Fallos del tipo CWE-319

539 resultados

Transmissão de dados sensíveis em texto plano

A aplicação envia dados críticos (senhas, tokens, informações pessoais) sem criptografia em um canal de comunicação que pode ser interceptado. Um atacante na mesma rede ou posicionado no caminho do tráfego consegue ler esses dados diretamente, comprometendo confidencialidade.

Ejemplo

Um aplicativo mobile que envia credenciais de login via HTTP simples em vez de HTTPS, ou um sistema legado que transmite números de cartão de crédito em texto plano pela rede corporativa. Qualquer um fazendo sniffing de pacotes consegue capturar essas informações.

Cómo mitigar

Use HTTPS/TLS para toda comunicação que envolva dados sensíveis, implemente verificação de certificados válidos no cliente, e nunca transmita senhas ou tokens em parâmetros GET — prefira POST com corpo criptografado. Em APIs, aplique autenticação com tokens seguros e considere criptografia adicional end-to-end para dados ultra-críticos.

CVE-2025-52490HIGHAn issue was discovered in Couchbase Sync Gateway before 3.2.6. In sgcollect_info_options.log and sync_gateway.log, there are cleartext passEPSS 0.2%CVE-2025-59448MEDIUMComponents of the YoSmart YoLink ecosystem through 2025-10-02 leverage unencrypted MQTT to communicate over the internet. An attacker with tEPSS 0.2%CVE-2025-61738LOWJohnson Controls PowerG and IQPanel cleartext transmission of sensitive informationEPSS 0.2%CVE-2024-42181LOWHCL MyXalytics is affected by a cleartext transmission of sensitive information vulnerabilityEPSS 0.2%CVE-2026-87482MEDIUMCleartext transmission of sensitive data in HttpsUpgrades in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker to leaEPSS 0.2%CVE-2025-25046LOWIBM InfoSphere Information Server information disclosureEPSS 0.2%CVE-2024-32384MEDIUMKerlink gateways running KerOS prior to version 5.10 expose their web interface exclusively over HTTP, without HTTPS support. This lack of tEPSS 0.2%CVE-2026-41275HIGHFlowise: Password Reset Link Sent Over Unsecured HTTPEPSS 0.2%CVE-2026-48022MEDIUM@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirectsEPSS 0.2%CVE-2026-22274MEDIUMDell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Transmission of Sensitive IEPSS 0.2%CVE-2025-0250LOWHCL IEM is affected by an authorization token sent in cookie vulnerabilityEPSS 0.2%CVE-2025-64769HIGHAVEVA Process Optimization Cleartext Transmission of Sensitive InformationEPSS 0.2%CVE-2025-26654MEDIUMPotential information disclosure vulnerability in SAP Commerce Cloud (Public Cloud)EPSS 0.2%CVE-2026-22155MEDIUMA cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 throughEPSS 0.2%CVE-2025-59406MEDIUMThe Flock Safety Pisco com.flocksafety.android.pisco application 6.21.11 for Android (installed on Falcon and Sparrow License Plate Readers EPSS 0.2%CVE-2025-2311CRITICALAuthentication Bypass in Sechard Information Technologies' SecHardEPSS 0.2%CVE-2024-27166HIGHInsecure permissionsEPSS 0.2%CVE-2024-45361MEDIUMMi Connect Service APP protocol flaws lead to leaking sensitive user informationEPSS 0.2%CVE-2023-40544MEDIUMWestermo Lynx Cleartext Transmission of Sensitive InformationEPSS 0.2%CVE-2023-46889MEDIUMMeross MSH30Q 4.5.23 is vulnerable to Cleartext Transmission of Sensitive Information. During the device setup phase, the MSH30Q creates an EPSS 0.2%