Weaknesses of type CWE-256

224 results

Senha codificada ou armazenamento em texto plano

É quando a senha ou credencial fica gravada direto no código-fonte, arquivo de configuração ou banco de dados sem criptografia. Qualquer um com acesso ao código, binário ou logs consegue ler a senha e comprometer sistemas. O risco aumenta exponencialmente se o código for versionado, distribuído ou ficar exposto em repositórios públicos.

Example

Um desenvolvedor escreve 'password = "admin123"' em uma variável de conexão ao banco, ou deixa credenciais de API em um arquivo .env commitado no Git. Um atacante clona o repositório ou decompila a aplicação e já tem acesso a sistemas críticos.

How to mitigate

Armazene senhas em gerenciadores de segredos (HashiCorp Vault, AWS Secrets Manager, Azure Key Vault), use variáveis de ambiente seguras, nunca commite credenciais no versionamento, e implemente rotação automática de senhas. Em bancos de dados, sempre aplique hash com salt (bcrypt, Argon2) em vez de armazenar em texto plano.

CVE-2025-53669MEDIUMJenkins VAddy Plugin 1.2.8 and earlier does not mask Vaddy API Auth Keys displayed on the job configuration form, increasing the potential fEPSS 0.2%CVE-2026-21660MEDIUMJohnson Controls-Frick Quantum HD-Hardcoded Email Credentials Saved as Plaintext in FirmwareEPSS 0.2%CVE-2021-36317MEDIUMDell EMC Avamar Server version 19.4 contains a plain-text password storage vulnerability in AvInstaller. A local attacker could potentially EPSS 0.2%CVE-2025-66910MEDIUMTurms Server v0.10.0-SNAPSHOT and earlier contains a plaintext password storage vulnerability in the administrator authentication system. ThEPSS 0.2%CVE-2025-3758HIGHExposure of Device Configuration without Authentication in WF2220EPSS 0.2%CVE-2021-23207MEDIUMFresenius Kabi Agilia Connect Infusion System plaintext storage of a passwordEPSS 0.2%CVE-2024-39922MEDIUMA vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA1) (All versions), LOGO! 12/24RCEo (6ED1052-2MD08-0BA1) (All versionEPSS 0.2%CVE-2026-19051HIGHPlaintext Storage of User Credentials in Menulux Software's Menulux PortalEPSS 0.2%CVE-2022-1794MEDIUMPlaintext Storage of a password in CODESYS V3 OPC DA ServerEPSS 0.2%CVE-2020-5315HIGHDell EMC Repository Manager (DRM) version 3.2 contains a plain-text password storage vulnerability. Proxy server user password is stored in EPSS 0.2%CVE-2022-22554HIGHDell EMC System Update, version 1.9.2 and prior, contain an Unprotected Storage of Credentials vulnerability. A local attacker with user priEPSS 0.2%CVE-2022-22557HIGHPowerStore contains Plain-Text Password Storage Vulnerability in PowerStore X & T environments running versions 2.0.0.x and 2.0.1.x A locallEPSS 0.2%CVE-2026-28360LOWNocoDB: Plaintext Storage of Shared View PasswordsEPSS 0.2%CVE-2024-42496LOWSmart-tab Android app installed April 2023 or earlier contains an issue with plaintext storage of a password. If this vulnerability is exploEPSS 0.2%CVE-2023-44300MEDIUM Dell DM5500 5.14.0.0, contain a Plain-text Password Storage Vulnerability in the appliance. A local attacker with privileges could potentEPSS 0.2%CVE-2025-53671MEDIUMJenkins Nouvola DiveCloud Plugin 1.08 and earlier does not mask DiveCloud API Keys and Credentials Encryption Keys displayed on the job confEPSS 0.2%CVE-2022-29085MEDIUMDell Unity, Dell UnityVSA, and Dell Unity XT versions prior to 5.2.0.0.5.173 contain a plain-text password storage vulnerability when certaiEPSS 0.2%CVE-2024-31899MEDIUMIBM Cognos Command Center information disclosureEPSS 0.2%CVE-2025-65009HIGHInsecure Password Storage in WODESYS WD-R608U routerEPSS 0.2%CVE-2025-36425MEDIUMIBM Db2 Information DisclosureEPSS 0.2%