Fallos del tipo CWE-522

690 resultados

Credenciais Insuficientemente Protegidas

É quando senhas, tokens ou chaves de acesso são armazenados ou transmitidos sem criptografia adequada, em texto plano ou com proteção fraca. O atacante que ganhar acesso ao código-fonte, banco de dados ou rede consegue ler as credenciais diretamente e entrar no sistema.

Ejemplo

Um desenvolvedor deixa a senha do banco de dados hardcoded em um arquivo .env versionado no Git, ou a API transmite tokens de autenticação por HTTP ao invés de HTTPS. Qualquer pessoa com acesso ao repositório ou monitorando a rede consegue roubar as credenciais.

Cómo mitigar

Use variáveis de ambiente ou gerenciadores de segredos (como HashiCorp Vault, AWS Secrets Manager); nunca versione credenciais. Sempre transmita sobre HTTPS, aplique hash com salt para senhas armazenadas, e implemente expiração e rotação de tokens e chaves.

CVE-2026-67425HIGHFlyto2 Core: LLM/API keys leak to an attacker-controlled base_urlEPSS 0.3%CVE-2025-23342HIGHThe NVIDIA NVDebug tool contains a vulnerability that may allow an actor to gain access to a privileged account . A successful exploit of thEPSS 0.3%CVE-2020-14391—A flaw was found in the GNOME Control Center in Red Hat Enterprise Linux 8 versions prior to 8.2, where it improperly uses Red Hat Customer EPSS 0.3%CVE-2020-1688MEDIUMJunos OS: SRX and NFX Series: Insufficient Web API private key protectionEPSS 0.3%CVE-2025-10880HIGHInsufficiently Protected Credentials in Dingtian DT-R002EPSS 0.3%CVE-2025-1886HIGHPass-Back vulnerability in Sage 200 SpainEPSS 0.3%CVE-2022-3474MEDIUMBazel leaks user credentials through the remote assets APIEPSS 0.3%CVE-2026-32913HIGHOpenClaw < 2026.3.7 - Custom Authorization Header Leakage via Cross-Origin RedirectsEPSS 0.3%CVE-2026-82288HIGHStable Diffusion WebUI Credential Disclosure via /sdapi/v1/cmd-flagsEPSS 0.3%CVE-2020-14334—A flaw was found in Red Hat Satellite 6 which allows privileged attacker to read cache files. These cache credentials could help attacker toEPSS 0.3%CVE-2026-50192MEDIUMKerberos Hub private key (X-Kerberos-Hub-PrivateKey) leaked to cross-host redirect target due to redirect-following HTTP client without CheckRedirectEPSS 0.3%CVE-2026-39908HIGHOpenBullet2 0.3.2 NTLMv2 Hash Disclosure via UNC Path Proxy SourceEPSS 0.3%CVE-2025-63361MEDIUMWaveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.002880.0301 was discovEPSS 0.3%CVE-2020-27781—User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. EPSS 0.3%CVE-2017-9552—A design flaw in authentication in Synology Photo Station 6.0-2528 through 6.7.1-3419 allows local users to obtain credentials via cmdline. EPSS 0.3%CVE-2026-17349CRITICALpgAdmin 4: Adhoc server clone leaks another user's stored database credentials and ownership to a non-ownerEPSS 0.3%CVE-2026-47660HIGHPathling: Explicit oauthMetadataUrl in bulk-submit allows OAuth client credential exfiltrationEPSS 0.3%CVE-2026-57485HIGHStirling-PDF: Internal Service Account API Key Disclosure via Pipeline EndpointEPSS 0.3%CVE-2020-28219—A CWE-522: Insufficiently Protected Credentials vulnerability exists in EcoStruxure Geo SCADA Expert 2019 (Original release and Monthly UpdaEPSS 0.3%CVE-2026-86600HIGHWorkload identity attestation generated before login host validation in Snowflake driversEPSS 0.3%