Weaknesses of type CWE-319

539 results

Transmissão de dados sensíveis em texto plano

A aplicação envia informações críticas (senhas, tokens, dados pessoais) sem criptografia em canais de comunicação que podem ser interceptados. Um atacante na rede consegue capturar esses dados diretamente, comprometendo a confidencialidade da informação e permitindo roubo de credenciais ou dados sensíveis.

Example

Um app mobile envia login e senha via HTTP (não HTTPS), ou um sistema transmite números de cartão de crédito em requisições não criptografadas. Ferramentas simples como Wireshark permitem capturar esse tráfego em redes abertas ou mesmo corporativas.

How to mitigate

Sempre usar HTTPS/TLS para qualquer transmissão de dados sensíveis, implementar pinning de certificado em apps mobile, validar certificados no lado cliente, e nunca transmitir segredos em URLs ou headers sem criptografia. Na prática: configure HTTPS em produção, force redirecionamento HTTP → HTTPS, e audite logs de requisições para detectar canais desprotegidos.

CVE-2024-9620MEDIUMEvent-driven automation in ansible automation platform (aap): ansible event-driven automation (eda) lacks encryptionEPSS 0.2%CVE-2025-32884MEDIUMAn issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. By default, a GID is the user's phone number unless theyEPSS 0.2%CVE-2025-32881MEDIUMAn issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. By default, the GID is the user's phone number unless theyEPSS 0.2%CVE-2023-0864HIGHConfiguration data is exchanged in plaintext and could be available to a nearby attacker if present during configuration or usage of the device via Bluetooth Low Energy (BLE).EPSS 0.2%CVE-2025-62330MEDIUMHCL DevOps Deploy is susceptible to a cleartext transmission of sensitive informationEPSS 0.2%CVE-2026-18536HIGHData::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTPEPSS 0.2%CVE-2024-36558HIGHForever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h suffers from Cleartext Transmission of Sensitive InformatioEPSS 0.2%CVE-2024-28786MEDIUMIBM QRadar SIEM information disclosureEPSS 0.2%CVE-2023-43124MEDIUMBIG-IP APM Clients TunnelCrack vulnerabilityEPSS 0.2%CVE-2024-40595MEDIUMAn authentication-bypass issue in the RDP component of One Identity Safeguard for Privileged Sessions (SPS) On Premise before 7.5.1 (and LTSEPSS 0.2%CVE-2020-3442MEDIUMDuoConnect SSH Connection VulnerabilityEPSS 0.2%CVE-2026-77131MEDIUMCleartext Transmission of Sensitive Information in extension "SYSSY - TYPO3 Monitoring & Security Checks" (syssy)EPSS 0.2%CVE-2024-41927MEDIUMCleartext transmission of sensitive information vulnerability exists in multiple IDEC PLCs. If an attacker sends a specific command to PLC'sEPSS 0.2%CVE-2025-43013MEDIUMIn JetBrains Toolbox App before 2.6 unencrypted credential transmission during SSH authentication was possibleEPSS 0.2%CVE-2026-55860MEDIUMMariaDB Connector/R2DBC: Cleartext password disclosure to a man-in-the-middle server (clear-text auth plugins not gated on a secure transport)EPSS 0.2%CVE-2026-20115MEDIUMA vulnerability in Cisco IOS XE Software for Cisco Meraki could allow a remote, unauthenticated attacker to view confidential device informaEPSS 0.2%CVE-2024-0098MEDIUMCVEEPSS 0.2%CVE-2026-86689HIGHCleartext Transmission of Sensitive Information in Bransys ELDEPSS 0.1%CVE-2026-29988HIGHA cleartext transmission of sensitive information vulnerability in the NFC interface of multiple Milesight IoT device models running affecteEPSS 0.1%CVE-2026-7666LOWPotential unencrypted email transmission via STARTTLS in the SMTP backendEPSS 0.1%