Fallos del tipo CWE-311

312 resultados

Ausência de criptografia para dados sensíveis

A aplicação processa ou armazena dados sensíveis (senhas, tokens, dados financeiros, PII) sem aplicar criptografia. Isso expõe as informações a quem tiver acesso ao meio de transmissão ou armazenamento, permitindo roubo ou vazamento direto.

Ejemplo

Um servidor que salva tokens de autenticação em um arquivo de log em texto plano, ou uma API que trafega CPF e dados bancários via HTTP simples em vez de HTTPS. Um atacante monitora a rede ou acessa o servidor e recupera os dados.

Cómo mitigar

Sempre use HTTPS/TLS para transmissão de dados sensíveis, criptografe dados em repouso usando algoritmos reconhecidos (AES-256), e aplique criptografia end-to-end onde possível. Nunca deixe senhas ou tokens em logs ou cache sem proteção.

CVE-2025-45768HIGHpyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length is chosen by the applEPSS 0.2%CVE-2014-6274HIGHS3 and Glacier remotes creds embedded in the git repo were not encryptedEPSS 0.2%CVE-2025-32875MEDIUMAn issue was discovered in the COROS application through 3.8.12 for Android. Bluetooth pairing and bonding is neither initiated nor enforcedEPSS 0.2%CVE-2023-40251MEDIUMMissing Encryption of Sensitive Data vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian NAC Suite V5.0, GeniaEPSS 0.2%CVE-2026-32891CRITICALAnchorr Privilege Escalation: Jellyseerr User → Anchorr Admin via Stored XSSEPSS 0.2%CVE-2025-64145MEDIUMJenkins ByteGuard Build Actions Plugin 1.0 does not mask API tokens displayed on the job configuration form, increasing the potential for atEPSS 0.2%CVE-2025-64146MEDIUMJenkins Curseforge Publisher Plugin 1.0 stores API Keys unencrypted in job config.xml files on the Jenkins controller where they can be viewEPSS 0.2%CVE-2025-64144MEDIUMJenkins ByteGuard Build Actions Plugin 1.0 stores API tokens unencrypted in job config.xml files on the Jenkins controller where they can beEPSS 0.2%CVE-2023-38267MEDIUMIBM Security Access Manager Appliance information disclosureEPSS 0.1%CVE-2025-8763MEDIUMRuijie EG306MG strongSwan strongswan.conf missing encryptionEPSS 0.1%CVE-2026-55568MEDIUMGuzzle: Silent HTTPS-Proxy Downgrade to CleartextEPSS 0.1%CVE-2024-56439HIGHAccess control vulnerability in the identity authentication module Impact: Successful exploitation of this vulnerability may affect service EPSS 0.1%CVE-2023-50129MEDIUMMissing encryption in the NFC tags of the Flient Smart Door Lock v1.0 allows attackers to create a cloned tag via brief physical proximity tEPSS 0.1%CVE-2025-59410MEDIUMDragonfly tiny file download uses hard coded HTTP protocolEPSS 0.1%CVE-2025-13453MEDIUMA potential vulnerability was reported in some ThinkPlus USB drives that could allow a user with physical access to read data stored on the EPSS 0.1%CVE-2025-65825MEDIUMThe firmware on the basestation of the Meatmeet is not encrypted. An adversary with physical access to the Meatmeet device can disassemble tEPSS 0.1%CVE-2025-47274LOWToolHive stores secrets in the state store with no encryptionEPSS 0.1%CVE-2022-38194MEDIUMPortal for ArcGIS system properties are not properly encrypted (10.8.1 only)EPSS 0.1%CVE-2026-81681CRITICALopenssl_encrypt before 1.4.9 False Encryption via Cleartext StorageEPSS 0.1%CVE-2025-43274MEDIUMA privacy issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.6. A sandboxed process may be able toEPSS 0.1%