Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-319'

View all threats tagged with 'cwe-319'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-319

Threats Tagged 'cwe-319'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-18536: CWE-319 Cleartext Transmission of Sensitive Information in RRWO Data::EntropyCVE-2026-18536
0

Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP. The Data::Entropy::RawSource::RandomOrg and Data::Entropy::RawSource::RandomnumbersInfo remote sources are accessed over plain HTTP. The Data::Entropy::RawSource::RandomOrg integrity check trivially matches any non-empty byte string. Any on-path attacker, such as open WiFi, a compromised ISP, captive portal, or a hostile egress proxy substitutes the response and thereby chooses the bytes returned by rand_bits and rand_int for every application that selected one of these sources via with_entropy_source. The _checkbuf method response is equally attacker-controlled, so the retry/sleep behaviour is steerable too.

Join the discussion
CVE-2026-3182: CWE-319 Cleartext transmission of sensitive information in Zohocorp ManageEngine Endpoint CentralCVE-2026-3182
0

Zohocorp ManageEngine Endpoint Central versions before 11.4.2528.34 are affected by cleartext transmission of sensitive information vulnerability.

Join the discussion
CVE-2026-47255: CWE-20: Improper Input Validation in agenticmail @agenticmail/apiCVE-2026-47255
0

CVE-2026-47255 is a high-severity vulnerability affecting the @agenticmail/api and @agenticmail/core packages prior to versions 0.9.32 and 0.9.10 respectively. The issue involves improper input validation and weaknesses in several security controls including inactive-agent hour filtering, SQL identifier validation, metadata ownership checks, blocking unauthorized SQL metadata access, secure handling of outbound worker secrets, SMTP envelope/header validation, and TLS certificate verification. These flaws could lead to integrity violations and partial denial of service. The vulnerability has been patched in the stated versions.

Join the discussion
CVE-2026-48978: CWE-918: Server-Side Request Forgery (SSRF) in oras-project oras-goCVE-2026-48978
0

oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, auth.Client follows the realm URL from a registry's WWW-Authenticate: Bearer challenge without validating the scheme or host, allowing a malicious or compromised registry to cause SSRF to internal networks such as http://169.254.169.254/, http://10.0.0.x/, and http://127.0.0.1/, or to downgrade a registry contacted over https:// to an http:// token endpoint in registry/remote/auth/client.go through Client.Do(), Client.fetchBearerToken(), fetchDistributionToken, and fetchOAuth2Token. This issue is fixed in version 2.6.1.

Join the discussion
CVE-2026-48022: CWE-319: Cleartext Transmission of Sensitive Information in hapijs wreckCVE-2026-48022
0

@hapi/wreck is an HTTP client utility. Prior to 18.1.2, Wreck strips credential headers including Authorization, Cookie, and Proxy-Authorization before following a cross-origin redirect, but the origin check compares hostnames only and ignores scheme and port, so credentials are forwarded intact across same-host port changes and HTTPS-to-HTTP downgrades, allowing a co-tenant on an adjacent port or a network-position attacker capable of forging a redirect to capture bearer tokens, session cookies, and proxy credentials and impersonate the victim against the upstream service. This issue is fixed in version 18.1.2.

Join the discussion
CVE-2026-34346: CWE-319: Cleartext Transmission of Sensitive Information in Microsoft Windows 10 Version 1607CVE-2026-34346
0

Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.

Join the discussion

Showing 1 to 6 of 6 results

Filters:Tag: cwe-319
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses