CWE-319 敏感数据的明文传输 类弱点 369 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-319 指敏感信息在通信过程中以明文形式传输,易被网络嗅探。攻击者通常利用中间人攻击或公共 Wi-Fi 环境截获数据,窃取凭证或隐私。开发者应避免使用 HTTP 等未加密协议,强制实施 TLS/SSL 加密传输,并对关键数据进行端到端加密,确保即使数据被拦截也无法被解读,从而保障通信安全。
try { URL u = new URL("http://www.secret.example.org/"); HttpURLConnection hu = (HttpURLConnection) u.openConnection(); hu.setRequestMethod("PUT"); hu.connect(); OutputStream os = hu.getOutputStream(); hu.disconnect(); } catch (IOException e) { //... }| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2025-7743 | Dolusoft Omaspot 安全漏洞 — Omaspot | 9.6 | Critical | 2025-09-16 |
| CVE-2025-41708 | Bender多款产品 安全漏洞 — CC612 | 7.4 | High | 2025-09-08 |
| CVE-2025-7731 | Mitsubishi Electric MELSEC iQ-F Series CPU 安全漏洞 — MELSEC iQ-F Series FX5U-32MT/ES | 7.5 | High | 2025-09-01 |
| CVE-2025-31972 | HCL BigFix SM 安全漏洞 — BigFix Service Management (SM) | 6.5 | Medium | 2025-08-28 |
| CVE-2025-6180 | StrongDM Client 安全漏洞 — sdm-cli | 7.4AI | HighAI | 2025-08-20 |
| CVE-2025-57727 | JetBrains IntelliJ IDEA 安全漏洞 — IntelliJ IDEA | 4.7 | Medium | 2025-08-20 |
| CVE-2025-54156 | Santesoft Sante PACS Server 安全漏洞 — Sante PACS Server | 7.4 | High | 2025-08-18 |
| CVE-2025-8863 | YugabyteDB 安全漏洞 — YugabyteDB | 7.5 | - | 2025-08-11 |
| CVE-2025-8741 | mall 安全漏洞 — mall | 3.7 | Low | 2025-08-08 |
| CVE-2025-52586 | EG4 Electronics EG4 Inverters 安全漏洞 — EG4 12kPV | 6.9 | Medium | 2025-08-08 |
| CVE-2025-54799 | Lego 安全漏洞 — lego | 5.9AI | MediumAI | 2025-08-07 |
| CVE-2025-36020 | IBM Guardium Data Protection 安全漏洞 — Guardium Data Protection | 5.9 | Medium | 2025-08-06 |
| CVE-2025-8205 | Comodo Dragon 安全漏洞 — Dragon | 3.7 | Low | 2025-07-26 |
| CVE-2025-0252 | HCL IEM 安全漏洞 — IEM | 2.6 | Low | 2025-07-25 |
| CVE-2025-0250 | HCL Connections 安全漏洞 — IEM | 2.2 | Low | 2025-07-24 |
| CVE-2025-53703 | DuraComm SPM-500 DP-10iN-100-MU 安全漏洞 — SPM-500 DP-10iN-100-MU | 7.5 | High | 2025-07-22 |
| CVE-2025-36107 | IBM Cognos Analytics Mobile 安全漏洞 — Cognos Analytics Mobile | 5.9 | Medium | 2025-07-21 |
| CVE-2025-2818 | Motorola Smart Connect Android Application 安全漏洞 — Smart Connect Android Application | 3.5 | Low | 2025-07-17 |
| CVE-2025-53756 | Digisol DG-GR6821AC Router 安全漏洞 — XPON ONU Wi-Fi Router (DG-GR6821AC) | 9.8AI | CriticalAI | 2025-07-16 |
| CVE-2025-53861 | Red Hat Ansible 安全漏洞 — Red Hat Ansible Automation Platform 2 | 3.1 | Low | 2025-07-11 |
| CVE-2025-27457 | Endress+Hauser MEAC300-FNADE4 安全漏洞 — Endress+Hauser MEAC300-FNADE4 | 6.5 | Medium | 2025-07-03 |
| CVE-2025-36034 | IBM InfoSphere DataStage Flow Designer 安全漏洞 — InfoSphere Information Server | 5.3 | Medium | 2025-06-26 |
| CVE-2025-5087 | Kaleris NAVIS N4 安全漏洞 — Navis N4 | 9.1AI | CriticalAI | 2025-06-24 |
| CVE-2025-4378 | Ataturk University ATA-AOF Mobile Application 安全漏洞 — ATA-AOF Mobile Application | 10.0 | Critical | 2025-06-24 |
| CVE-2025-4227 | Palo Alto Networks GlobalProtect app 安全漏洞 — GlobalProtect App | 4.6AI | MediumAI | 2025-06-13 |
| CVE-2025-49194 | SICK Field Analytics和SICK Media Server安全漏洞 — SICK Media Server | 7.5 | High | 2025-06-12 |
| CVE-2025-49183 | SICK Field Analytics和SICK Media Server 安全漏洞 — SICK Media Server | 7.5 | High | 2025-06-12 |
| CVE-2025-0136 | Palo Alto Networks PAN-OS 安全漏洞 — Cloud NGFW | 7.5AI | HighAI | 2025-05-14 |
| CVE-2025-40583 | Siemens SCALANCE LPE9403 安全漏洞 — SCALANCE LPE9403 | 4.4 | Medium | 2025-05-13 |
| CVE-2025-27720 | Pixmeo OsiriX MD 安全漏洞 — OsiriX MD | 7.4 | High | 2025-05-08 |
CWE-319(敏感数据的明文传输) 是常见的弱点类别,本平台收录该类弱点关联的 369 条 CVE 漏洞。