Weaknesses of type CWE-319

538 results

Transmissão de dados sensíveis em texto plano

A aplicação envia informações críticas (senhas, tokens, dados pessoais) sem criptografia em canais de comunicação que podem ser interceptados. Um atacante na rede consegue capturar esses dados diretamente, comprometendo a confidencialidade da informação e permitindo roubo de credenciais ou dados sensíveis.

Example

Um app mobile envia login e senha via HTTP (não HTTPS), ou um sistema transmite números de cartão de crédito em requisições não criptografadas. Ferramentas simples como Wireshark permitem capturar esse tráfego em redes abertas ou mesmo corporativas.

How to mitigate

Sempre usar HTTPS/TLS para qualquer transmissão de dados sensíveis, implementar pinning de certificado em apps mobile, validar certificados no lado cliente, e nunca transmitir segredos em URLs ou headers sem criptografia. Na prática: configure HTTPS em produção, force redirecionamento HTTP → HTTPS, e audite logs de requisições para detectar canais desprotegidos.

CVE-2024-5631MEDIUMLongse NVR (Network Video Recorder) model NVR3608PGE2W, as well as products based on this device, are transmitting user's login and passwordEPSS 0.2%CVE-2025-36274HIGHIBM Aspera HTTP Gateway information disclosureEPSS 0.2%CVE-2024-0066MEDIUMJohan Fagerström, member of the AXIS OS Bug Bounty Program, has found that a O3C feature may expose sensitive traffic between the client (AxEPSS 0.2%CVE-2022-2338MEDIUMSofting Secure Integration Server Cleartext Transmission of Sensitive InformationEPSS 0.2%CVE-2025-11492CRITICALHTTP Configuration and Encryption in TransitEPSS 0.2%CVE-2026-32309HIGHCryptomator: Hub unlocking accepts plaintext HTTP and unvalidated endpoint schemesEPSS 0.2%CVE-2025-54156CRITICALSantesoft Sante PACS Server Cleartext Transmission of Sensitive InformationEPSS 0.2%CVE-2021-23896LOWCleartext Transmission of Sensitive Information in McAfee DBSecEPSS 0.2%CVE-2024-45101MEDIUMA privilege escalation vulnerability was discovered when Single Sign On (SSO) is enabled that could allow an attacker to intercept a valid, EPSS 0.2%CVE-2025-36421MEDIUMMultiple vulnerabilities in IBM ControllerEPSS 0.2%CVE-2025-12530MEDIUMVulnerabilities found in Watson Data IntelligenceEPSS 0.2%CVE-2025-36336MEDIUMCleartext Transmission of Sensitive Information in Watson Data IntelligenceEPSS 0.2%CVE-2024-47577LOWInformation Disclosure vulnerability in SAP Commerce CloudEPSS 0.2%CVE-2024-45102MEDIUMA privilege escalation vulnerability was discovered that could allow a valid, authenticated LXCA user to escalate their permissions for a coEPSS 0.2%CVE-2022-0005LOWSensitive information accessible by physical probing of JTAG interface for some Intel(R) Processors with SGX may allow an unprivileged user EPSS 0.2%CVE-2026-2671LOWMendi Neurofeedback Headset Bluetooth Low Energy cleartext transmissionEPSS 0.2%CVE-2026-24060CRITICALAutomated Logic WebCTRL Premium Server Cleartext Transmission of Sensitive InformationEPSS 0.2%CVE-2026-81691HIGHopenssl_encrypt before 1.4.9 Credential Leakage via Unvalidated Server URLsEPSS 0.2%CVE-2026-55857MEDIUMMariaDB Connector/J: Cleartext Transmission of Sensitive Information and Insufficiently Protected CredentialsEPSS 0.2%CVE-2024-35495MEDIUMAn Information Disclosure vulnerability in the Telemetry component in TP-Link Kasa KP125M V1.0.0 and Tapo P125M 1.0.0 Build 220930 Rel.14394EPSS 0.2%