Falhas do tipo CWE-319

536 resultados

Transmissão de dados sensíveis em texto plano

A aplicação envia informações sensíveis (senhas, tokens, dados pessoais) sem criptografia em um canal de comunicação que pode ser interceptado. Um atacante na rede consegue capturar esses dados facilmente com ferramentas simples como packet sniffers, comprometendo a confidencialidade.

Exemplo

Uma API envia credenciais de usuário via HTTP simples em vez de HTTPS, ou um sistema transmite tokens de autenticação em requisições GET visíveis em logs de proxy. Um atacante na mesma rede Wi-Fi captura os pacotes e acessa as credenciais diretamente.

Como mitigar

Use HTTPS/TLS em todas as comunicações envolvendo dados sensíveis, implemente criptografia end-to-end quando necessário, e nunca transmita credenciais em parâmetros de URL. Valide certificados SSL/TLS do lado cliente e revise protocolos legados (FTP, Telnet) para alternativas seguras.

CVE-2026-23564MEDIUMTransmission of Unencrypted Data in Content Distribution ServiceEPSS 0.1%CVE-2026-79782CRITICALrclone before 1.74.4 Security Token Disclosure via HTTPS to HTTP RedirectEPSS 0.1%CVE-2026-38740MEDIUMFoscam VD1 Video Doorbell before V5.3.13_1072 is vulnerable to Cleartext Transmission of Sensitive Information. The device transmits sensitiEPSS 0.1%CVE-2025-10174HIGHImproper Access Control in Pan Software's PanCafe ProEPSS 0.1%CVE-2023-52951MEDIUMA cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703 allows man-in-the-middle atEPSS 0.1%CVE-2021-39077MEDIUMIBM Security Guardium information disclosureEPSS 0.1%CVE-2022-22457MEDIUMIBM Security Verify Governance, Identity Manager information disclosureEPSS 0.1%CVE-2022-41327HIGHA cleartext transmission of sensitive information vulnerability [CWE-319] in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0EPSS 0.1%CVE-2025-53703HIGHDuraComm DP-10iN-100-MU Cleartext Transmission of Sensitive InformationEPSS 0.1%CVE-2025-10540MEDIUMUnencrypted and Unauthenticated Communication Allows Data Exposure and Manipulation in iMonitor EAMEPSS 0.1%CVE-2023-45321HIGHThe Android Client application, when enrolled with the define method 1 (the user manually inserts the server ip address), use HTTP protocolEPSS 0.1%CVE-2025-66604LOWA vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The library version could be displayed on the webEPSS 0.1%CVE-2024-8013LOWCSFLE and Queryable Encryption self-lookup may fail to encrypt values in subpipelinesEPSS 0.1%CVE-2026-22080HIGHInsecure Transmission Vulnerability in Tenda Wireless RoutersEPSS 0.1%CVE-2026-22079HIGHCleartext Transmission Vulnerability in Tenda Wireless RoutersEPSS 0.1%CVE-2026-0714HIGHA physical attack vulnerability exists in certain Moxa industrial computers using TPM-backed LUKS full-disk encryption on Moxa Industrial LiEPSS 0.1%CVE-2026-40045MEDIUMOpenClaw < 2026.4.2 - Cleartext Credential Transmission via Unencrypted WebSocket Gateway EndpointsEPSS 0.1%CVE-2023-47745MEDIUMIBM MQ Container information disclosureEPSS 0.1%CVE-2026-25599MEDIUMMissing authentication and clear‑text data transmission affecting Orca heat pumpsEPSS 0.1%CVE-2024-25960HIGHDell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains a cleartext transmission of sensitive information vulnerability. A local lowEPSS 0.1%