VulnSea

CWE-319

CVEs classified under CWE-319, newest first.

47 CVEsRSS

CVE-2026-18536None
1mo ago

Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP. The Data::Entropy::RawSource::RandomOrg and Data::Entropy::RawSource::RandomnumbersInfo remote sources are accessed over plain HTTP. The Data::En…

Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP. The Data::Entropy::RawSource::RandomOrg and Data::Entropy::RawSource::RandomnumbersInfo remote sources are accessed over plain HTTP. The Data::En…

SunlitEPSS 0.15%via NVD
CVE-2026-34346Medium· 5.5
2mo ago

Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.

Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.

Sunlitmicrosoft · windows_10_1607EPSS 0.27%via NVD
CVE-2026-53624Medium· 4.8
2mo ago

GoFiber never set HSTS header in helmet middleware due to incorrect protocol check

GoFiber never set HSTS header in helmet middleware due to incorrect protocol check

Sunlitgofiber · github.com/gofiber/fiberEPSS 0.21%via GHSA
CVE-2026-50200High· 7.5
2mo ago

Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords

Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords

TwilightSteeltoe · Steeltoe.Management.EndpointEPSS 0.18%via GHSA
CVE-2026-48978Low
2mo ago

oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens

oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens

Sunlitoras-go · oras.land/oras-go/v2EPSS 0.26%via GHSA
CVE-2026-49486High· 7.5
2mo ago

The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p()`, so although the control channel was TLS-protected the data channel was transmitted in cleartext

The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p()`, so although the control channel was TLS-protected the data channel was transmitted in cleartext. Any deployment u…

Twilightapache · apache-airflow-providers-ftpEPSS 0.44%via NVD
CVE-2026-55568Medium· 5.9
3mo ago

guzzlehttp/guzzle: Silent HTTPS-Proxy Downgrade to Cleartext

guzzlehttp/guzzle: Silent HTTPS-Proxy Downgrade to Cleartext

Sunlitguzzlehttp · guzzlehttp/guzzleEPSS 0.15%via GHSA
CVE-2026-48022Medium· 6.5
3mo ago

@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects

@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects

Sunlithapi · @hapi/wreckEPSS 0.18%via GHSA
CVE-2026-6276High· 7.5PoC⚖ disputed
4mo ago

Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information…

Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information…

Midnighthaxx · curlEPSS 0.29%via NVD
CVE-2026-4873Medium· 5.9
4mo ago

A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool

A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool. If an initial transfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request to …

Sunlithaxx · curlEPSS 0.33%via NVD
CVE-2026-22155Medium· 6.5
5mo ago

A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.…

A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.…

Sunlitfortinet · fortisoarEPSS 0.17%via NVD
CVE-2026-21742Medium· 5.7
5mo ago

A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.…

A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.…

Sunlitfortinet · fortisoarEPSS 0.15%via NVD
CVE-2026-2671Low· 3.1
6mo ago

A vulnerability was detected in Mendi Neurofeedback Headset V4

A vulnerability was detected in Mendi Neurofeedback Headset V4. Affected by this vulnerability is an unknown functionality of the component Bluetooth Low Energy Handler. Performing a manipulation results in cleartext transmission of sens…

SunlitMendi · Neurofeedback HeadsetEPSS 0.20%via NVD
CVE-2026-20801Medium· 5.6
6mo ago

Cleartext Transmission of Sensitive Information (CWE-319) in a component used in the Gallagher Hanwha VMS and Gallagher NxWitness VMS integrations allows unprivileged users with local network access to view live video streams

Cleartext Transmission of Sensitive Information (CWE-319) in a component used in the Gallagher Hanwha VMS and Gallagher NxWitness VMS integrations allows unprivileged users with local network access to view live video streams. This …

Sunlitgallagher · hanwha_vms_integrationEPSS 0.10%via NVD
CVE-2025-56447Critical· 9.8
11mo ago

TM2 Monitoring v3.04 contains an authentication bypass and plaintext credential disclosure.

TM2 Monitoring v3.04 contains an authentication bypass and plaintext credential disclosure.

MidnightEPSS 0.27%via NVD
CVE-2025-40583Medium· 4.4
1y ago

A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge Client installed)

A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge Client installed). Affected devices do transmit sensitive information in cleartext. This could allow a…

Sunlitsiemens · scalance_lpe9403_firmwareEPSS 0.11%via NVD
CVE-2024-10973Medium· 5.7
1y ago

A vulnerability was found in Keycloak

A vulnerability was found in Keycloak. The environment option `KC_CACHE_EMBEDDED_MTLS_ENABLED` does not work and the JGroups replication configuration is always used in plain text which can allow an attacker that has access to adjacent n…

SunlitEPSS 0.27%via NVD
CWE-319 vulnerabilities (CVEs) — page 2 · VulnSea