Weaknesses of type CWE-319

539 results

Transmissão de dados sensíveis em texto plano

A aplicação envia informações críticas (senhas, tokens, dados pessoais) sem criptografia em canais de comunicação que podem ser interceptados. Um atacante na rede consegue capturar esses dados diretamente, comprometendo a confidencialidade da informação e permitindo roubo de credenciais ou dados sensíveis.

Example

Um app mobile envia login e senha via HTTP (não HTTPS), ou um sistema transmite números de cartão de crédito em requisições não criptografadas. Ferramentas simples como Wireshark permitem capturar esse tráfego em redes abertas ou mesmo corporativas.

How to mitigate

Sempre usar HTTPS/TLS para qualquer transmissão de dados sensíveis, implementar pinning de certificado em apps mobile, validar certificados no lado cliente, e nunca transmitir segredos em URLs ou headers sem criptografia. Na prática: configure HTTPS em produção, force redirecionamento HTTP → HTTPS, e audite logs de requisições para detectar canais desprotegidos.

CVE-2026-34126HIGHBluetooth Communication Uses Unencrypted Transmission During Initial Setup on TP-Link's Tapo L535E, P300 and D100CEPSS 0.1%CVE-2024-47124LOWCleartext Transmission of Sensitive Information in goTenna ProEPSS 0.1%CVE-2025-31972MEDIUMHCL BigFix Service Management (SM) is affected by a Sensitive Information Exposure vulnerabilityEPSS 0.1%CVE-2026-41281MEDIUMAndroid App "あんしんフィルター for au" provided by KDDI CORPORATION contains Cleartext Transmission of Sensitive Information (CWE-319) vulnerabilityEPSS 0.1%CVE-2025-24849HIGHDario Health USB-C Blood Glucose Monitoring System Starter Kit Android Application Cleartext Transmission of Sensitive InformationEPSS 0.1%CVE-2024-45838LOWgoTenna Pro ATAK Plugin Cleartext Transmission of Sensitive InformationEPSS 0.1%CVE-2025-59852LOWHCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerabilityEPSS 0.1%CVE-2026-32683MEDIUMSome EZVIZ products utilize older versions of cloud feature modules with legacy API interfaces, which pose a data transmission risk. AttackeEPSS 0.1%CVE-2025-31981MEDIUMHCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryptionEPSS 0.1%CVE-2026-6066HIGHUnencrypted Client‑Server Communication in ConnectWise Automate™ Solution CenterEPSS 0.1%CVE-2025-62311MEDIUMHCL AION is affected by a vulnerability where backend service details may be transmitted over insecure HTTP channels.EPSS 0.1%CVE-2025-52586HIGHEG4 Electronics EG4 Inverters Cleartext Transmission of Sensitive InformationEPSS 0.1%CVE-2026-84381HIGHHTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxiesEPSS 0.1%CVE-2026-85628HIGHCleartext Transmission of Sensitive Information in the Pairing Process vulnerabilityEPSS 0.1%CVE-2024-43766MEDIUMIn multiple functions of btm_ble_sec.cc, there is a possible unencrypted communication due to Invalid error handling. This could lead to remEPSS 0.1%CVE-2026-81330HIGHSoftish C6 Ear Camera and EarVision Android Application Cleartext transmission of sensitive informationEPSS 0.1%CVE-2026-19854MEDIUMCVE-2026-19854 CVE RecordEPSS 0.1%CVE-2025-62310MEDIUMHCL AION is affected by a vulnerability where encryption is not enforced for certain data transmissions or operationsEPSS 0.0%CVE-2026-96550MEDIUMsfturing hosp_order MailUtil.java getProperties cleartext transmissionEPSS —