422No exploit | Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior use a proprietary configuration protocol that does not provide confidentimoxa · oncell g3150-hspa firmware · CWE-319 | Critical9.8 | — | 1.0% | Jul 3, 2019 |
39Monitor | CVE-2018-7259No exploit | The FSX / P3Dv4 installer 2.0.1.231 for Flight Sim Labs A320-X sends a user's Google account credentials to http://installLog.flightsimlabs.flightsimlabs · a320-x · CWE-319 | Critical9.8 | — | 1.0% | Feb 19, 2018 |
39Monitor | CVE-2022-33321No exploit | Cleartext Transmission of Sensitive Information vulnerability due to the use of Basic Authentication for HTTP connections in Mitsubishi Elecmitsubishielectric · mac-557if-e firmware · CWE-319 | Critical9.8 | — | 1.0% | Nov 8, 2022 |
39Monitor | CVE-2020-25190No exploit | MOXA NPort IAW5000A-I/O Seriesmoxa · nport iaw5000a-i\/o firmware · CWE-319 | Critical9.8 | — | 1.0% | Dec 23, 2020 |
39Monitor | CVE-2020-12040No exploit | Sigma Spectrum Infusion System v's6.x (model 35700BAX) and Baxter Spectrum Infusion System Version(s) 8.x (model 35700BAX2) at the applicatibaxter · sigma spectrum infusion system firmware · CWE-319 | Critical9.8 | — | 0.9% | Jun 29, 2020 |
39Monitor | CVE-2018-11421No exploit | Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior use a proprietary monitoring protocol that does not provide confidentialimoxa · oncell g3150-hspa firmware · CWE-319 | Critical9.8 | — | 0.9% | Jul 3, 2019 |
39Monitor | CVE-2019-15911No exploit | An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO.asus · hg100 firmware · CWE-319 | Critical9.8 | — | 0.8% | Dec 20, 2019 |
39Monitor | CVE-2019-5505No exploit | ONTAP Select Deploy administration utility versions 2.2 through 2.12.1 transmit credentials in plaintext.netapp · ontap select deploy administration utility · CWE-319 | Critical9.8 | — | 0.8% | Sep 24, 2019 |
- CVE-2018-1271055Plan
An issue was discovered on D-Link DIR-601 2.02NA devices.
HighCVSS 8.0Proof of conceptEPSS 77%dlink · dir-601 firmwareAug 29, 2018
- CVE-2024-2573551Plan
An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58.
CriticalCVSS 9.1Proof of conceptEPSS 51%wyrestorm · apollo vx20 firmwareMar 26, 2024
- CVE-2016-564946Plan
Netgear DGN2200 and DGND3700 disclose the administrator password
CriticalCVSS 9.8Proof of conceptEPSS 24%netgear · dgn2200 firmwareJul 24, 2018
- CVE-2018-129742Plan
When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection.
CriticalCVSS 9.8Proof of conceptEPSS 10%apache · jmeterFeb 13, 2018
- CVE-2021-2062340Plan
Video Insight VMS versions prior to 7.8 allows a remote attacker to execute arbitrary code with the system user privilege by sending a speci
CriticalCVSS 9.8No exploitEPSS 3%panasonic · video insight vmsFeb 5, 2021
- CVE-2019-1739340Plan
The Customer's Tomedo Server in Version 1.7.3 communicates to the Vendor Tomedo Server via HTTP (in cleartext) that can be sniffed by unauth
CriticalCVSS 9.8No exploitEPSS 2%tomedo · serverOct 18, 2019
- CVE-2022-2182940Plan
Concrete CMS Versions 9.0.0 through 9.0.2 and 8.5.7 and below can download zip files over HTTP and execute code from those zip files which c
CriticalCVSS 9.8No exploitEPSS 2%concretecms · concrete cmsJun 24, 2022
- CVE-2025-437840Plan
Hardcoded Credentials in Ataturk University's ATA-AOF Mobile Application
CriticalCVSS 10.0No exploitEPSS 0%ataturk university · ata-aof mobile applicationJun 24, 2025
- CVE-2025-4741940Plan
Cleartext Transmission of Sensitive Information vulnerability in Crestron Automate VX allows Sniffing Network Traffic.
