Weaknesses of type CWE-311
312 resultsAusência de criptografia de dados sensíveis
Quando dados sensíveis (senhas, tokens, PII, chaves) são transmitidos ou armazenados sem criptografia, qualquer pessoa com acesso à rede ou ao disco consegue lê-los diretamente. O risco é grave porque expõe informações críticas a interceptação ou roubo.
Example
Uma aplicação web envia credenciais de usuário em HTTP plano em vez de HTTPS, ou salva senhas em um arquivo de texto sem criptografar. Um atacante na mesma rede (ou com acesso ao servidor) captura as credenciais facilmente.
How to mitigate
Use HTTPS/TLS para toda transmissão de dados sensíveis, criptografe dados em repouso com algoritmos fortes (AES-256), implemente gestão segura de chaves e nunca armazene ou transmita dados sensíveis em claro. Revise logs e backups também.
CVE-2025-45768HIGHpyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length is chosen by the applEPSS 0.2%CVE-2014-6274HIGHS3 and Glacier remotes creds embedded in the git repo were not encryptedEPSS 0.2%CVE-2025-32875MEDIUMAn issue was discovered in the COROS application through 3.8.12 for Android. Bluetooth pairing and bonding is neither initiated nor enforcedEPSS 0.2%CVE-2026-32891CRITICALAnchorr Privilege Escalation: Jellyseerr User → Anchorr Admin via Stored XSSEPSS 0.2%CVE-2023-40251MEDIUMMissing Encryption of Sensitive Data vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian NAC Suite V5.0, GeniaEPSS 0.2%CVE-2025-64145MEDIUMJenkins ByteGuard Build Actions Plugin 1.0 does not mask API tokens displayed on the job configuration form, increasing the potential for atEPSS 0.2%CVE-2025-64144MEDIUMJenkins ByteGuard Build Actions Plugin 1.0 stores API tokens unencrypted in job config.xml files on the Jenkins controller where they can beEPSS 0.2%CVE-2025-64146MEDIUMJenkins Curseforge Publisher Plugin 1.0 stores API Keys unencrypted in job config.xml files on the Jenkins controller where they can be viewEPSS 0.2%CVE-2023-38267MEDIUMIBM Security Access Manager Appliance information disclosureEPSS 0.1%CVE-2025-8763MEDIUMRuijie EG306MG strongSwan strongswan.conf missing encryptionEPSS 0.1%CVE-2026-55568MEDIUMGuzzle: Silent HTTPS-Proxy Downgrade to CleartextEPSS 0.1%CVE-2024-56439HIGHAccess control vulnerability in the identity authentication module
Impact: Successful exploitation of this vulnerability may affect service EPSS 0.1%CVE-2023-50129MEDIUMMissing encryption in the NFC tags of the Flient Smart Door Lock v1.0 allows attackers to create a cloned tag via brief physical proximity tEPSS 0.1%CVE-2025-59410MEDIUMDragonfly tiny file download uses hard coded HTTP protocolEPSS 0.1%CVE-2025-13453MEDIUMA potential vulnerability was reported in some ThinkPlus USB drives that could allow a user with physical access to read data stored on the EPSS 0.1%CVE-2025-65825MEDIUMThe firmware on the basestation of the Meatmeet is not encrypted. An adversary with physical access to the Meatmeet device can disassemble tEPSS 0.1%CVE-2025-47274LOWToolHive stores secrets in the state store with no encryptionEPSS 0.1%CVE-2026-81681CRITICALopenssl_encrypt before 1.4.9 False Encryption via Cleartext StorageEPSS 0.1%CVE-2022-38194MEDIUMPortal for ArcGIS system properties are not properly encrypted (10.8.1 only)EPSS 0.1%CVE-2025-43274MEDIUMA privacy issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.6. A sandboxed process may be able toEPSS 0.1%