Fallos del tipo CWE-798

945 resultados

Credenciais codificadas no código-fonte

Senhas, chaves de API ou tokens de autenticação gravados diretamente no código-fonte ou configurações do aplicativo. O atacante que acessa o repositório, binário ou arquivo de configuração obtém acesso imediato aos sistemas protegidos, sem precisar quebrá-los.

Ejemplo

Um desenvolvedor inclui a senha do banco de dados como string literal no código: `const dbPassword = 'admin123';` ou em um arquivo .env commitado no Git. Qualquer pessoa com acesso ao repositório (público ou com vazamento) tem a senha de produção.

Cómo mitigar

Use variáveis de ambiente, gerenciadores de secrets (como Vault, AWS Secrets Manager, Azure Key Vault) e nunca commite credenciais no versionamento. Implemente escaneamento automático de repositórios para detectar padrões de credenciais e revogue chaves encontradas imediatamente.

CVE-2026-63239MEDIUMHard-coded AWS IAM credentials vulnerabilityEPSS 0.2%CVE-2025-2394MEDIUMDisclosure of Alibaba (OSS) Keys In Ecovacs Home Android and iOS Mobile ApplicationsEPSS 0.2%CVE-2023-33304MEDIUMA use of hard-coded credentials vulnerability in Fortinet FortiClient Windows 7.0.0 - 7.0.9 and 7.2.0 - 7.2.1 allows an attacker to bypass sEPSS 0.2%CVE-2026-86555MEDIUMHardcoded Key Vulnerability in ZTE SmartLife APPEPSS 0.2%CVE-2025-53842MEDIUMUse of hard-coded credentials issue exists in ZWX-2000CSW2-HN prior to 0.3.19 and ZWX-2000CS2-HN firmware all versions. If this vulnerabilitEPSS 0.2%CVE-2023-41372HIGHThe vulnerability allows an unprivileged (untrusted) third- party application to arbitrary modify the server settings of the Android Client EPSS 0.2%CVE-2023-49221HIGHPrecor touchscreen console P62, P80, and P82 could allow a remote attacker (within the local network) to bypass security restrictions, and aEPSS 0.2%CVE-2023-40719MEDIUMA use of hard-coded credentials vulnerability in Fortinet FortiAnalyzer and FortiManager 7.0.0 - 7.0.8, 7.2.0 - 7.2.3 and 7.4.0 allows an atEPSS 0.2%CVE-2019-25722HIGHDräger SC Monitoring Devices Hard-coded Credentials and DoSEPSS 0.2%CVE-2025-23179MEDIUMRibbon Communications - CWE-798: Use of Hard-coded CredentialsEPSS 0.2%CVE-2025-63433MEDIUMXtooltech Xtool AnyScan Android Application 4.40.40 and prior uses a hardcoded cryptographic key and IV to decrypt update metadata. The key EPSS 0.2%CVE-2023-44296HIGH Dell ELab-Navigator, version 3.1.9 contains a hard-coded credential vulnerability. A local attacker could potentially exploit this vulnerabEPSS 0.2%CVE-2026-36616MEDIUMMercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 contains hardcoded WiFi driver credentials including a RADIUS shared secret, WPS teEPSS 0.2%CVE-2025-55263HIGHHCL Aftermarket DPC is affected by Hardcoded Sensitive DataEPSS 0.2%CVE-2025-26398MEDIUMSolarWinds Database Performance Analyzer Hard-coded Cryptographic Key VulnerabilityEPSS 0.2%CVE-2025-1143HIGHBillion Electric M120N - Use of Hard-coded CredentialsEPSS 0.2%CVE-2026-19412HIGHHardcoded Credentials Vulnerability in CP Plus CP-XR-DE21-S RouterEPSS 0.2%CVE-2024-50593HIGHHardcoded Service PasswordEPSS 0.2%CVE-2025-54465MEDIUMHard-coded Credentials Vulnerability in ZKTeco WL20EPSS 0.2%CVE-2026-20111MEDIUMCisco Prime Infrastructure Stored Cross-Site Scripting VulnerabilityEPSS 0.2%