VYPR

CWE-319

Cleartext Transmission of Sensitive Information

BaseDraftLikelihood: High

Description

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-117 · CAPEC-383 · CAPEC-477 · CAPEC-65

CVEs mapped to this weakness (914)

page 44 of 46
  • CVE-2020-2142MedMar 9, 2020
    risk 0.21cvss 4.3epss 0.01

    A missing permission check in Jenkins P4 Plugin 1.10.10 and earlier allows attackers with Overall/Read permission to trigger builds.

  • CVE-2026-7666LowJun 3, 2026
    risk 0.20cvss 3.1epss 0.00

    An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.core.mail.backends.smtp.EmailBackend` in Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake when `fail_silently=True`, which allows on-path…

  • CVE-2026-4584LowMar 23, 2026
    risk 0.20cvss 3.1epss 0.00

    A flaw has been found in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. This affects an unknown part of the component Cardholder Data Handler. Executing a manipulation can lead to cleartext transmission of sensitive information. The attack requires access to the local network.…

  • CVE-2026-2671LowMar 7, 2026
    risk 0.20cvss 3.1epss 0.00

    A vulnerability was detected in Mendi Neurofeedback Headset V4. Affected by this vulnerability is an unknown functionality of the component Bluetooth Low Energy Handler. Performing a manipulation results in cleartext transmission of sensitive information. The attack can only be…

  • CVE-2025-11640LowOct 12, 2025
    risk 0.20cvss 3.1epss 0.00

    A vulnerability was found in Tomofun Furbo 360 and Furbo Mini. This affects an unknown function of the component Bluetooth Low Energy. The manipulation results in cleartext transmission of sensitive information. Access to the local network is required for this attack. Attacks of…

  • CVE-2025-53861LowJul 11, 2025
    risk 0.20cvss 3.1epss 0.00

    A flaw was found in Ansible. Sensitive cookies without security flags over non-encrypted channels can lead to Man-in-the-Middle (MitM) and Cross-site scripting (XSS) attacks allowing attackers to read transmitted data.

  • CVE-2025-3329LowApr 7, 2025
    risk 0.20cvss 3.1epss 0.00

    A vulnerability classified as problematic has been found in Consumer Comanda Mobile up to 14.9.3.2/15.0.0.8. This affects an unknown part of the component Restaurant Order Handler. The manipulation of the argument Login/Password leads to cleartext transmission of sensitive…

  • CVE-2023-5035LowNov 2, 2023
    risk 0.20cvss 3.1epss 0.00

    A vulnerability has been identified in PT-G503 Series firmware versions prior to v5.2, where the Secure attribute for sensitive cookies in HTTPS sessions is not set, which could cause the cookie to be transmitted in plaintext over an HTTP session. The vulnerability may lead to…

  • CVE-2019-10397LowSep 12, 2019
    risk 0.20cvss 3.1epss 0.01

    Jenkins Aqua Security Serverless Scanner Plugin 1.0.4 and earlier transmitted configured passwords in plain text as part of job configuration forms, potentially resulting in their exposure.

  • CVE-2025-32793MedApr 21, 2025
    risk 0.19cvss 4.0epss 0.00

    Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.15.0 to 1.15.15, 1.16.0 to 1.16.8, and 1.17.0 to 1.17.2, are vulnerable when using Wireguard transparent encryption in a Cilium cluster, packets that originate from a…

  • CVE-2024-47577LowDec 10, 2024
    risk 0.18cvss 2.7epss 0.00

    Webservice API endpoints for Assisted Service Module within SAP Commerce Cloud has information disclosure vulnerability. When an authorized agent searches for customer to manage their accounts, the request url includes customer data and it is recorded in server logs. If an…

  • CVE-2021-37939LowNov 18, 2021
    risk 0.18cvss 2.7epss 0.00

    It was discovered that Kibana’s JIRA connector & IBM Resilient connector could be used to return HTTP response data on internal hosts, which may be intentionally hidden from public view. Using this vulnerability, a malicious user with the ability to create connectors, could…

  • CVE-2025-0252LowJul 25, 2025
    risk 0.17cvss 2.6epss 0.00

    HCL IEM is affected by a password in cleartext vulnerability.  Sensitive information is transmitted without adequate protection, potentially exposing it to unauthorized access during transit.

  • CVE-2021-36382LowJul 12, 2021
    risk 0.17cvss 2.6epss 0.01

    Devolutions Server before 2021.1.18, and LTS before 2020.3.20, allows attackers to intercept private keys via a man-in-the-middle attack against the connections/partial endpoint (which accepts cleartext).

  • CVE-2022-0005LowMay 12, 2022
    risk 0.16cvss 2.4epss 0.00

    Sensitive information accessible by physical probing of JTAG interface for some Intel(R) Processors with SGX may allow an unprivileged user to potentially enable information disclosure via physical access.

  • CVE-2026-25608LowMay 22, 2026
    risk 0.15cvss epss 0.00

    STER uses unencrypted TCP traffic to transmit data over the network. It allows an attacker to conduct a Man-In-The-Middle attack and obtain sensitive data such as passwords, personal data, or authentication tokens. This issue was fixed in version 9.5.

  • CVE-2025-61738LowDec 22, 2025
    risk 0.15cvss epss 0.00

    Under certain circumstances, attacker can capture the network key, read or write encrypted packets on the PowerG network.

  • CVE-2025-0250LowJul 25, 2025
    risk 0.14cvss 2.2epss 0.00

    HCL IEM is affected by an authorization token sent in cookie vulnerability.  A token used for authentication and authorization is being handled in a manner that may increase its exposure to security risks.

  • CVE-2024-8013LowOct 28, 2024
    risk 0.14cvss 2.2epss 0.00

    A bug in query analysis of certain complex self-referential $lookup subpipelines may result in literal values in expressions for encrypted fields to be sent to the server as plaintext instead of ciphertext. Should this occur, no documents would be returned or written. This issue…

  • CVE-2023-45716LowFeb 9, 2024
    risk 0.11cvss 1.7epss 0.00

    Sametime is impacted by sensitive information passed in URL.