Falhas do tipo CWE-522

691 resultados

Credenciais Insuficientemente Protegidas

Credenciais (senhas, tokens, chaves de API) armazenadas ou transmitidas sem proteção adequada, deixando-as expostas a interceptação ou acesso não autorizado. O código falha em aplicar criptografia, hash ou controles de acesso, tornando fácil para um atacante roubar ou ler essas informações sensíveis.

Exemplo

Uma aplicação web armazena senhas em banco de dados em texto plano, ou transmite tokens de autenticação via HTTP desprotegido. Um atacante que ganhe acesso ao banco ou intercepte a rede obtém acesso imediato a todas as contas.

Como mitigar

Hash de senhas com algoritmos fortes (bcrypt, Argon2); criptografe dados sensíveis em repouso; use HTTPS obrigatório para transmissão; implemente versionamento e rotação de credenciais; evite armazenar secrets em código-fonte ou variáveis de ambiente sem proteção; use gerenciadores de segredos (HashiCorp Vault, AWS Secrets Manager).

CVE-2024-46341HIGHTP-Link TL-WR845N(UN)_V4_190219 was discovered to transmit credentials in base64 encoded form, which can be easily decoded by an attacker exEPSS 0.2%CVE-2023-6259HIGHLocal Access to Sensitive Data in Brivo ACS100 and ACS300 EPSS 0.2%CVE-2025-53669MEDIUMJenkins VAddy Plugin 1.2.8 and earlier does not mask Vaddy API Auth Keys displayed on the job configuration form, increasing the potential fEPSS 0.2%CVE-2025-37728MEDIUMKibana Insufficiently Protected Credentials in the CrowdStrike ConnectorEPSS 0.2%CVE-2026-82255HIGHgitoxide 0.25.4 HTTP Credential Leak via RedirectEPSS 0.2%CVE-2026-71260MEDIUMESPHome web_server Plaintext Password Disclosure via JSON "value" FieldEPSS 0.2%CVE-2026-35467HIGHPrivate Key stored as extractable in browser IndexeDBEPSS 0.2%CVE-2026-11921CRITICALSecurity vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify AccessEPSS 0.2%CVE-2026-8862HIGHVulnerabilities exists in IBM Netezza SoftwareEPSS 0.2%CVE-2025-42897MEDIUMInformation Disclosure vulnerability in SAP Business One (SLD)EPSS 0.2%CVE-2022-38465CRITICALA vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP EPSS 0.2%CVE-2026-6345MEDIUMPrevent password disclosure and force reset during Slack importEPSS 0.2%CVE-2026-0715HIGHMoxa Arm-based industrial computers running Moxa Industrial Linux Secure use a device-unique bootloader password provided on the device. An EPSS 0.2%CVE-2020-10710—A flaw was found where the Plaintext Candlepin password is disclosed while updating Red Hat Satellite through the satellite-installer. This EPSS 0.2%CVE-2026-6446MEDIUMMy Social Feeds <= 1.0.4 - Missing Authorization to Unauthenticated Sensitive Information Exposure via 'ttp_get_accounts' AJAX ActionEPSS 0.2%CVE-2026-71577MEDIUMMulticluster-global-hub: multicluster-global-hub: spec-topic read acl leaks bootstrap kubeconfigs to all managed hubs during migrationEPSS 0.2%CVE-2016-15014LOWCESNET theme-cesnet resetpassword.php insufficiently protected credentialsEPSS 0.2%CVE-2021-34733MEDIUMCisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Information Disclosure VulnerabilityEPSS 0.2%CVE-2021-40503—An information disclosure vulnerability exists in SAP GUI for Windows - versions < 7.60 PL13, 7.70 PL4, which allows an attacker with sufficEPSS 0.2%CVE-2026-0289LOWPrisma Browser: Inappropriate Implementation in Account ProtectionEPSS 0.2%