Weaknesses of type CWE-319

539 results

Transmissão de dados sensíveis em texto plano

A aplicação envia informações críticas (senhas, tokens, dados pessoais) sem criptografia em canais de comunicação que podem ser interceptados. Um atacante na rede consegue capturar esses dados diretamente, comprometendo a confidencialidade da informação e permitindo roubo de credenciais ou dados sensíveis.

Example

Um app mobile envia login e senha via HTTP (não HTTPS), ou um sistema transmite números de cartão de crédito em requisições não criptografadas. Ferramentas simples como Wireshark permitem capturar esse tráfego em redes abertas ou mesmo corporativas.

How to mitigate

Sempre usar HTTPS/TLS para qualquer transmissão de dados sensíveis, implementar pinning de certificado em apps mobile, validar certificados no lado cliente, e nunca transmitir segredos em URLs ou headers sem criptografia. Na prática: configure HTTPS em produção, force redirecionamento HTTP → HTTPS, e audite logs de requisições para detectar canais desprotegidos.

CVE-2026-25599MEDIUMMissing authentication and clear‑text data transmission affecting Orca heat pumpsEPSS 0.1%CVE-2024-25960HIGHDell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains a cleartext transmission of sensitive information vulnerability. A local lowEPSS 0.1%CVE-2025-2818MEDIUMA vulnerability was reported in version 1.0 of the Bluetooth Transmission Alliance protocol adopted by Motorola Smart Connect Android ApplicEPSS 0.1%CVE-2025-6180HIGHAuthentication HijackEPSS 0.1%CVE-2025-40583MEDIUMA vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge ClientEPSS 0.1%CVE-2026-79779MEDIUMrclone before v1.75.0 WebDAV Credential Exposure via HTTPS-to-HTTP RedirectEPSS 0.1%CVE-2023-42144MEDIUMCleartext Transmission during initial setup in Shelly TRV 20220811-15234 v.2.1.8 allows a local attacker to obtain the Wi-Fi password.EPSS 0.1%CVE-2023-23371MEDIUMQVPN Device ClientEPSS 0.1%CVE-2025-22493MEDIUMImproper cookie attributes in Foreseer Reporting Software (FRS)EPSS 0.1%CVE-2025-63292LOWFreebox v5 HD (firmware = 1.7.20), Freebox v5 Crystal (firmware = 1.7.20), Freebox v6 Révolution r1–r3 (firmware = 4.7.x), Freebox Mini 4K (EPSS 0.1%CVE-2026-33472MEDIUMCryptomator Hub OAuth token exchange HTTP downgrade via getAuthority() scheme confusion (CVE-2026-32303 bypass)EPSS 0.1%CVE-2026-79588MEDIUMU-speed WIFI4 N300 T1 Pro v1.0.0 is vulnerable to Cleartext transmission of administration credentials over HTTP.EPSS 0.1%CVE-2025-65855MEDIUMThe OTA firmware update mechanism in Netun Solutions HelpFlash IoT (firmware v18_178_221102_ASCII_PRO_1R5_50) uses hard-coded WiFi credentiaEPSS 0.1%CVE-2025-13454MEDIUMA potential vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to gain access to senEPSS 0.1%CVE-2026-9741HIGHClient side encryption fails to encrypt values in a $vectorSearchEPSS 0.1%CVE-2026-20801MEDIUMCleartext Transmission of Sensitive Information (CWE-319) in a component used in the Gallagher Hanwha VMS and Gallagher NxWitness VMS integrEPSS 0.1%CVE-2026-10584HIGHHTTPS Fallback to HTTP in Graph ExplorerEPSS 0.1%CVE-2025-53861LOWAap: sensitive cookie(s) set without security flagsEPSS 0.1%CVE-2026-34126HIGHBluetooth Communication Uses Unencrypted Transmission During Initial Setup on TP-Link's Tapo L535E, P300 and D100CEPSS 0.1%CVE-2024-47124LOWCleartext Transmission of Sensitive Information in goTenna ProEPSS 0.1%