CWE-319

CWE-319 · 11 records · 7 with a public proof-of-concept

Records the NVD classes under CWE-319, highest CVSS first.

  1. HIGH 7.5CVE-2026-18134

    IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive information.

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 7.5CVE-2026-85719public PoC

    The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.1.0 until 2.16.1 and 3.0.12, requests using an authenticated SOCKS proxy can expose the proxy's credentials to the orig…

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 7.4CVE-2026-18176

    IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive information.

    AI risk analysis on Exploit-DB.ai →

  4. MEDIUM 6.5CVE-2026-82585public PoC

    The Botslab G980H dash camera firmware transmits sensitive information over unencrypted HTTP and RTSP connections. An attacker capable of intercepting communications on the device's WiFi network could obtain stored recordings, live video, location information,…

    AI risk analysis on Exploit-DB.ai →

  5. MEDIUM 5.9CVE-2026-100635public PoC

    SiYuan before v3.8.4 contains an authentication bypass vulnerability in the publish service where session cookies are issued without Secure or SameSite attributes over plaintext HTTP connections. An on-path attacker can observe a valid publish-visitor-session-…

    AI risk analysis on Exploit-DB.ai →

  6. MEDIUM 5.9CVE-2026-85720public PoC

    The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, a request using an HTTP proxy to reach an HTTPS origin can expose preemptive origin creden…

    AI risk analysis on Exploit-DB.ai →

  7. LOW 3.7CVE-2026-96550public PoC

    A vulnerability was found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This issue affects the function getProperties of the file ssm_pro/src/main/java/cn/sfturing/utils/MailUtil.java. Performing a manipulation results in cleartext tra…

    AI risk analysis on Exploit-DB.ai →

  8. LOW 3.1CVE-2026-101057public PoC

    utcp-mcp (the MCP plugin of python-utcp) through 1.1.2 connects to the HTTP and WebSocket MCP server URLs given in a call template's mcpServers configuration without the ensure_secure_url validation that the HTTP-family plugins apply, so the HTTPS/WSS-or-loopb…

    AI risk analysis on Exploit-DB.ai →

  9. UNSCOREDCVE-2026-54586public PoC

    mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_index(), mport_fetch_bootstrap_index(), and mport_fetch_bundle() paths in libmport/fetch.c accepted non-HTTPS repository and package mirror URLs without a url_is_https() enforcement chec…

    AI risk analysis on Exploit-DB.ai →

  10. UNSCOREDCVE-2026-73174

    Nozomi Networks Labs identified a CWE-319: Cleartext Transmission of Sensitive Information vulnerability in the edgserver management protocol of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a network-adjacent passive observer to intercept ma…

    AI risk analysis on Exploit-DB.ai →

  11. UNSCOREDCVE-2026-85628

    Transmission of the home Wi-Fi credentials without encryption during the pairing process between the DuoxMe application and VEO and VEO-XS Wi-Fi monitors, in versions prior to 4.3.4 of the application and 01.50.001 of the monitor firmware, allows an attacker o…

    AI risk analysis on Exploit-DB.ai →