← Back
CWE-319

923 CVEs • Abstraction: Base • Likelihood of Exploit: High

Cleartext Transmission of Sensitive Information

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

JSON object

Loading...

CVEs (923)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hcltechsw
1Bigfix Insights For Vulnerability Remediation
Jun 17, 2026
Dec 21, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Insights for Vulnerability Remediation (IVR) is vulnerable to man-in-the-middle attacks that may lead to information disclosure.  This requires privileged network access.
1Whohas Project
1Whohas
Jun 17, 2026
Dec 19, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
A vulnerability was found in whohas. It has been rated as problematic. This issue affects some unknown processing of the component Package Information Handler. The manipulation leads to cleartext transmission of sensitiv...Show more
A vulnerability was found in whohas. It has been rated as problematic. This issue affects some unknown processing of the component Package Information Handler. The manipulation leads to cleartext transmission of sensitive information. The attack may be initiated remotely. The real existence of this vulnerability is still doubted at the moment. The name of the patch is 667c3e2e9178f15c23d7918b5db25cd0792c8472. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216251. NOTE: Most sources redirect to the encrypted site which limits the possibilities of an attack.Show less
1Ibm
1Spectrum Protect Plus
Jun 17, 2026
Dec 14, 2022
N/A· v4
5.9 MEDIUM· v3
N/A· v2
IBM Spectrum Protect Plus 10.1.0 through 10.1.12 discloses sensitive information due to unencrypted data being used in the communication flow between Spectrum Protect Plus vSnap and its agents. An attacker could obtain...Show more
IBM Spectrum Protect Plus 10.1.0 through 10.1.12 discloses sensitive information due to unencrypted data being used in the communication flow between Spectrum Protect Plus vSnap and its agents. An attacker could obtain information using main in the middle techniques. IBM X-Force ID: 182106. Show less
1Arcadyan
1Vrv9506jac23 Firmware
Jun 17, 2026
Dec 14, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The login password of the web administrative dashboard in Arcadyan Wifi routers VRV9506JAC23 is sent in cleartext, allowing an attacker to sniff and intercept traffic to learn the administrative credentials to the router...Show more
The login password of the web administrative dashboard in Arcadyan Wifi routers VRV9506JAC23 is sent in cleartext, allowing an attacker to sniff and intercept traffic to learn the administrative credentials to the router.Show less
1Siemens
1Sicam Pas/pqs
Jun 17, 2026
Dec 13, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability has been identified in SICAM PAS/PQS (All versions < V7.0). Affected software transmits the database credentials for the inbuilt SQL server in cleartext. In combination with the by default enabled xp_cmds...Show more
A vulnerability has been identified in SICAM PAS/PQS (All versions < V7.0). Affected software transmits the database credentials for the inbuilt SQL server in cleartext. In combination with the by default enabled xp_cmdshell feature unauthenticated remote attackers could execute custom OS commands. At the time of assigning the CVE, the affected firmware version of the component has already been superseded by succeeding mainline versions.Show less
1Gitea
1Gitea
Jun 17, 2026
Dec 12, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
In Jenkins Gitea Plugin 1.4.4 and earlier, the implementation of Gitea personal access tokens did not support credentials masking, potentially exposing them through the build log.
1Secu
1Secustation Firmware
Jun 17, 2026
Dec 8, 2022
N/A· v4
4.9 MEDIUM· v3
N/A· v2
In certain Secustation products the administrator account password can be read. This affects V2.5.5.3116-S50-SMA-B20171107A, V2.3.4.1301-M20-TSA-B20150617A, V2.5.5.3116-S50-RXA-B20180502A, V2.5.5.3116-S50-SMA-B20190723A,...Show more
In certain Secustation products the administrator account password can be read. This affects V2.5.5.3116-S50-SMA-B20171107A, V2.3.4.1301-M20-TSA-B20150617A, V2.5.5.3116-S50-RXA-B20180502A, V2.5.5.3116-S50-SMA-B20190723A, V2.5.5.3116-S50-SMB-B20161012A, V2.3.4.2103-S50-NTD-B20170508B, V2.5.5.3116-S50-SMB-B20160601A, V2.5.5.2601-S50-TSA-B20151229A, and V2.5.5.3116-S50-SMA-B20170217.Show less
1Openharmony
1Openharmony
Jun 17, 2026
Dec 8, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
OpenHarmony-v3.1.4 and prior versions had an vulnerability. PIN code is transmitted to the peer device in plain text during cross-device authentication, which reduces the difficulty of man-in-the-middle attacks.
1Telepad App
1Telepad
Jun 17, 2026
Dec 5, 2022
N/A· v4
5.9 MEDIUM· v3
N/A· v2
Telepad allows an attacker (in a man-in-the-middle position between the server and a connected device) to see all data (including keypresses) in cleartext. CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
1Lazy Mouse Project
1Lazy Mouse
Jun 17, 2026
Dec 2, 2022
N/A· v4
5.9 MEDIUM· v3
N/A· v2
Lazy Mouse allows an attacker (in a man in the middle position between the server and a connected device) to see all data (including keypresses) in cleartext. CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
1Beappsmobile
1Pc Keyboard Wifi & Bluetooth
Jun 17, 2026
Dec 2, 2022
N/A· v4
5.9 MEDIUM· v3
N/A· v2
