Threats Tagged 'cwe-319'
View all threats tagged with 'cwe-319'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-319'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-18536: CWE-319 Cleartext Transmission of Sensitive Information in RRWO Data::EntropyCVE-2026-18536 0 Data::Entropy versions before 0.010 for Perl transmit remote entropy source data over unencrypted HTTP. This allows on-path attackers to intercept and modify the entropy data returned by the RandomOrg and RandomnumbersInfo sources. The integrity check for RandomOrg is weak, accepting any non-empty byte string, enabling attackers to control the random bytes used by applications relying on these sources. This can influence the randomness used by applications, potentially weakening security. Join the discussion | CVE Database V5 | 08/01/2026, 10:35:38 UTC Added: 08/01/2026, 11:03:52 UTC |
CVE-2026-3182: CWE-319 Cleartext transmission of sensitive information in Zohocorp ManageEngine Endpoint CentralCVE-2026-3182 0 Zohocorp ManageEngine Endpoint Central versions before 11.4.2528.34 are affected by cleartext transmission of sensitive information vulnerability. Join the discussion | CVE Database V5 | 07/21/2026, 05:30:33 UTC Added: 07/21/2026, 05:42:32 UTC |
CVE-2026-47255: CWE-20: Improper Input Validation in agenticmail @agenticmail/apiCVE-2026-47255 0 CVE-2026-47255 is a high-severity vulnerability affecting the @agenticmail/api and @agenticmail/core packages prior to versions 0.9.32 and 0.9.10 respectively. The issue involves improper input validation and weaknesses in several security controls including inactive-agent hour filtering, SQL identifier validation, metadata ownership checks, blocking unauthorized SQL metadata access, secure handling of outbound worker secrets, SMTP envelope/header validation, and TLS certificate verification. These flaws could lead to integrity violations and partial denial of service. The vulnerability has been patched in the stated versions. Join the discussion | CVE Database V5 | 07/20/2026, 21:56:40 UTC Added: 07/20/2026, 22:12:19 UTC |
CVE-2026-48978: CWE-918: Server-Side Request Forgery (SSRF) in oras-project oras-goCVE-2026-48978 0 oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, auth.Client follows the realm URL from a registry's WWW-Authenticate: Bearer challenge without validating the scheme or host, allowing a malicious or compromised registry to cause SSRF to internal networks such as http://169.254.169.254/, http://10.0.0.x/, and http://127.0.0.1/, or to downgrade a registry contacted over https:// to an http:// token endpoint in registry/remote/auth/client.go through Client.Do(), Client.fetchBearerToken(), fetchDistributionToken, and fetchOAuth2Token. This issue is fixed in version 2.6.1. Join the discussion | CVE Database V5 | 07/17/2026, 19:34:53 UTC Added: 07/18/2026, 11:08:30 UTC |
CVE-2026-48022: CWE-319: Cleartext Transmission of Sensitive Information in hapijs wreckCVE-2026-48022 0 @hapi/wreck is an HTTP client utility. Prior to 18.1.2, Wreck strips credential headers including Authorization, Cookie, and Proxy-Authorization before following a cross-origin redirect, but the origin check compares hostnames only and ignores scheme and port, so credentials are forwarded intact across same-host port changes and HTTPS-to-HTTP downgrades, allowing a co-tenant on an adjacent port or a network-position attacker capable of forging a redirect to capture bearer tokens, session cookies, and proxy credentials and impersonate the victim against the upstream service. This issue is fixed in version 18.1.2. Join the discussion | CVE Database V5 | 07/17/2026, 21:02:05 UTC Added: 07/18/2026, 08:58:02 UTC |
CVE-2026-34346: CWE-319: Cleartext Transmission of Sensitive Information in Microsoft Windows 10 Version 1607CVE-2026-34346 0 Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally. Join the discussion | CVE Database V5 | 07/14/2026, 17:04:19 UTC Added: 07/14/2026, 17:18:29 UTC |
Showing 1 to 6 of 6 results