Falhas do tipo CWE-522

689 resultados

Credenciais Insuficientemente Protegidas

Credenciais (senhas, tokens, chaves de API) armazenadas ou transmitidas sem proteção adequada, deixando-as expostas a interceptação ou acesso não autorizado. O código falha em aplicar criptografia, hash ou controles de acesso, tornando fácil para um atacante roubar ou ler essas informações sensíveis.

Exemplo

Uma aplicação web armazena senhas em banco de dados em texto plano, ou transmite tokens de autenticação via HTTP desprotegido. Um atacante que ganhe acesso ao banco ou intercepte a rede obtém acesso imediato a todas as contas.

Como mitigar

Hash de senhas com algoritmos fortes (bcrypt, Argon2); criptografe dados sensíveis em repouso; use HTTPS obrigatório para transmissão; implemente versionamento e rotação de credenciais; evite armazenar secrets em código-fonte ou variáveis de ambiente sem proteção; use gerenciadores de segredos (HashiCorp Vault, AWS Secrets Manager).

CVE-2026-59209HIGHn8n: Shared Credential Header Leak via HTTP Request Pagination ExpressionEPSS 0.4%CVE-2026-21670HIGHA vulnerability allowing a low-privileged user to extract saved SSH credentials.EPSS 0.4%CVE-2026-54618CRITICALObsidian Web MCP: Unauthenticated vault access: /oauth/authorize auto-approves without authenticating the userEPSS 0.4%CVE-2024-31800MEDIUMAuthentication Bypass in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to gain a privileged command shell EPSS 0.4%CVE-2023-50310MEDIUMIBM CICS Transaction Gateway for Multiplatforms information disclosureEPSS 0.4%CVE-2019-10224MEDIUMA flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may diEPSS 0.4%CVE-2026-62684LOWFile Browser: Share API exposes the password hash and bypass tokenEPSS 0.4%CVE-2026-39462CRITICALSenseLive X3050 Insufficiently Protected CredentialsEPSS 0.4%CVE-2024-49396HIGHInsufficiently Protected Credentials in Elvaco M-Bus Metering Gateway CMe3100EPSS 0.4%CVE-2025-15617HIGHWazuh GitHub Actions Workflow Exposure of Sensitive CredentialsEPSS 0.4%CVE-2019-10210MEDIUMPostgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via superuser writing password to unprotectedEPSS 0.4%CVE-2026-81861MEDIUMCWE-522: Insufficiently Protected Credentials vulnerability that could result in exposure of authentication information and unauthorized accEPSS 0.4%CVE-2023-49233HIGHInsufficient access checks in Visual Planning Admin Center 8 before v.1 Build 240207 allow attackers in possession of a non-administrative VEPSS 0.4%CVE-2026-61516CRITICALNetis NX10 Credential Disclosure via sysinfo Diagnostic EndpointEPSS 0.4%CVE-2025-0498HIGHRockwell Automation FactoryTalk® AssetCentre Data Exposure VulnerabilityEPSS 0.4%CVE-2019-10981In Vijeo Citect 7.30 and 7.40, and CitectSCADA 7.30 and 7.40, a vulnerability has been identified that may allow an authenticated local userEPSS 0.4%CVE-2024-12799CRITICALInsufficiently Protected CredentialsEPSS 0.4%CVE-2025-40838MEDIUMEricsson Indoor Connect 8855 - Insufficiently Protected Credentials VulnerabilityEPSS 0.4%CVE-2025-7386MEDIUMInformation exposure vulnerability in Hitachi Storage NavigatorEPSS 0.4%CVE-2024-34883MEDIUMInsufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allow remote administrators to read proxy-serveEPSS 0.4%