Weaknesses of type CWE-319

538 results

Transmissão de dados sensíveis em texto plano

A aplicação envia informações críticas (senhas, tokens, dados pessoais) sem criptografia em canais de comunicação que podem ser interceptados. Um atacante na rede consegue capturar esses dados diretamente, comprometendo a confidencialidade da informação e permitindo roubo de credenciais ou dados sensíveis.

Example

Um app mobile envia login e senha via HTTP (não HTTPS), ou um sistema transmite números de cartão de crédito em requisições não criptografadas. Ferramentas simples como Wireshark permitem capturar esse tráfego em redes abertas ou mesmo corporativas.

How to mitigate

Sempre usar HTTPS/TLS para qualquer transmissão de dados sensíveis, implementar pinning de certificado em apps mobile, validar certificados no lado cliente, e nunca transmitir segredos em URLs ou headers sem criptografia. Na prática: configure HTTPS em produção, force redirecionamento HTTP → HTTPS, e audite logs de requisições para detectar canais desprotegidos.

CVE-2024-48121MEDIUMThe HI-SCAN 6040i Hitrax HX-03-19-I was discovered to transmit user credentials in cleartext over the GIOP protocol. This allows attackers tEPSS 0.2%CVE-2024-32864MEDIUMexacqVison - HTTPS Session EstablishmentEPSS 0.2%CVE-2026-24441HIGHTenda AC7 Transmits Admin Credentials Without HTTPS ProtectionEPSS 0.2%CVE-2026-45179MEDIUMPlack::Middleware::Statsd versions before 0.9.0 for Perl may leak user IP addressesEPSS 0.2%CVE-2026-22271HIGHDell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Transmission of Sensitive IEPSS 0.2%CVE-2025-11640LOWTomofun Furbo 360/Furbo Mini Bluetooth Low Energy cleartext transmissionEPSS 0.2%CVE-2026-76244CRITICALstigmem-node Insecure Federation Transport ConfigurationEPSS 0.2%CVE-2019-9532—The web application portal of the Cobham EXPLORER 710, firmware version 1.07, sends the login password in cleartextEPSS 0.2%CVE-2026-1014MEDIUMIBM InfoSphere Information Server is vulnerable due to disclosure of sensitive informationEPSS 0.2%CVE-2025-36020MEDIUMIBM Guardium Data Protection information disclosureEPSS 0.2%CVE-2021-23884MEDIUMClear text exposure of password in McAfee CSR ePO extensionEPSS 0.2%CVE-2025-25728MEDIUMBosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 were discovered to send communications to the updEPSS 0.2%CVE-2023-0001MEDIUMCortex XDR Agent: Cleartext Exposure of Agent Admin PasswordEPSS 0.2%CVE-2026-85719HIGHAsyncHttpClient: SOCKS proxy credentials sent to the origin server over plaintext HTTPEPSS 0.2%CVE-2026-53624MEDIUMFiber: HSTS header never set in helmet middleware due to incorrect protocol checkEPSS 0.2%CVE-2026-73756MEDIUMUnauthenticated Sensitive Information Disclosure via Man-in-the-Middle in AOS-CX via API EndpointEPSS 0.2%CVE-2022-42454MEDIUMHCL BigFix Insights for Vulnerability Remediation (IVR) is vulnerable to improper certificate validationEPSS 0.2%CVE-2022-47895MEDIUMIn JetBrains IntelliJ IDEA before 2022.3.1 the "Validate JSP File" action used the HTTP protocol to download required JAR files.EPSS 0.2%CVE-2026-50034HIGHApollo Pharmacy Blood Glucose Monitoring System APG-01 BT Cleartext Transmission of Sensitive InformationEPSS 0.2%CVE-2024-5631MEDIUMLongse NVR (Network Video Recorder) model NVR3608PGE2W, as well as products based on this device, are transmitting user's login and passwordEPSS 0.2%