Weaknesses of type CWE-319

539 results

Transmissão de dados sensíveis em texto plano

A aplicação envia informações críticas (senhas, tokens, dados pessoais) sem criptografia em canais de comunicação que podem ser interceptados. Um atacante na rede consegue capturar esses dados diretamente, comprometendo a confidencialidade da informação e permitindo roubo de credenciais ou dados sensíveis.

Example

Um app mobile envia login e senha via HTTP (não HTTPS), ou um sistema transmite números de cartão de crédito em requisições não criptografadas. Ferramentas simples como Wireshark permitem capturar esse tráfego em redes abertas ou mesmo corporativas.

How to mitigate

Sempre usar HTTPS/TLS para qualquer transmissão de dados sensíveis, implementar pinning de certificado em apps mobile, validar certificados no lado cliente, e nunca transmitir segredos em URLs ou headers sem criptografia. Na prática: configure HTTPS em produção, force redirecionamento HTTP → HTTPS, e audite logs de requisições para detectar canais desprotegidos.

CVE-2026-71216MEDIUMApache SkyWalking: PagerDuty alarm hook transmits the integration routing key over cleartext HTTPEPSS 0.1%CVE-2024-35210MEDIUMA vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server is not enfEPSS 0.1%CVE-2026-55568MEDIUMGuzzle: Silent HTTPS-Proxy Downgrade to CleartextEPSS 0.1%CVE-2024-28169MEDIUMCleartext transmission of sensitive information for some BigDL software maintained by Intel(R) before version 2.5.0 may allow an authenticatEPSS 0.1%CVE-2026-21742MEDIUMA cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 throughEPSS 0.1%CVE-2025-54818HIGHCognex In-Sight Explorer and In-Sight Camera Firmware Cleartext Transmission of Sensitive InformationEPSS 0.1%CVE-2026-36610MEDIUMMercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 transmits DDNS credentials over plaintext HTTP with only Base64 encoding. The firmwEPSS 0.1%CVE-2026-73743LOWUnauthenticated Information Disclosure Leading to Data Exposure in HPE Networking Fabric ComposerEPSS 0.1%CVE-2025-0252LOWHCL IEM is affected by a password in cleartext vulnerabilityEPSS 0.1%CVE-2025-0432MEDIUMHMS Networks Ewon Flexy 202 Cleartext Transmission of Sensitive InformationEPSS 0.1%CVE-2026-73174HIGHNozomi Networks Labs identified a CWE-319: Cleartext Transmission of Sensitive Information vulnerability in the edgserver management protocoEPSS 0.1%CVE-2026-32838HIGHEdimax GS-5008PL <= 1.00.54 Transmits Credentials Over Cleartext HTTPEPSS 0.1%CVE-2023-30565LOW CQI Data Sniffing EPSS 0.1%CVE-2025-32793MEDIUMCilium packets from terminating endpoints may not be encrypted in Wireguard-enabled clustersEPSS 0.1%CVE-2025-43704MEDIUMArctera/Veritas Data Insight before 7.1.2 can send cleartext credentials when configured to use HTTP Basic Authentication to a Dell Isilon OEPSS 0.1%CVE-2025-47698HIGHAn adjacent attacker without authentication can exploit this vulnerability to retrieve a set of user-privileged credentials. These credentiaEPSS 0.1%CVE-2026-8874HIGHCVE-2026-8874EPSS 0.1%CVE-2021-20335MEDIUMSSL may be unexpectedly disabled during upgrade of multiple-server MongoDB Ops ManagerEPSS 0.1%CVE-2025-27903MEDIUMMultiple vulnerabilities in IBM Java SDK affecting Db2 Recovery Expert for Linux, Unix and WindowsEPSS 0.1%CVE-2024-9834CRITICALImproper data protection on Life2000 ventilator serial interfaceEPSS 0.1%