Weaknesses of type CWE-319

539 results

Transmissão de dados sensíveis em texto plano

A aplicação envia informações críticas (senhas, tokens, dados pessoais) sem criptografia em canais de comunicação que podem ser interceptados. Um atacante na rede consegue capturar esses dados diretamente, comprometendo a confidencialidade da informação e permitindo roubo de credenciais ou dados sensíveis.

Example

Um app mobile envia login e senha via HTTP (não HTTPS), ou um sistema transmite números de cartão de crédito em requisições não criptografadas. Ferramentas simples como Wireshark permitem capturar esse tráfego em redes abertas ou mesmo corporativas.

How to mitigate

Sempre usar HTTPS/TLS para qualquer transmissão de dados sensíveis, implementar pinning de certificado em apps mobile, validar certificados no lado cliente, e nunca transmitir segredos em URLs ou headers sem criptografia. Na prática: configure HTTPS em produção, force redirecionamento HTTP → HTTPS, e audite logs de requisições para detectar canais desprotegidos.

CVE-2024-37163MEDIUMSkyScrape Secure API RequestsEPSS 0.2%CVE-2023-34972LOWQTS, QuTS hero and QuTScloudEPSS 0.2%CVE-2026-31278HIGHAn issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0.2 allows attackers EPSS 0.2%CVE-2026-73809HIGHEbyte NA111-M Cleartext Transmission of Sensitive InformationEPSS 0.2%CVE-2025-69272MEDIUMSpectrum password returned in clearEPSS 0.2%CVE-2025-4227LOWGlobalProtect App: Interception in Endpoint Traffic Policy EnforcementEPSS 0.2%CVE-2024-44105HIGHCleartext transmission of sensitive information in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allEPSS 0.2%CVE-2026-4584LOWShenzhen HCC Technology MPOS M6 PLUS Cardholder Data cleartext transmissionEPSS 0.2%CVE-2026-2539MEDIUMMicca KE700 Cleartext transmission of key fob IDEPSS 0.2%CVE-2026-22306CRITICALCritical flaw impacting OZOLS ERP's automatic update channelEPSS 0.2%CVE-2025-0136MEDIUMPAN-OS: Unencrypted Data Transfer when using AES-128-CCM on Intel-based hardware devicesEPSS 0.2%CVE-2025-7743CRITICALSensitive Data Exposure in Dolusoft's OmaspotEPSS 0.2%CVE-2024-49387MEDIUMCleartext transmission of sensitive information in acep-collector service. The following products are affected: Acronis Cyber Protect 16 (LiEPSS 0.2%CVE-2025-32887HIGHAn issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. A command channel includes the next hop. which can be inteEPSS 0.2%CVE-2026-84366HIGHScrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by defaultEPSS 0.2%CVE-2026-5115LOWSession hijacking in PaperCut NG/MF embedded application for Konica Minolta devicesEPSS 0.2%CVE-2026-12556HIGHHP Easy Start for macOS - Security UpdateEPSS 0.2%CVE-2025-36034MEDIUMIBM InfoSphere DataStage Flow Designer information disclosureEPSS 0.2%CVE-2025-15619LOWHCL Connections is vulnerable to broken access controlEPSS 0.2%CVE-2024-5462MEDIUMBrocade Fabric OS may capture SNMP Passwords in clear textEPSS 0.2%