Weaknesses of type CWE-319

539 results

Transmissão de dados sensíveis em texto plano

A aplicação envia informações críticas (senhas, tokens, dados pessoais) sem criptografia em canais de comunicação que podem ser interceptados. Um atacante na rede consegue capturar esses dados diretamente, comprometendo a confidencialidade da informação e permitindo roubo de credenciais ou dados sensíveis.

Example

Um app mobile envia login e senha via HTTP (não HTTPS), ou um sistema transmite números de cartão de crédito em requisições não criptografadas. Ferramentas simples como Wireshark permitem capturar esse tráfego em redes abertas ou mesmo corporativas.

How to mitigate

Sempre usar HTTPS/TLS para qualquer transmissão de dados sensíveis, implementar pinning de certificado em apps mobile, validar certificados no lado cliente, e nunca transmitir segredos em URLs ou headers sem criptografia. Na prática: configure HTTPS em produção, force redirecionamento HTTP → HTTPS, e audite logs de requisições para detectar canais desprotegidos.

CVE-2025-52490HIGHAn issue was discovered in Couchbase Sync Gateway before 3.2.6. In sgcollect_info_options.log and sync_gateway.log, there are cleartext passEPSS 0.2%CVE-2025-59448MEDIUMComponents of the YoSmart YoLink ecosystem through 2025-10-02 leverage unencrypted MQTT to communicate over the internet. An attacker with tEPSS 0.2%CVE-2025-61738LOWJohnson Controls PowerG and IQPanel cleartext transmission of sensitive informationEPSS 0.2%CVE-2024-42181LOWHCL MyXalytics is affected by a cleartext transmission of sensitive information vulnerabilityEPSS 0.2%CVE-2026-87482MEDIUMCleartext transmission of sensitive data in HttpsUpgrades in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker to leaEPSS 0.2%CVE-2025-25046LOWIBM InfoSphere Information Server information disclosureEPSS 0.2%CVE-2024-32384MEDIUMKerlink gateways running KerOS prior to version 5.10 expose their web interface exclusively over HTTP, without HTTPS support. This lack of tEPSS 0.2%CVE-2026-41275HIGHFlowise: Password Reset Link Sent Over Unsecured HTTPEPSS 0.2%CVE-2026-48022MEDIUM@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirectsEPSS 0.2%CVE-2026-22274MEDIUMDell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Transmission of Sensitive IEPSS 0.2%CVE-2025-0250LOWHCL IEM is affected by an authorization token sent in cookie vulnerabilityEPSS 0.2%CVE-2025-64769HIGHAVEVA Process Optimization Cleartext Transmission of Sensitive InformationEPSS 0.2%CVE-2025-26654MEDIUMPotential information disclosure vulnerability in SAP Commerce Cloud (Public Cloud)EPSS 0.2%CVE-2026-22155MEDIUMA cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 throughEPSS 0.2%CVE-2025-59406MEDIUMThe Flock Safety Pisco com.flocksafety.android.pisco application 6.21.11 for Android (installed on Falcon and Sparrow License Plate Readers EPSS 0.2%CVE-2025-2311CRITICALAuthentication Bypass in Sechard Information Technologies' SecHardEPSS 0.2%CVE-2024-27166HIGHInsecure permissionsEPSS 0.2%CVE-2024-45361MEDIUMMi Connect Service APP protocol flaws lead to leaking sensitive user informationEPSS 0.2%CVE-2023-40544MEDIUMWestermo Lynx Cleartext Transmission of Sensitive InformationEPSS 0.2%CVE-2023-46889MEDIUMMeross MSH30Q 4.5.23 is vulnerable to Cleartext Transmission of Sensitive Information. During the device setup phase, the MSH30Q creates an EPSS 0.2%