Weaknesses of type CWE-319

538 results

Transmissão de dados sensíveis em texto plano

A aplicação envia informações críticas (senhas, tokens, dados pessoais) sem criptografia em canais de comunicação que podem ser interceptados. Um atacante na rede consegue capturar esses dados diretamente, comprometendo a confidencialidade da informação e permitindo roubo de credenciais ou dados sensíveis.

Example

Um app mobile envia login e senha via HTTP (não HTTPS), ou um sistema transmite números de cartão de crédito em requisições não criptografadas. Ferramentas simples como Wireshark permitem capturar esse tráfego em redes abertas ou mesmo corporativas.

How to mitigate

Sempre usar HTTPS/TLS para qualquer transmissão de dados sensíveis, implementar pinning de certificado em apps mobile, validar certificados no lado cliente, e nunca transmitir segredos em URLs ou headers sem criptografia. Na prática: configure HTTPS em produção, force redirecionamento HTTP → HTTPS, e audite logs de requisições para detectar canais desprotegidos.

CVE-2025-61481CRITICALAn issue in MikroTik RouterOS v.7.14.2 and SwOS v.2.18 exposes the WebFig management interface over cleartext HTTP by default, allowing an oEPSS 0.3%CVE-2025-47419CRITICALNon-Secure AccessEPSS 0.3%CVE-2026-55854MEDIUMMariaDB Connector/Node.js: Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials in mariadbEPSS 0.3%CVE-2021-21270MEDIUMCleartext Storage of Sensitive InformationEPSS 0.3%CVE-2025-0631HIGHPowerFlex® 755 Credential Exposure VulnerabilityEPSS 0.3%CVE-2024-39746MEDIUMIBM Sterling Connect:Direct Web Services information disclosureEPSS 0.3%CVE-2024-30209CRITICALA vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating ManageEPSS 0.3%CVE-2024-10973MEDIUMKeycloak: cli option for encrypted jgroups ignoredEPSS 0.3%CVE-2026-30795HIGHRustDesk HTTP Client Silently Accepts Invalid TLS Certificates After Handshake FailureEPSS 0.3%CVE-2024-41124MEDIUMPuncia Cleartext Transmission of Sensitive Information via HTTP urls in `API_URLS`EPSS 0.3%CVE-2026-34346MEDIUMWindows Ancillary Function Driver for WinSock Information Disclosure VulnerabilityEPSS 0.3%CVE-2023-31195MEDIUMASUS Router RT-AX3000 Firmware versions prior to 3.0.0.4.388.23403 uses sensitive cookies without 'Secure' attribute. When an attacker is inEPSS 0.3%CVE-2026-11833HIGHOverview: A vulnerability has been found in FAST/TOOLS and CI Server. The web server may return a response containing the CI Server settingEPSS 0.3%CVE-2025-50110HIGHAn issue was discovered in the method push.lite.avtech.com.AvtechLib.GetHttpsResponse in AVTECH EagleEyes Lite 2.0.0, the GetHttpsResponse mEPSS 0.3%CVE-2021-32456MEDIUMSITEL CAP/PRX cleartext transmission of sensitive informationEPSS 0.3%CVE-2024-41757MEDIUMIBM Concert Software information disclosureEPSS 0.3%CVE-2022-41983LOWBIG-IP TMM Vulnerability CVE-2022-41983EPSS 0.3%CVE-2025-53756HIGHCleartext Transmission Vulnerability in Digisol DG-GR6821AC RouterEPSS 0.3%CVE-2025-63364HIGHWaveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.002880.0301 was discovEPSS 0.3%CVE-2023-33837MEDIUMIBM Security Verify Governance information disclosureEPSS 0.3%