CWE-319: Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
423 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-47419 — Non-Secure Access
- CVE-2025-11492 — HTTP Configuration and Encryption in Transit
- CVE-2025-27720 — Pixmeo OsiriX MD Cleartext Transmission of Sensitive Information
- CVE-2024-9834 — Improper data protection on Life2000 ventilator serial interface
- CVE-2026-24060 — Automated Logic WebCTRL Premium Server Cleartext Transmission of Sensitive Information
- CVE-2025-54156 — Santesoft Sante PACS Server Cleartext Transmission of Sensitive Information
- CVE-2024-12378 — On affected platforms running Arista EOS with secure Vxlan configured, restarting the Tunnelsec agent will result in packets being sent over the secure Vxlan tunnels in the clear.
- CVE-2025-0556 — Telerik Report Server Clear Text Transmission of Agent Commands
- CVE-2026-32309 — Cryptomator: Hub unlocking accepts plaintext HTTP and unvalidated endpoint schemes
- CVE-2026-30795 — RustDesk HTTP Client Silently Accepts Invalid TLS Certificates After Handshake Failure
- CVE-2026-22544 — EXCHANGE OF CREDENTIALS IN CLEAR TEXT
- CVE-2026-22080 — Insecure Transmission Vulnerability in Tenda Wireless Routers
- CVE-2026-22079 — Cleartext Transmission Vulnerability in Tenda Wireless Routers
- CVE-2025-62765 — General Industrial Controls Lynx+ Gateway Cleartext Transmission of Sensitive Information
- CVE-2025-53756 — Cleartext Transmission Vulnerability in Digisol DG-GR6821AC Router
- CVE-2025-53703 — DuraComm DP-10iN-100-MU Cleartext Transmission of Sensitive Information
- CVE-2025-42603 — Information Disclosure Vulnerability in Meon KYC solutions
- CVE-2025-34271 — Nagios Log Server < 2024R2.0.2 Cluster Manager Credential Requests Sent Over Plaintext
- CVE-2025-1060 — CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists that could result in the exposure of data
- CVE-2025-0631 — PowerFlex® 755 Credential Exposure Vulnerability
Recently published
- CVE-2026-81330 — Softish C6 Ear Camera and EarVision Android Application Cleartext transmission of sensitive information
- CVE-2026-87482 — Cleartext transmission of sensitive data in HttpsUpgrades in Google Chrome on on iOS prior to 153.0.8010.36 allowed a re
- CVE-2026-71216 — Apache SkyWalking: PagerDuty alarm hook transmits the integration routing key over cleartext HTTP
- CVE-2026-84381 — HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies
- CVE-2026-84366 — Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default
- CVE-2026-55860 — MariaDB Connector/R2DBC: Cleartext password disclosure to a man-in-the-middle server (clear-text auth plugins not gated on a secure transport)
- CVE-2026-55857 — MariaDB Connector/J: Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials
- CVE-2026-55854 — MariaDB Connector/Node.js: Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials in mariadb
- CVE-2026-69658 — Ebyte NA111-M Cleartext Transmission of Sensitive Information
- CVE-2026-73809 — Ebyte NA111-M Cleartext Transmission of Sensitive Information
- CVE-2026-81836 — RooCodeInc Roo-Code OAuth Callback oauth.ts cleartext transmission
- CVE-2026-19854 — CVE-2026-19854 CVE Record
- CVE-2026-81691 — openssl_encrypt before 1.4.9 Credential Leakage via Unvalidated Server URLs
- CVE-2026-29988 — A cleartext transmission of sensitive information vulnerability in the NFC interface of multiple Milesight IoT device mo
- CVE-2026-80216 — A cleartext transmission of sensitive information vulnerability in the NFC interface of multiple Milesight IoT device mo
- CVE-2026-79782 — rclone before 1.74.4 Security Token Disclosure via HTTPS to HTTP Redirect
- CVE-2026-79779 — rclone before v1.75.0 WebDAV Credential Exposure via HTTPS-to-HTTP Redirect
- CVE-2026-77131 — Cleartext Transmission of Sensitive Information in extension "SYSSY - TYPO3 Monitoring & Security Checks" (syssy)
- CVE-2026-12556 — HP Easy Start for macOS - Security Update
- CVE-2026-19683 — Unencrypted Credential Transmission in Omada Gateway Dynamic DNS Authentication in Omada Gateways