VulnSea

CWE-319

CVEs classified under CWE-319, newest first.

47 CVEsRSS

CVE-2026-86689Medium· 5.9
3d ago

Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active device across a subset of carriers that were connected to the affected MQTT broker.

Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active device across a subset of carriers that were connected to the affected MQTT broker.

SunlitBransys · ELDEPSS 0.15%via NVD
CVE-2025-36421Medium· 5.9
3d ago

IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.

IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.

SunlitIBM · ControllerEPSS 0.20%via NVD
CVE-2026-54586Medium· 6.0
4d ago

mport is the MidnightBSD Package Manager

mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_index(), mport_fetch_bootstrap_index(), and mport_fetch_bundle() paths in libmport/fetch.c accepted non-HTTPS repository and package mirror URLs without a url_is_h…

SunlitMidnightBSD · mportEPSS 0.13%via NVD
CVE-2026-85720Medium· 5.9
4d ago

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, a request using an HTTP proxy to reach an HTTPS origin can expose p…

Sunlitasynchttpclient · org.asynchttpclient:async-http-clientEPSS 0.25%via NVD
CVE-2026-85719High· 7.5
4d ago

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.1.0 until 2.16.1 and 3.0.12, requests using an authenticated SOCKS proxy can expose the proxy's …

TwilightAsyncHttpClient · async-http-clientEPSS 0.21%via NVD
CVE-2026-73174High· 8.7
5d ago

Nozomi Networks Labs identified a CWE-319: Cleartext Transmission of Sensitive Information vulnerability in the edgserver management protocol of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a network-adjacent passive o…

Nozomi Networks Labs identified a CWE-319: Cleartext Transmission of Sensitive Information vulnerability in the edgserver management protocol of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a network-adjacent passive o…

TwilightAdvantech · EKI-1242IEIMSEPSS 0.14%via NVD
CVE-2026-85628High· 7.0
5d ago

Transmission of the home Wi-Fi credentials without encryption during the pairing process between the DuoxMe application and VEO and VEO-XS Wi-Fi monitors, in versions prior to 4.3.4 of the application and 01.50.001 of the monitor firmwar…

Transmission of the home Wi-Fi credentials without encryption during the pairing process between the DuoxMe application and VEO and VEO-XS Wi-Fi monitors, in versions prior to 4.3.4 of the application and 01.50.001 of the monitor firmwar…

TwilightFermax Electronica S.A.U. · com.fermax.blue.appEPSS 0.08%via NVD
CVE-2026-69212Medium· 5.9PoC
6d ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The FollowRedirect client middleware strips Authorization and Cookie headers only when a redirect changes authority, but authority comparison excludes the URI…

Twilighthttp4s · http4sEPSS 0.24%via NVD
CVE-2026-91988High· 8.1
6d ago

atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the HTTP MCP server-registry backend factory, allowing network man-in-the-middle attackers to rewrite catalog responses

atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the HTTP MCP server-registry backend factory, allowing network man-in-the-middle attackers to rewrite catalog responses. Attackers can inject arbitrary command and argume…

Twilightdep0we · atomic-agents-stackEPSS 0.25%via NVD
CVE-2026-31278High· 7.7PoC
1w ago

An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0.2 allows attackers to obtain Active Directory service account credentials in cleartext by supplying a crafted GET re…

An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0.2 allows attackers to obtain Active Directory service account credentials in cleartext by supplying a crafted GET re…

Midnightsupremainc · BioStar 2EPSS 0.17%via NVD
CVE-2026-88013Low· 3.7PoC
1w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.49.0 until 1.75.1, the HTTP backend attaches headers configured through --http-headers or headers= to requests in backen…

Twilightrclone · rcloneEPSS 0.18%via NVD
CVE-2026-81330Medium· 6.5
1w ago

The C6 ear camera transmits live video to the EarVision Android application over unencrypted UDP streams

The C6 ear camera transmits live video to the EarVision Android application over unencrypted UDP streams. The application manifest permits cleartext traffic, and captured network traffic contains reconstructable JPEG or WEBP video frames…

SunlitSoftish · EarVision Android applicationEPSS 0.07%via NVD
CVE-2026-87482Medium· 5.9
1w ago

Cleartext transmission of sensitive data in HttpsUpgrades in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via crafted network traffic

Cleartext transmission of sensitive data in HttpsUpgrades in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via crafted network traffic. (Chromium security severity: Medium)

Sunlitgoogle · chromeEPSS 0.18%via NVD
CVE-2026-79588Medium· 4.3PoC
1w ago

U-speed WIFI4 N300 T1 Pro v1.0.0 is vulnerable to Cleartext transmission of administration credentials over HTTP.

U-speed WIFI4 N300 T1 Pro v1.0.0 is vulnerable to Cleartext transmission of administration credentials over HTTP.

