Fallos del tipo CWE-319

538 resultados

Transmissão de dados sensíveis em texto plano

A aplicação envia dados críticos (senhas, tokens, informações pessoais) sem criptografia em um canal de comunicação que pode ser interceptado. Um atacante na mesma rede ou posicionado no caminho do tráfego consegue ler esses dados diretamente, comprometendo confidencialidade.

Ejemplo

Um aplicativo mobile que envia credenciais de login via HTTP simples em vez de HTTPS, ou um sistema legado que transmite números de cartão de crédito em texto plano pela rede corporativa. Qualquer um fazendo sniffing de pacotes consegue capturar essas informações.

Cómo mitigar

Use HTTPS/TLS para toda comunicação que envolva dados sensíveis, implemente verificação de certificados válidos no cliente, e nunca transmita senhas ou tokens em parâmetros GET — prefira POST com corpo criptografado. Em APIs, aplique autenticação com tokens seguros e considere criptografia adicional end-to-end para dados ultra-críticos.

CVE-2025-42603HIGHInformation Disclosure Vulnerability in Meon KYC solutionsEPSS 0.3%CVE-2021-39081MEDIUMIBM Cognos Analytics Mobile information disclosureEPSS 0.3%CVE-2021-45447HIGH Pentaho Business Analytics Server - With the Data Lineage feature enabled, the system transmits database passwords in clear textEPSS 0.3%CVE-2024-28275MEDIUMPuwell Cloud Tech Co, Ltd 360Eyes Pro v3.9.5.16(3090516) was discovered to transmit sensitive information in cleartext. This vulnerability aEPSS 0.3%CVE-2025-62643LOWThe Restaurant Brands International (RBI) assistant platform through 2025-09-06 transmits passwords of user accounts in cleartext e-mail mesEPSS 0.3%CVE-2026-7610MEDIUMTRENDnet TEW-821DAP Firmware Update ssi cleartext transmissionEPSS 0.3%CVE-2023-50962MEDIUMIBM PowerSC information disclosureEPSS 0.3%CVE-2022-1524HIGH3.2.5 CLEARTEXT TRANSMISSION OF SENSITIVE INFORMATION CWE-319EPSS 0.3%CVE-2025-49194HIGHUnencrypted communicationEPSS 0.3%CVE-2025-10641HIGHUnencrypted cleartext communication in EfficientLab WorkExaminer ProfessionalEPSS 0.3%CVE-2025-4378CRITICALHardcoded Credentials in Ataturk University's ATA-AOF Mobile ApplicationEPSS 0.3%CVE-2020-36914HIGHQiHang Media Web Digital Signage 3.0.9 Cookie Authentication Credentials DisclosureEPSS 0.3%CVE-2020-36917HIGHiDS6 DSSPro Digital Signage System 6.2 Cleartext Password Disclosure via CookieEPSS 0.3%CVE-2024-41687HIGHCleartext Transmission of Sensitive Information VulnerabilityEPSS 0.3%CVE-2025-49183HIGHUnencrypted communication (HTTP)EPSS 0.3%CVE-2023-43503LOWA vulnerability has been identified in COMOS (All versions < V10.4.4). Caching system in the affected application leaks sensitive informatioEPSS 0.3%CVE-2025-62765HIGHGeneral Industrial Controls Lynx+ Gateway Cleartext Transmission of Sensitive InformationEPSS 0.3%CVE-2024-26288HIGHPHOENIX CONTACT: Lack of SSL support in CHARX SeriesEPSS 0.3%CVE-2025-0556HIGHTelerik Report Server Clear Text Transmission of Agent CommandsEPSS 0.3%CVE-2023-53881CRITICALReyeeOS 1.204.1614 Man-in-the-Middle Remote Code Execution via CWMPEPSS 0.3%