Weaknesses of type CWE-256

224 results

Senha codificada ou armazenamento em texto plano

É quando a senha ou credencial fica gravada direto no código-fonte, arquivo de configuração ou banco de dados sem criptografia. Qualquer um com acesso ao código, binário ou logs consegue ler a senha e comprometer sistemas. O risco aumenta exponencialmente se o código for versionado, distribuído ou ficar exposto em repositórios públicos.

Example

Um desenvolvedor escreve 'password = "admin123"' em uma variável de conexão ao banco, ou deixa credenciais de API em um arquivo .env commitado no Git. Um atacante clona o repositório ou decompila a aplicação e já tem acesso a sistemas críticos.

How to mitigate

Armazene senhas em gerenciadores de segredos (HashiCorp Vault, AWS Secrets Manager, Azure Key Vault), use variáveis de ambiente seguras, nunca commite credenciais no versionamento, e implemente rotação automática de senhas. Em bancos de dados, sempre aplique hash com salt (bcrypt, Argon2) em vez de armazenar em texto plano.

CVE-2025-46366MEDIUMDell CloudLink, versions prior to 8.1.1, contain a vulnerability where a privileged user may exploit and gain parallel privilege escalation EPSS 0.1%CVE-2025-21111HIGHDell VxRail, versions 8.0.000 through 8.0.311, contain(s) a Plaintext Storage of a Password vulnerability. A high privileged attacker with lEPSS 0.1%CVE-2026-82783MEDIUMPlaintext storage of a password issue exists in CONPROSYS nano Series . If this vulnerability is exploited, an attacker with physical accessEPSS 0.1%CVE-2026-44187LOWAnsible-lightspeed: ansible lightspeed extension for visual studio code: information disclosure of google gemini api keyEPSS 0.1%CVE-2023-31002MEDIUMIBM Security Access Manager Container information disclosureEPSS 0.1%CVE-2021-38489HIGHHDD Password Stored In PlaintextEPSS 0.1%CVE-2024-25024MEDIUMIBM QRadar Suite Software information disclosureEPSS 0.1%CVE-2025-25051MEDIUMAutomationDirect CLICK Programmable Logic Controller Plaintext Storage of a PasswordEPSS 0.1%CVE-2024-3082MEDIUMA “CWE-256: Plaintext Storage of a Password” affecting the administrative account allows an attacker with physical access to the machine to EPSS 0.1%CVE-2025-43938MEDIUMDell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) a Plaintext Storage of a Password vulnerability. A high priviEPSS 0.1%CVE-2025-11193MEDIUMA potential vulnerability was reported in some Lenovo Tablets that could allow a local authenticated user or application to gain access to sEPSS 0.1%CVE-2024-42197MEDIUMHCL Workload Scheduler is vulnerable to plain text storage of a passwordEPSS 0.1%CVE-2026-4243LOWLa Nacion App app.lanacion.activity BuildConfig.java credentials storageEPSS 0.1%CVE-2021-25358MEDIUMA vulnerability that stores IMSI values in an improper path prior to SMR APR-2021 Release 1 allows local attackers to access IMSI values witEPSS 0.1%CVE-2026-22285MEDIUMDell Device Management Agent (DDMA), versions prior to 26.02, contain a Plaintext Storage of Password vulnerability. A high privileged attacEPSS 0.1%CVE-2026-4250LOWAlbert Sağlık Hizmetleri ve Ticaret Albert Health Google Cloud Service Account Key service-account.json credentials storageEPSS 0.1%CVE-2026-4242LOWBabyChakra Pregnancy & Parenting App app.babychakra.babychakra Configuration.java credentials storageEPSS 0.1%CVE-2026-4251LOWCityData CityChat ai.citydata.citychat credentials.json credentials storageEPSS 0.1%CVE-2026-4217LOWXREAL Nebula App ai.nreal.nebula.universal CloudStoragePlugin.java credentials storageEPSS 0.1%CVE-2026-6500MEDIUMPlaintext storage of a password vulnerability in ILM Informatique OpenConcerto allows Retrieve Embedded Sensitive Data. This issue affects EPSS 0.1%