Weaknesses of type CWE-319

538 results

Transmissão de dados sensíveis em texto plano

A aplicação envia informações críticas (senhas, tokens, dados pessoais) sem criptografia em canais de comunicação que podem ser interceptados. Um atacante na rede consegue capturar esses dados diretamente, comprometendo a confidencialidade da informação e permitindo roubo de credenciais ou dados sensíveis.

Example

Um app mobile envia login e senha via HTTP (não HTTPS), ou um sistema transmite números de cartão de crédito em requisições não criptografadas. Ferramentas simples como Wireshark permitem capturar esse tráfego em redes abertas ou mesmo corporativas.

How to mitigate

Sempre usar HTTPS/TLS para qualquer transmissão de dados sensíveis, implementar pinning de certificado em apps mobile, validar certificados no lado cliente, e nunca transmitir segredos em URLs ou headers sem criptografia. Na prática: configure HTTPS em produção, force redirecionamento HTTP → HTTPS, e audite logs de requisições para detectar canais desprotegidos.

CVE-2023-35017MEDIUMIBM Security Verify Governance informationEPSS 0.2%CVE-2026-31924MEDIUMApache APISIX: Plugin tencent-cloud-cls log export uses plaintext HTTPEPSS 0.2%CVE-2023-43125MEDIUMBIG-IP APM Clients TunnelCrack vulnerabilityEPSS 0.2%CVE-2025-2861MEDIUMCleartext Transmission of Sensitive Information vulnerability in saTECH BCUEPSS 0.2%CVE-2025-52351HIGHAikaan IoT management platform v3.25.0325-5-g2e9c59796 sends a newly generated password to users in plaintext via email and also includes thEPSS 0.2%CVE-2026-69212MEDIUMHttp4s: FollowRedirect middleware leaks credentials over https->http same-authority redirectEPSS 0.2%CVE-2025-8863HIGHYugabyteDB diagnostic information was transmitted over HTTP, which could expose sensitive data during transmissionEPSS 0.2%CVE-2026-44726HIGHDeno: TLS retry copies stale upgrade hook, risking plaintext trafficEPSS 0.2%CVE-2025-23060MEDIUMSensitive Data Exposure Vulnerability in HPE Aruba Networking ClearPass Policy Manager (CPPM)EPSS 0.2%CVE-2024-13872CRITICALBitdefender Box Insecure Update Mechanism Vulnerability in libboxhermes.soEPSS 0.2%CVE-2025-64389HIGHEXCHANGE OF SENSITIVE INFORMATION IN CLEAR TEXTEPSS 0.2%CVE-2026-22544HIGHEXCHANGE OF CREDENTIALS IN CLEAR TEXTEPSS 0.2%CVE-2024-47269MEDIUMCleartext transmission of sensitive information vulnerability in Export Key functionality in Synology Surveillance Station before 9.2.2-1157EPSS 0.2%CVE-2023-4509MEDIUMIt is possible for an API key to be logged in clear text in the audit log file after an invalid login attempt.EPSS 0.2%CVE-2025-36107MEDIUMIBM Cognos Analytics Mobile (iOS) information disclosureEPSS 0.2%CVE-2024-6972MEDIUMIn affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the task log in cEPSS 0.2%CVE-2025-41708HIGHCleartext Transmission of Sensitive Data via Insecure HTTP Web InterfaceEPSS 0.2%CVE-2026-42514HIGHSensitive Data Exposure Vulnerability in e-Sushrut HMISEPSS 0.2%CVE-2025-54799LOWLego does not enforce HTTPSEPSS 0.2%CVE-2024-41262HIGHmmudb v1.9.3 was discovered to use the HTTP protocol in the ShowMetricsRaw and ShowMetricsAsText functions, possibly allowing attackers to iEPSS 0.2%