Falhas do tipo CWE-522

690 resultados

Credenciais Insuficientemente Protegidas

Credenciais (senhas, tokens, chaves de API) armazenadas ou transmitidas sem proteção adequada, deixando-as expostas a interceptação ou acesso não autorizado. O código falha em aplicar criptografia, hash ou controles de acesso, tornando fácil para um atacante roubar ou ler essas informações sensíveis.

Exemplo

Uma aplicação web armazena senhas em banco de dados em texto plano, ou transmite tokens de autenticação via HTTP desprotegido. Um atacante que ganhe acesso ao banco ou intercepte a rede obtém acesso imediato a todas as contas.

Como mitigar

Hash de senhas com algoritmos fortes (bcrypt, Argon2); criptografe dados sensíveis em repouso; use HTTPS obrigatório para transmissão; implemente versionamento e rotação de credenciais; evite armazenar secrets em código-fonte ou variáveis de ambiente sem proteção; use gerenciadores de segredos (HashiCorp Vault, AWS Secrets Manager).

CVE-2026-67425HIGHFlyto2 Core: LLM/API keys leak to an attacker-controlled base_urlEPSS 0.3%CVE-2025-23342HIGHThe NVIDIA NVDebug tool contains a vulnerability that may allow an actor to gain access to a privileged account . A successful exploit of thEPSS 0.3%CVE-2020-14391—A flaw was found in the GNOME Control Center in Red Hat Enterprise Linux 8 versions prior to 8.2, where it improperly uses Red Hat Customer EPSS 0.3%CVE-2020-1688MEDIUMJunos OS: SRX and NFX Series: Insufficient Web API private key protectionEPSS 0.3%CVE-2025-10880HIGHInsufficiently Protected Credentials in Dingtian DT-R002EPSS 0.3%CVE-2025-1886HIGHPass-Back vulnerability in Sage 200 SpainEPSS 0.3%CVE-2022-3474MEDIUMBazel leaks user credentials through the remote assets APIEPSS 0.3%CVE-2026-32913HIGHOpenClaw < 2026.3.7 - Custom Authorization Header Leakage via Cross-Origin RedirectsEPSS 0.3%CVE-2026-82288HIGHStable Diffusion WebUI Credential Disclosure via /sdapi/v1/cmd-flagsEPSS 0.3%CVE-2020-14334—A flaw was found in Red Hat Satellite 6 which allows privileged attacker to read cache files. These cache credentials could help attacker toEPSS 0.3%CVE-2026-50192MEDIUMKerberos Hub private key (X-Kerberos-Hub-PrivateKey) leaked to cross-host redirect target due to redirect-following HTTP client without CheckRedirectEPSS 0.3%CVE-2026-39908HIGHOpenBullet2 0.3.2 NTLMv2 Hash Disclosure via UNC Path Proxy SourceEPSS 0.3%CVE-2025-63361MEDIUMWaveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.002880.0301 was discovEPSS 0.3%CVE-2020-27781—User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. EPSS 0.3%CVE-2017-9552—A design flaw in authentication in Synology Photo Station 6.0-2528 through 6.7.1-3419 allows local users to obtain credentials via cmdline. EPSS 0.3%CVE-2026-17349CRITICALpgAdmin 4: Adhoc server clone leaks another user's stored database credentials and ownership to a non-ownerEPSS 0.3%CVE-2026-47660HIGHPathling: Explicit oauthMetadataUrl in bulk-submit allows OAuth client credential exfiltrationEPSS 0.3%CVE-2026-57485HIGHStirling-PDF: Internal Service Account API Key Disclosure via Pipeline EndpointEPSS 0.3%CVE-2020-28219—A CWE-522: Insufficiently Protected Credentials vulnerability exists in EcoStruxure Geo SCADA Expert 2019 (Original release and Monthly UpdaEPSS 0.3%CVE-2026-86600HIGHWorkload identity attestation generated before login host validation in Snowflake driversEPSS 0.3%