The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Volume of CVEs assigned to CWE-319 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
897 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-12710HIGH An issue was discovered on D-Link DIR-601 2.02NA devices. Being local to the network and having only "User" account (which is a low privilege account) access, an attacker can inter | Aug 29, 2018 | 8.0 | 78 | NO | YES |
CVE-2024-25735CRITICAL An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext passwords via a SoftAP /device/config GET request. | Mar 27, 2024 | 9.1 | 73 | NO | YES |
CVE-2017-5259HIGH In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, an undocumented, root-privilege administration web shell is available using the HTTP path https://<device-ip-or | Dec 20, 2017 | 8.8 | 59 | NO | YES |
CVE-2021-39341HIGH The OptinMonster WordPress plugin is vulnerable to sensitive information disclosure and unauthorized setting updates due to insufficient authorization validation via the logged_in_ | Nov 1, 2021 | 8.2 | 50 | NO | YES |
CVE-2016-5649CRITICAL A vulnerability is in the 'BSW_cxttongr.htm' page of the Netgear DGN2200, version DGN2200-V1.0.0.50_7.0.50, and DGND3700, version DGND3700-V1.0.0.17_1.0.17, which can allow a remot | Jul 24, 2018 | 9.8 | 49 | NO | YES |
CVE-2019-3993HIGH ELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. A remote unauthenticated attacker can recover a user's password hash by sending a crafted HTTP | Dec 17, 2019 | 7.5 | 47 | NO | NO |
CVE-2020-14930HIGH An issue was discovered in BT CTROMS Terminal OS Port Portal CT-464. Account takeover can occur because the password-reset feature discloses the verification token. Upon a getverif | Jun 19, 2020 | 8.1 | 38 | NO | YES |
CVE-2026-48902CRITICAL The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set. | May 26, 2026 | 9.8 | 36 | NO | NO |
CVE-2018-1297CRITICAL When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection. This could allow an attacker to get Access to JMeterEngine and send unauth | Feb 13, 2018 | 9.8 | 36 | NO | NO |
CVE-2026-47255HIGH AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0.9.10 had weakness related to v | Jul 20, 2026 | 8.2 | 35 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.