TwilightEPSS 0.10%via NVD
CVE-2026-71216Medium· 5.3
2w ago

PagerDuty alarm hook transmits the integration routing key over cleartext HTTP. PagerDuty serves this endpoint over HTTPS and will normally answer plain HTTP with a redirect

PagerDuty alarm hook transmits the integration routing key over cleartext HTTP. PagerDuty serves this endpoint over HTTPS and will normally answer plain HTTP with a redirect. That does not remove the exposure. The initial POST -- incl…

SunlitApache Software Foundation · Apache SkyWalkingEPSS 0.15%via NVD
CVE-2026-84381High· 8.1
2w ago

HTTPX2 is a next generation HTTP client for Python

HTTPX2 is a next generation HTTP client for Python. Prior to 2.10.0, httpcore2 fails to start TLS in src/httpcore2/httpcore2/_sync/socks_proxy.py and src/httpcore2/httpcore2/_async/socks_proxy.py when the remote origin uses wss through a…

Twilighthttpcore2 · httpcore2EPSS 0.08%via NVD
CVE-2026-84366High· 7.4
2w ago

Scrapy is a high-level web crawling and scraping framework for Python

Scrapy is a high-level web crawling and scraping framework for Python. Prior to 2.17.0, in scrapy/core/downloader/handlers/s3.py, Scrapy's S3DownloadHandler converts an S3-scheme bucket and key request into a plaintext HTTP request to th…

Twilightscrapy · scrapyEPSS 0.16%via NVD
GHSA-vx52-2968-3vc6High· 7.4
2w ago

pnpm: Environment secrets exfiltrated via env-placeholder expansion in proxy settings read from an untrusted pnpm-workspace.yaml

pnpm: Environment secrets exfiltrated via env-placeholder expansion in proxy settings read from an untrusted pnpm-workspace.yaml

Twilightpnpm · pnpmvia GHSA
CVE-2026-55857Medium· 5.9
3w ago

MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases

MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, PAM dialog authentication can be coerced into transmitting the account password over an insec…

Sunlitmariadb · org.mariadb.jdbc:mariadb-java-clientEPSS 0.20%via NVD
CVE-2026-55860Medium· 5.9
3w ago

MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java

MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java. Prior to 1.4.1, org.mariadb:r2dbc-mariadb does not gate clear-text password authentication plugins on transport encryption because the Authentication…

Sunlitmariadb · org.mariadb:r2dbc-mariadbEPSS 0.15%via NVD
CVE-2026-55854Medium· 5.9
3w ago

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.4, 3.3.3, 3.4.6, and 3.5.3, MariaDB Connector/Node.js can disclose an account password when PAM dialog authentica…

Sunlitmariadb · mariadbEPSS 0.28%via NVD
CVE-2026-29988High· 7.6
3w ago

A cleartext transmission of sensitive information vulnerability in the NFC interface of multiple Milesight IoT device models running affected firmware versions allows an unauthenticated attacker with physical proximity to retrieve LoRaWA…

A cleartext transmission of sensitive information vulnerability in the NFC interface of multiple Milesight IoT device models running affected firmware versions allows an unauthenticated attacker with physical proximity to retrieve LoRaWA…

TwilightEPSS 0.15%via NVD
CVE-2026-79779Medium· 5.3
3w ago

rclone versions before v1.75.0 fail to reject transport downgrades in redirect handling, allowing Basic authorization and Cookie headers to be replayed over plaintext HTTP after same-host HTTPS-to-HTTP redirects

rclone versions before v1.75.0 fail to reject transport downgrades in redirect handling, allowing Basic authorization and Cookie headers to be replayed over plaintext HTTP after same-host HTTPS-to-HTTP redirects. An on-path attacker obse…

Sunlitrclone · github.com/rclone/rcloneEPSS 0.11%via NVD
CVE-2026-79782Low· 3.1
3w ago

rclone before 1.74.4 fails to strip the X-Amz-Security-Token header when an S3 redirect changes scheme from HTTPS to HTTP on the same host

rclone before 1.74.4 fails to strip the X-Amz-Security-Token header when an S3 redirect changes scheme from HTTPS to HTTP on the same host. Attackers can intercept plaintext HTTP traffic to capture AWS STS session tokens sent in request …

Sunlitrclone · github.com/rclone/rcloneEPSS 0.13%via NVD
CVE-2026-19683High· 7.4
1mo ago

A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways

A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During communication with a third-party DDNS service, authentication credentials are transmitted over an unencrypted channel. An attacker who can o…

Twilighttp-link · er7212pc_firmwareEPSS 0.25%via NVD
CVE-2026-76244Critical
1mo ago

stigmem-node contains an insecure default configuration vulnerability that allows federation traffic to traverse networks without mTLS protection when non-loopback endpoints are enabled

stigmem-node contains an insecure default configuration vulnerability that allows federation traffic to traverse networks without mTLS protection when non-loopback endpoints are enabled. Operators who explicitly disabled mTLS while bindi…

Midnightstigmem-node · stigmem-nodeEPSS 0.22%via NVD
GHSA-xhcr-cqfr-m3hvHigh
1mo ago

atomic-agents-stack: HTTP MCP catalog accepts cleartext http and spawns catalog-supplied commands (MITM to RCE)

atomic-agents-stack: HTTP MCP catalog accepts cleartext http and spawns catalog-supplied commands (MITM to RCE)

Twilightatomic-agents-stack · atomic-agents-stackvia GHSA
GHSA-8mxv-9xhp-86h4Medium· 5.3
1mo ago

rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys

rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys

Sunlitrclone · github.com/rclone/rclonevia GHSA
GHSA-h4mf-4v27-hggjMedium· 5.3
1mo ago

rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect

rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect

Sunlitrclone · github.com/rclone/rclonevia GHSA
GHSA-gx4c-2hqx-cw2rLow· 3.1
1mo ago

rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect

rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect

Sunlitrclone · github.com/rclone/rclonevia GHSA
CWE-319 vulnerabilities (CVEs) · VulnSea