Threats Tagged 'cwe-319'
View all threats tagged with 'cwe-319'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-319'
Click on any threat for detailed analysis and mitigation recommendations
0 The Botslab G980H dash camera firmware transmits sensitive information over unencrypted HTTP and RTSP connections. An attacker capable of intercepting communications on the device's WiFi network could obtain stored recordings, live video, location information, images, diagnostic logs, or other sensitive information exchanged between the device and its mobile application. Join the discussion | CVE Database V5 | 09/24/2026, 20:28:47 UTC Added: 09/24/2026, 21:05:07 UTC |
0 IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive information. Join the discussion | CVE Database V5 | 09/22/2026, 22:21:06 UTC Added: 09/22/2026, 22:33:33 UTC |
0 IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive information. Join the discussion | CVE Database V5 | 09/22/2026, 22:02:11 UTC Added: 09/22/2026, 22:18:14 UTC |
0 Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active device across a subset of carriers that were connected to the affected MQTT broker. Join the discussion | CVE Database V5 | 09/18/2026, 15:48:16 UTC Added: 09/18/2026, 16:02:24 UTC |
0 IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques. Join the discussion | CVE Database V5 | 09/18/2026, 15:44:27 UTC Added: 09/18/2026, 15:47:08 UTC |
0 CVE-2026-54586 is a vulnerability in the MidnightBSD package manager mport prior to version 2.7.8. It involves cleartext transmission of sensitive information due to acceptance of non-HTTPS URLs for repository and package mirrors. This allows a network-positioned attacker to tamper with package index or download traffic, potentially compromising package selection or integrity. The issue is fixed in version 2.7.8. Join the discussion | CVE Database V5 | 09/17/2026, 16:53:24 UTC Added: 09/17/2026, 17:02:24 UTC |
0 AsyncHttpClient versions from 2.0.0 up to but not including 2.16.1, and from 3.0.0 up to but not including 3.0.12, have a vulnerability where HTTP proxy requests to HTTPS origins expose preemptive origin credentials in cleartext. This occurs because authorization headers are sent in the plaintext CONNECT request before the TLS tunnel is established, potentially exposing sensitive credentials to the proxy or observers on the client-to-proxy connection. The issue is fixed in versions 2.16.1 and 3.0.12. Join the discussion | CVE Database V5 | 09/17/2026, 16:00:01 UTC Added: 09/17/2026, 16:32:45 UTC |
0 AsyncHttpClient versions from 2.1.0 up to but not including 2.16.1 and from 3.0.0 up to but not including 3.0.12 allow proxy credentials to be exposed in cleartext. This occurs when using an authenticated SOCKS proxy, where the Proxy-Authorization header is attached to requests without verifying the proxy type, potentially exposing sensitive credentials to the origin server. The issue is fixed in versions 2.16.1 and 3.0.12. Join the discussion | CVE Database V5 | 09/17/2026, 15:52:16 UTC Added: 09/17/2026, 16:02:19 UTC |
0 CVE-2026-73174 is a high-severity vulnerability in the Advantech EKI-1242IEIMS device firmware version V1.06.01. It involves cleartext transmission of sensitive information via the edgserver management protocol, allowing a network-adjacent passive observer to intercept management traffic and recover sensitive device identity and network metadata. Join the discussion | CVE Database V5 | 09/16/2026, 12:59:58 UTC Added: 09/16/2026, 13:17:09 UTC |
0 Transmission of the home Wi-Fi credentials without encryption during the pairing process between the DuoxMe application and VEO and VEO-XS Wi-Fi monitors, in versions prior to 4.3.4 of the application and 01.50.001 of the monitor firmware, allows an attacker on the Wi-Fi Direct network to intercept the network password. Join the discussion | CVE Database V5 | 09/16/2026, 09:36:34 UTC Added: 09/16/2026, 09:47:09 UTC |
Showing 1 to 10 of 151 results