VYPR

CWE-319

Cleartext Transmission of Sensitive Information

BaseDraftLikelihood: High

Description

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-117 · CAPEC-383 · CAPEC-477 · CAPEC-65

CVEs mapped to this weakness (950)

page 43 of 48
  • CVE-2019-10735MedApr 7, 2019
    risk 0.28cvss 4.3epss 0.01

    In Claws Mail 3.14.1, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by…

  • CVE-2019-10734MedApr 7, 2019
    risk 0.28cvss 4.3epss 0.01

    In KDE Trojita 0.7, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by…

  • CVE-2019-10732MedApr 7, 2019
    risk 0.28cvss 4.3epss 0.01

    In KDE KMail 5.2.3, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by…

  • CVE-2018-14627MedSep 4, 2018
    risk 0.28cvss 5.3epss 0.01

    The IIOP OpenJDK Subsystem in WildFly before version 14.0.0 does not honour configuration when SSL transport is required. Servers before this version that are configured with the following setting allow clients to create plaintext connections: <transport-config…

  • CVE-2018-11399MedMay 24, 2018
    risk 0.28cvss 4.3epss 0.00

    SimpliSafe Original has Unencrypted Sensor Transmissions, which allows physically proximate attackers to obtain potentially sensitive information about the specific times when alarm-system events occur.

  • CVE-2026-79779MedAug 25, 2026
    risk 0.27cvss 5.3epss 0.00

    rclone versions before v1.75.0 fail to reject transport downgrades in redirect handling, allowing Basic authorization and Cookie headers to be replayed over plaintext HTTP after same-host HTTPS-to-HTTP redirects. An on-path attacker observing the plaintext hop can capture and…

  • CVE-2026-45179MedMay 10, 2026
    risk 0.27cvss 5.3epss 0.00

    Plack::Middleware::Statsd versions before 0.9.0 for Perl may leak user IP addresses. If the communication channel to the statsd daemon is not secured (for example, by sending UDP packets to a host on another network), then users' IP addresses may be leaked. Since version…

  • CVE-2026-31924MedApr 14, 2026
    risk 0.27cvss 5.3epss 0.00

    Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. tencent-cloud-cls log export uses plaintext HTTP This issue affects Apache APISIX: from 2.99.0 through 3.15.0. Users are recommended to upgrade to version 3.16.0, which fixes the issue.

  • CVE-2024-49819MedDec 17, 2024
    risk 0.27cvss 4.1epss 0.00

    IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information in cleartext in a communication channel that can be sniffed by unauthorized actors.

  • CVE-2023-33837MedOct 23, 2023
    risk 0.27cvss 4.1epss 0.00

    IBM Security Verify Governance 10.0 does not encrypt sensitive or critical information before storage or transmission. IBM X-Force ID: 256020.

  • CVE-2023-0055MedJan 4, 2023
    risk 0.27cvss 5.3epss 0.00

    Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository pyload/pyload prior to 0.5.0b3.dev32.

  • CVE-2022-43691MedNov 14, 2022
    risk 0.27cvss 5.3epss 0.00

    Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 inadvertently disclose server-side sensitive information (secrets in environment variables and server information) when Debug Mode is left on in production.

  • CVE-2020-2143MedMar 9, 2020
    risk 0.27cvss 5.3epss 0.01

    Jenkins Logstash Plugin 2.3.1 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.

  • CVE-2019-8345MedFeb 15, 2019
    risk 0.27cvss 4.2epss 0.00

    The Help feature in the ES File Explorer File Manager application 4.1.9.7.4 for Android allows session hijacking by a Man-in-the-middle attacker on the local network because HTTPS is not used, and an attacker's web site is displayed in a WebView with no information about the URL.

  • CVE-2017-9637MedMay 18, 2018
    risk 0.27cvss 4.1epss 0.00

    Schneider Electric Ampla MES 6.4 provides capability to interact with data from third party databases. When connectivity to those databases is configured to use a SQL user name and password, an attacker may be able to sniff details from the connection string. Schneider Electric…

  • CVE-2022-29945MedApr 29, 2022
    risk 0.26cvss 4.0epss 0.01

    DJI drone devices sold in 2017 through 2022 broadcast unencrypted information about the drone operator's physical location via the AeroScope protocol.

  • CVE-2019-10363MedJul 31, 2019
    risk 0.25cvss 4.9epss 0.01

    Jenkins Configuration as Code Plugin 1.24 and earlier did not reliably identify sensitive values expected to be exported in their encrypted form.

  • CVE-2026-73743LowSep 1, 2026
    risk 0.24cvss 3.7epss 0.00

    A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to gain insight into some data handled by the affected interface. A successful exploit could allow an attacker to gain access to some data in a…

  • CVE-2026-81836LowAug 28, 2026
    risk 0.24cvss 3.7epss 0.00

    A vulnerability was detected in RooCodeInc Roo-Code up to 3.51.1. This vulnerability affects unknown code of the file src/integrations/claude-code/oauth.ts of the component OAuth Callback. The manipulation results in cleartext transmission of sensitive information. The attack…

  • CVE-2025-59852LowMay 6, 2026
    risk 0.24cvss 3.7epss 0.00

    HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability where data is transmitted over the network without encryption, which could allow an attacker to compromise the confidentiality, integrity, and authentication of sensitive information.