CriticalCVSS 10.0No exploitEPSS 0%crestron · automate vxMay 6, 2025
- CVE-2026-2230640Plan
Critical flaw impacting OZOLS ERP's automatic update channel
CriticalCVSS 10.0No exploitEPSS 0%ozols grupa · ozolsAug 19, 2026
- CVE-2023-2543739Monitor
An issue was discovered in vTech VCS754 version 1.1.1.A before 1.1.1.H, allows attackers to gain escalated privileges and gain sensitive inf
HighCVSS 8.8No exploitEPSS 14%vtech · vcs754a firmwareApr 27, 2023
- CVE-2019-1885239Monitor
Certain D-Link devices have a hardcoded Alphanetworks user account with TELNET access because of /etc/config/image_sign or /etc/alpha_config
CriticalCVSS 9.8No exploitEPSS 2%dlink · dir-600 b1 firmwareNov 11, 2019
- CVE-2020-559439Monitor
Mitsubishi Electric MELSEC iQ-R, iQ-F, Q, L, and FX series CPU modules all versions contain a vulnerability that allows cleartext transmissi
CriticalCVSS 9.8No exploitEPSS 1%mitsubishielectric · melsec iq-r firmwareJun 23, 2020
- CVE-2019-1667239Monitor
An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 161
CriticalCVSS 9.8No exploitEPSS 1%weidmueller · ie-sw-pl09m-5gc-4gt firmwareDec 6, 2019
- CVE-2020-947739Monitor
An issue was discovered on HUMAX HGA12R-02 BRGCAA 1.1.53 devices.
CriticalCVSS 9.8No exploitEPSS 1%humaxdigital · hga12r-02 firmwareMar 4, 2020
- CVE-2023-3373039Monitor
Privilege Escalation in the "GetUserCurrentPwd" function in Microworld Technologies eScan Management Console 14.0.1400.2281 allows any remot
CriticalCVSS 9.8Proof of conceptEPSS 1%escanav · escan management consoleMay 31, 2023
- CVE-2020-1037639Monitor
Technicolor TC7337NET 08.89.17.23.03 devices allow remote attackers to discover passwords by sniffing the network for an "Authorization: Bas
CriticalCVSS 9.8No exploitEPSS 1%technicolor · tc7337net firmwareMar 11, 2020
- CVE-2018-1142239Monitor
Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior use a proprietary configuration protocol that does not provide confidenti
CriticalCVSS 9.8No exploitEPSS 1%moxa · oncell g3150-hspa firmwareJul 3, 2019
- CVE-2018-725939Monitor
The FSX / P3Dv4 installer 2.0.1.231 for Flight Sim Labs A320-X sends a user's Google account credentials to http://installLog.flightsimlabs.
CriticalCVSS 9.8No exploitEPSS 1%flightsimlabs · a320-xFeb 19, 2018
- CVE-2022-3332139Monitor
Cleartext Transmission of Sensitive Information vulnerability due to the use of Basic Authentication for HTTP connections in Mitsubishi Elec
CriticalCVSS 9.8No exploitEPSS 1%mitsubishielectric · mac-557if-e firmwareNov 8, 2022
- CVE-2020-2519039Monitor
MOXA NPort IAW5000A-I/O Series
CriticalCVSS 9.8No exploitEPSS 1%moxa · nport iaw5000a-i\/o firmwareDec 23, 2020
- CVE-2020-1204039Monitor
Sigma Spectrum Infusion System v's6.x (model 35700BAX) and Baxter Spectrum Infusion System Version(s) 8.x (model 35700BAX2) at the applicati
CriticalCVSS 9.8No exploitEPSS 1%baxter · sigma spectrum infusion system firmwareJun 29, 2020
- CVE-2018-1142139Monitor
Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior use a proprietary monitoring protocol that does not provide confidentiali
CriticalCVSS 9.8No exploitEPSS 1%moxa · oncell g3150-hspa firmwareJul 3, 2019
- CVE-2019-1591139Monitor
An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO.
CriticalCVSS 9.8No exploitEPSS 1%asus · hg100 firmwareDec 20, 2019
- CVE-2019-550539Monitor
ONTAP Select Deploy administration utility versions 2.2 through 2.12.1 transmit credentials in plaintext.
CriticalCVSS 9.8No exploitEPSS 1%netapp · ontap select deploy administration utilitySep 24, 2019