VYPR

CWE-319

Cleartext Transmission of Sensitive Information

BaseDraftLikelihood: High

Description

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-117 · CAPEC-383 · CAPEC-477 · CAPEC-65

CVEs mapped to this weakness (950)

page 21 of 48
  • CVE-2023-1831HigApr 17, 2023
    risk 0.47cvss 7.2epss 0.00

    Mattermost fails to redact from audit logs the user password during user creation and the user password hash in other operations if the experimental audit logging configuration was enabled (ExperimentalAuditSettings section in config).

  • CVE-2021-41835HigJan 21, 2022
    risk 0.47cvss 7.3epss 0.00

    Fresenius Kabi Agilia Link + version 3.0 does not enforce transport layer encryption. Therefore, transmitted data may be sent in cleartext. Transport layer encryption is offered on Port TCP/443, but the affected service does not perform an automated redirect from the unencrypted…

  • CVE-2017-0925HigMar 21, 2018
    risk 0.47cvss 7.2epss 0.01

    Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration API endpoint resulting in an information disclosure of plaintext password.

  • CVE-2026-85628HigSep 16, 2026
    risk 0.46cvss —epss 0.00

    Transmission of the home Wi-Fi credentials without encryption during the pairing process between the DuoxMe application and VEO and VEO-XS Wi-Fi monitors, in versions prior to 4.3.4 of the application and 01.50.001 of the monitor firmware, allows an attacker on the Wi-Fi Direct…

  • CVE-2026-84381HigSep 2, 2026
    risk 0.46cvss 8.1epss 0.00

    HTTPX2 is a next generation HTTP client for Python. Prior to 2.10.0, httpcore2 fails to start TLS in src/httpcore2/httpcore2/_sync/socks_proxy.py and src/httpcore2/httpcore2/_async/socks_proxy.py when the remote origin uses wss through a SOCKS5 proxy because the TLS upgrade…

  • CVE-2026-47255HigJul 20, 2026
    risk 0.46cvss 8.2epss 0.00

    AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0.9.10 had weakness related to validation and and binding of inactive-agent hour filtering; storage SQL identifier validation;…

  • CVE-2026-8874HigJun 3, 2026
    risk 0.46cvss 7.1epss 0.00

    Version 3.0.7 of the Securly Chrome Extension downloads JSON files containing crisis alert keywords and filtering rules over unencrypted HTTP via the Fetch API. Other endpoints in the same extension correctly fetch IWF and CIPA data over HTTPS, demonstrating an inconsistent…

  • CVE-2026-6066HigApr 20, 2026
    risk 0.46cvss 7.1epss 0.00

    ConnectWise has released a security update for ConnectWise Automate™ that addresses a behavior in the ConnectWise Automate Solution Center where certain client-to-server communications could occur without transport-layer encryption. This could allow network‑based…

  • CVE-2026-32034HigMar 19, 2026
    risk 0.46cvss 8.1epss 0.00

    OpenClaw versions prior to 2026.2.21 contain an authentication bypass vulnerability in the Control UI when allowInsecureAuth is explicitly enabled and the gateway is exposed over plaintext HTTP, allowing attackers to bypass device identity and pairing verification. An attacker…

  • CVE-2025-64769HigJan 16, 2026
    risk 0.46cvss 7.1epss 0.00

    The Process Optimization application suite leverages connection channels/protocols that by-default are not encrypted and could become subject to hijacking or data leakage in certain man-in-the-middle or passive inspection scenarios.

  • CVE-2025-10641HigOct 21, 2025
    risk 0.46cvss 7.1epss 0.00

    All WorkExaminer Professional traffic between monitoring client, console and server is transmitted as plain text. This allows an attacker with access to the network to read the transmitted sensitive data. An attacker can also freely modify the data on the wire. The monitoring…

  • CVE-2025-8863HigAug 11, 2025
    risk 0.46cvss —epss 0.00

    YugabyteDB diagnostic information was transmitted over HTTP, which could expose sensitive data during transmission

  • CVE-2025-32887HigMay 1, 2025
    risk 0.46cvss 7.1epss 0.00

    An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. A command channel includes the next hop. which can be intercepted and used to break frequency hopping.

  • CVE-2025-24849HigFeb 28, 2025
    risk 0.46cvss 7.1epss 0.00

    Lack of encryption in transit for cloud infrastructure facilitating potential for sensitive data manipulation or exposure.

  • CVE-2024-28134HigMay 14, 2024
    risk 0.46cvss 7.0epss 0.00

    An unauthenticated remote attacker can extract a session token with a MitM attack and gain web-based management access with the privileges of the currently logged in user due to cleartext transmission of sensitive…

  • CVE-2022-32510HigMay 14, 2024
    risk 0.46cvss 7.1epss 0.00

    An issue was discovered on certain Nuki Home Solutions devices. The HTTP API exposed by a Bridge used an unencrypted channel to provide an administrative interface. A token can be easily eavesdropped by a malicious actor to impersonate a legitimate user and gain access to the…

  • CVE-2024-31206HigApr 4, 2024
    risk 0.46cvss 8.2epss 0.00

    dectalk-tts is a Node package to interact with the aeiou Dectalk web API. In `[email protected]`, network requests to the third-party API are sent over HTTP, which is unencrypted. Unencrypted traffic can be easily intercepted and modified by attackers. Anyone who uses the…

  • CVE-2023-0864HigMay 17, 2023
    risk 0.46cvss 7.1epss 0.00

    Cleartext Transmission of Sensitive Information vulnerability in ABB Terra AC wallbox (UL40/80A), ABB Terra AC wallbox (UL32A), ABB Terra AC wallbox (CE) (Terra AC MID), ABB Terra AC wallbox (CE) Terra AC Juno CE, ABB Terra AC wallbox (CE) Terra AC PTB, ABB Terra AC wallbox (CE)…

  • CVE-2022-39287HigOct 7, 2022
    risk 0.46cvss 8.1epss 0.00

    tiny-csrf is a Node.js cross site request forgery (CSRF) protection middleware. In versions prior to 1.1.0 cookies were not encrypted and thus CSRF tokens were transmitted in the clear. This issue has been addressed in commit `8eead6d` and the patch with be included in version…

  • CVE-2022-0988HigMar 25, 2022
    risk 0.46cvss 7.1epss 0.01

    Delta Electronics DIAEnergie (Version 1.7.5 and prior) is vulnerable to cleartext transmission as the web application runs by default on HTTP. This could allow an attacker to remotely read transmitted information between the client and product.