Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-319
Weakness type CWE-319 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 91 | 88 | 0 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▃▆▃▆█▃
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 2 · 2026-04 0 · 2026-05 7 · 2026-06 19 · 2026-07 7 · 2026-08 19 · 2026-09 26 · 2026-10 8
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-21406 | 7.5 | 56.9 | — | Windows Printing Service Spoofing Vulnerability |
| CVE-2026-24212 | 9.8 | 49.6 | — | — |
| CVE-2026-3182 | 4.3 | 49.2 | — | Sensitive Data Exposure |
| CVE-2026-15806 | 6.0 | 38.0 | — | `HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorrect scheme… |
| CVE-2026-49486 | 7.5 | 36.2 | — | Apache Airflow FTP provider: FTP Provider does not protect FTPS data channel (missing P… |
| CVE-2026-55854 | 5.9 | 33.8 | — | MariaDB Connector/Node.js: Cleartext Transmission of Sensitive Information and Insuffic… |
| CVE-2026-45432 | 8.7 | 33.1 | — | Cleartext Transmission of Credentials Vulnerability in GX Earth ONT Models |
| CVE-2026-55857 | 5.9 | 30.8 | — | MariaDB Connector/J: Cleartext Transmission of Sensitive Information and Insufficiently… |
| CVE-2026-85719 | 7.5 | 27.6 | — | AsyncHttpClient: SOCKS proxy credentials sent to the origin server over plaintext HTTP |
| CVE-2026-4873 | 5.9 | 27.4 | — | connection reuse ignores TLS requirement |
| CVE-2026-6276 | 7.5 | 26.2 | — | stale custom cookie host causes cookie leak |
| CVE-2026-69658 | 9.3 | 25.6 | — | Ebyte NA111-M Cleartext Transmission of Sensitive Information |
| CVE-2026-25608 | 2.3 | 23.9 | — | Lack of traffic encryption in STER |
| CVE-2026-48902 | 9.8 | 23.3 | — | Joomla! Core - [20260518] - Transport encryption downgrade for password and username re… |
| CVE-2026-91988 | 9.2 | 22.6 | — | atomic-agents-stack before 1.1.0 Remote Code Execution via HTTP MCP |
| CVE-2026-50200 | 7.5 | 21.2 | — | Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords |
| CVE-2026-43625 | 8.2 | 20.8 | — | CodexBar < 0.32.0 Session Cookie Exposure via HTTP Redirect |
| CVE-2026-81836 | 2.9 | 18.8 | — | RooCodeInc Roo-Code OAuth Callback oauth.ts cleartext transmission |
| CVE-2026-69212 | 5.9 | 18.5 | — | Http4s: FollowRedirect middleware leaks credentials over https->http same-authority red… |
| CVE-2026-31278 | 7.7 | 18.2 | — | — |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| ibm | 5 |
| mariadb-corporation | 3 |
| rclone | 3 |
| teledyne flir | 3 |
| apache | 2 |
| asynchttpclient | 2 |
| curl | 2 |
| ebyte | 2 |
| hewlett packard enterprise (hpe) | 2 |
| microsoft | 2 |
| synology | 2 |
| tp-link systems | 2 |
| advantech | 1 |
| agenticmail | 1 |
| apollo pharmacy | 1 |