Falhas do tipo CWE-319

539 resultados

Transmissão de dados sensíveis em texto plano

A aplicação envia informações sensíveis (senhas, tokens, dados pessoais) sem criptografia em um canal de comunicação que pode ser interceptado. Um atacante na rede consegue capturar esses dados facilmente com ferramentas simples como packet sniffers, comprometendo a confidencialidade.

Exemplo

Uma API envia credenciais de usuário via HTTP simples em vez de HTTPS, ou um sistema transmite tokens de autenticação em requisições GET visíveis em logs de proxy. Um atacante na mesma rede Wi-Fi captura os pacotes e acessa as credenciais diretamente.

Como mitigar

Use HTTPS/TLS em todas as comunicações envolvendo dados sensíveis, implemente criptografia end-to-end quando necessário, e nunca transmita credenciais em parâmetros de URL. Valide certificados SSL/TLS do lado cliente e revise protocolos legados (FTP, Telnet) para alternativas seguras.

CVE-2025-52490HIGHAn issue was discovered in Couchbase Sync Gateway before 3.2.6. In sgcollect_info_options.log and sync_gateway.log, there are cleartext passEPSS 0.2%CVE-2025-59448MEDIUMComponents of the YoSmart YoLink ecosystem through 2025-10-02 leverage unencrypted MQTT to communicate over the internet. An attacker with tEPSS 0.2%CVE-2025-61738LOWJohnson Controls PowerG and IQPanel cleartext transmission of sensitive informationEPSS 0.2%CVE-2024-42181LOWHCL MyXalytics is affected by a cleartext transmission of sensitive information vulnerabilityEPSS 0.2%CVE-2026-87482MEDIUMCleartext transmission of sensitive data in HttpsUpgrades in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker to leaEPSS 0.2%CVE-2025-25046LOWIBM InfoSphere Information Server information disclosureEPSS 0.2%CVE-2024-32384MEDIUMKerlink gateways running KerOS prior to version 5.10 expose their web interface exclusively over HTTP, without HTTPS support. This lack of tEPSS 0.2%CVE-2026-41275HIGHFlowise: Password Reset Link Sent Over Unsecured HTTPEPSS 0.2%CVE-2026-48022MEDIUM@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirectsEPSS 0.2%CVE-2026-22274MEDIUMDell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Transmission of Sensitive IEPSS 0.2%CVE-2025-0250LOWHCL IEM is affected by an authorization token sent in cookie vulnerabilityEPSS 0.2%CVE-2025-64769HIGHAVEVA Process Optimization Cleartext Transmission of Sensitive InformationEPSS 0.2%CVE-2025-26654MEDIUMPotential information disclosure vulnerability in SAP Commerce Cloud (Public Cloud)EPSS 0.2%CVE-2026-22155MEDIUMA cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 throughEPSS 0.2%CVE-2025-59406MEDIUMThe Flock Safety Pisco com.flocksafety.android.pisco application 6.21.11 for Android (installed on Falcon and Sparrow License Plate Readers EPSS 0.2%CVE-2024-27166HIGHInsecure permissionsEPSS 0.2%CVE-2025-2311CRITICALAuthentication Bypass in Sechard Information Technologies' SecHardEPSS 0.2%CVE-2024-37163MEDIUMSkyScrape Secure API RequestsEPSS 0.2%CVE-2023-40544MEDIUMWestermo Lynx Cleartext Transmission of Sensitive InformationEPSS 0.2%CVE-2023-46889MEDIUMMeross MSH30Q 4.5.23 is vulnerable to Cleartext Transmission of Sensitive Information. During the device setup phase, the MSH30Q creates an EPSS 0.2%