Weaknesses of type CWE-319

538 results

Transmissão de dados sensíveis em texto plano

A aplicação envia informações críticas (senhas, tokens, dados pessoais) sem criptografia em canais de comunicação que podem ser interceptados. Um atacante na rede consegue capturar esses dados diretamente, comprometendo a confidencialidade da informação e permitindo roubo de credenciais ou dados sensíveis.

Example

Um app mobile envia login e senha via HTTP (não HTTPS), ou um sistema transmite números de cartão de crédito em requisições não criptografadas. Ferramentas simples como Wireshark permitem capturar esse tráfego em redes abertas ou mesmo corporativas.

How to mitigate

Sempre usar HTTPS/TLS para qualquer transmissão de dados sensíveis, implementar pinning de certificado em apps mobile, validar certificados no lado cliente, e nunca transmitir segredos em URLs ou headers sem criptografia. Na prática: configure HTTPS em produção, force redirecionamento HTTP → HTTPS, e audite logs de requisições para detectar canais desprotegidos.

CVE-2026-19683MEDIUMUnencrypted Credential Transmission in Omada Gateway Dynamic DNS Authentication in Omada GatewaysEPSS 0.3%CVE-2026-91988CRITICALatomic-agents-stack before 1.1.0 Remote Code Execution via HTTP MCPEPSS 0.3%CVE-2026-31923HIGHApache APISIX: Openid-connect `tls_verify` field is disabled by defaultEPSS 0.3%CVE-2024-25650MEDIUMInsecure key exchange between Delinea PAM Secret Server 11.4 and the Distributed Engine 8.4.3 allows a PAM administrator to obtain the SymmeEPSS 0.3%CVE-2022-30312MEDIUMThe Trend Controls IC protocol through 2022-05-06 allows Cleartext Transmission of Sensitive Information. According to FSCT-2022-0050, thereEPSS 0.3%CVE-2023-34829MEDIUMIncorrect access control in TP-Link Tapo before v3.1.315 allows attackers to access user credentials in plaintext.EPSS 0.2%CVE-2024-43187MEDIUMIBM Security Verify Access information disclosureEPSS 0.2%CVE-2025-1060HIGHCWE-319: Cleartext Transmission of Sensitive Information vulnerability exists that could result in the exposure of data when network trafficEPSS 0.2%CVE-2024-37183MEDIUMWestermo L210-F2G Lynx Cleartext Transmission of Sensitive InformationEPSS 0.2%CVE-2026-24455HIGHJinan USR IOT Technology Limited (PUSR) USR-W610 Cleartext Transmission of Sensitive InformationEPSS 0.2%CVE-2024-49820LOWIBM Security Guardium Key Lifecycle Manager information disclosureEPSS 0.2%CVE-2023-34441MEDIUMBaker Hughes Bently Nevada 3500 System Cleartext Transmission of Sensitive InformationEPSS 0.2%CVE-2025-5087MEDIUMCleartext Transmission of Sensitive Information in Kaleris Navis N4EPSS 0.2%CVE-2026-45180HIGHCatalyst::Plugin::Statsd versions through 0.10.0 for Perl may leak session idsEPSS 0.2%CVE-2026-45432HIGHCleartext Transmission of Credentials Vulnerability in GX Earth ONT ModelsEPSS 0.2%CVE-2023-41088MEDIUMCleartext Transmission of Sensitive Information in DEXMA DEXGateEPSS 0.2%CVE-2024-26155MEDIUMETIC Telecom Remote Access Server (RAS) Cleartext Transmission of Sensitive InformationEPSS 0.2%CVE-2023-6094MEDIUMOnCell G3150A-LTE Series: Web Server Transmits Cleartext CredentialsEPSS 0.2%CVE-2026-69658CRITICALEbyte NA111-M Cleartext Transmission of Sensitive InformationEPSS 0.2%CVE-2026-31924MEDIUMApache APISIX: Plugin tencent-cloud-cls log export uses plaintext HTTPEPSS 0.2%