PC Keyboard WiFi & Bluetooth allows an attacker (in a man-in-the-middle position between the server and a connected device) to see all data (including keypresses) in cleartext. CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:...Show more
PC Keyboard WiFi & Bluetooth allows an attacker (in a man-in-the-middle position between the server and a connected device) to see all data (including keypresses) in cleartext. CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NShow less
1Nextcloud
1Openid Connect User Backend
Jun 17, 2026
Nov 25, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
user_oidc is an OpenID Connect user backend for Nextcloud. In versions prior to 1.2.1 sensitive information such as the OIDC client credentials and tokens are sent in plain text of HTTP without TLS. Any malicious actor w...Show more
user_oidc is an OpenID Connect user backend for Nextcloud. In versions prior to 1.2.1 sensitive information such as the OIDC client credentials and tokens are sent in plain text of HTTP without TLS. Any malicious actor with access to monitor user traffic may have been able to compromise account security. This issue has been addressed in in user_oidc v1.2.1. Users are advised to upgrade. Users unable to upgrade may use https to access Nextcloud. Set an HTTPS discovery URL in the provider settings (in Nextcloud OIDC admin settings).Show less
1Web Based Quiz System Project
1Web Based Quiz System
Jun 17, 2026
Nov 25, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Web Based Quiz System v1.0 transmits user passwords in plaintext during the authentication process, allowing attackers to obtain users' passwords via a bruteforce attack.
1Solarwinds
1Engineer's Toolset
Jun 17, 2026
Nov 23, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The application fails to prevent users from connecting to it over unencrypted connections. An attacker able to modify a legitimate user's network traffic could bypass the application's use of SSL/TLS encryption and use t...Show more
The application fails to prevent users from connecting to it over unencrypted connections. An attacker able to modify a legitimate user's network traffic could bypass the application's use of SSL/TLS encryption and use the application as a platform for attacks against its users.Show less
1Concretecms
1Concrete Cms
Jun 17, 2026
Nov 14, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 inadvertently disclose server-side sensitive information (secrets in environment variables and server information) when Debug Mode is left on in...Show more
Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 inadvertently disclose server-side sensitive information (secrets in environment variables and server information) when Debug Mode is left on in production.Show less
1Xiongmaitech
1Xm Jpr2 Lx Firmware
Jun 17, 2026
Nov 14, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Xiongmai Camera XM-JPR2-LX V4.02.R12.A6420987.10002.147502.00000 is vulnerable to plain-text traffic sniffing.
1Upspowercom
1Upsmon Pro
Jun 17, 2026
Nov 10, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
UPSMON PRO transmits sensitive data in cleartext over HTTP protocol. An unauthenticated remote attacker can exploit this vulnerability to access sensitive data.
1Mitsubishielectric
178Ma Ew85s E Firmware
Ma Ew85s Uk FirmwareMac 507if E Firmware+175 more
Jun 17, 2026
Nov 8, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Cleartext Transmission of Sensitive Information vulnerability due to the use of Basic Authentication for HTTP connections in Mitsubishi Electric consumer electronics products (PHOTOVOLTAIC COLOR MONITOR ECO-GUIDE, HEMS a...Show more
Cleartext Transmission of Sensitive Information vulnerability due to the use of Basic Authentication for HTTP connections in Mitsubishi Electric consumer electronics products (PHOTOVOLTAIC COLOR MONITOR ECO-GUIDE, HEMS adapter, Wi-Fi Interface, Air Conditioning, Induction hob, Mitsubishi Electric HEMS Energy Measurement Unit, Refrigerator, Remote control with Wi-Fi Interface, BATHROOM THERMO VENTILATOR, Rice cooker, Mitsubishi Electric HEMS control adapter, Energy Recovery Ventilator, Smart Switch, Ventilating Fan, Range hood fan, Energy Measurement Unit and Air Purifier) allows a remote unauthenticated attacker to disclose information in the products or cause a denial of service (DoS) condition as a result by sniffing credential information (username and password). The wide range of models/versions of Mitsubishi Electric consumer electronics products are affected by this vulnerability. As for the affected product models/versions, see the Mitsubishi Electric's advisory which is listed in [References] section. Show less
1Ibm
1Security Guardium
Jun 17, 2026
Nov 3, 2022
N/A· v4
4.4 MEDIUM· v3
N/A· v2
IBM Security Guardium 10.5, 10.6, 11.0, 11.1, 11.2, 11.3, and 11.4 stores user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 215587.
1Hitachi
1Vantara Pentaho
Jun 17, 2026
Nov 2, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Hitachi Vantara Pentaho Business Analytics Server versions before 9.3.0.0, 9.2.0.2 and 8.3.0.25 with the Data Lineage feature enabled transmits database passwords in clear text.   The transmission of sensitive data in...Show more
Hitachi Vantara Pentaho Business Analytics Server versions before 9.3.0.0, 9.2.0.2 and 8.3.0.25 with the Data Lineage feature enabled transmits database passwords in clear text.   The transmission of sensitive data in clear text allows unauthorized actors with access to the network to sniff and obtain sensitive information that can be later used to gain unauthorized access. Show less