Falhas do tipo CWE-522

689 resultados

Credenciais Insuficientemente Protegidas

Credenciais (senhas, tokens, chaves de API) armazenadas ou transmitidas sem proteção adequada, deixando-as expostas a interceptação ou acesso não autorizado. O código falha em aplicar criptografia, hash ou controles de acesso, tornando fácil para um atacante roubar ou ler essas informações sensíveis.

Exemplo

Uma aplicação web armazena senhas em banco de dados em texto plano, ou transmite tokens de autenticação via HTTP desprotegido. Um atacante que ganhe acesso ao banco ou intercepte a rede obtém acesso imediato a todas as contas.

Como mitigar

Hash de senhas com algoritmos fortes (bcrypt, Argon2); criptografe dados sensíveis em repouso; use HTTPS obrigatório para transmissão; implemente versionamento e rotação de credenciais; evite armazenar secrets em código-fonte ou variáveis de ambiente sem proteção; use gerenciadores de segredos (HashiCorp Vault, AWS Secrets Manager).

CVE-2024-36127HIGHapko Exposure of HTTP basic auth credentials in log outputEPSS 0.4%CVE-2026-62214MEDIUMOpenClaw < 2026.5.28 Bot Framework SSRF via serviceUrl Parameter ValidationEPSS 0.4%CVE-2026-32171HIGHAzure Logic Apps Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2020-28390A vulnerability has been identified in Opcenter Execution Core (V8.2), Opcenter Execution Core (V8.3). The application contains an informatiEPSS 0.4%CVE-2026-42869CRITICALSOCFortress CoPilot: Hardcoded JWT secret allows unauthenticated full admin compromise and lateral movement into all integrated SOC toolsEPSS 0.4%CVE-2022-45157HIGHExposure of vSphere's CPI and CSI credentials in RancherEPSS 0.4%CVE-2025-64898MEDIUMColdFusion | Insufficiently Protected Credentials (CWE-522)EPSS 0.4%CVE-2026-50017MEDIUMpnpm binds unscoped user-level npm auth credentials to a repository-selected registryEPSS 0.4%CVE-2025-58130CRITICALApache Fineract: Server Key not maskedEPSS 0.4%CVE-2024-51545CRITICALUsername EnumerationEPSS 0.4%CVE-2026-53632MEDIUMNTLMv2 hash disclosure via UNC path handling on WindowsEPSS 0.4%CVE-2024-34885MEDIUMInsufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to read SMTP accoEPSS 0.4%CVE-2026-44622MEDIUMEVoke Systems EVoke CSMS Insufficiently Protected CredentialsEPSS 0.4%CVE-2017-16718Beckhoff TwinCAT 3 supports communication over ADS. ADS is a protocol for industrial automation in protected environments. This protocol useEPSS 0.4%CVE-2026-55215HIGHMariaDB Connector/Node.js: Connector leaks the cleartext password to an MitM despite `ssl: true`EPSS 0.4%CVE-2026-1223MEDIUMBROWAN COMMUNICATIONS |PrismX MX100 AP controller - Insufficiently Protected CredentialsEPSS 0.4%CVE-2024-50699HIGHTP-Link TL-WR845N(UN)_V4_201214, TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 were discovered to contain weak default credentials forEPSS 0.4%CVE-2026-44979MEDIUM@hapi/wreck : Sensitive `Proxy-Authorization` header leaked across cross-hostname redirectsEPSS 0.4%CVE-2025-0619MEDIUMUnsafe stored password recoveryEPSS 0.4%CVE-2026-33182MEDIUMSaloon is vulnerable to SSRF and credential leakage via absolute URL in endpoint overriding base URLEPSS 0.4%