Weaknesses of type CWE-497

369 results

Divulgação de Informações Sensíveis

A aplicação expõe dados sensíveis (senhas, tokens, chaves criptográficas, dados pessoais) através de canais inseguros ou em contextos onde não deveria — logs, mensagens de erro, cache, memória ou tráfego de rede desencriptado. O risco é um atacante interceptar ou acessar esses dados e comprometer contas, sistemas ou privacidade.

Example

Uma API retorna a senha do usuário em texto plano dentro de um JSON de resposta de erro; um servidor expõe tokens de autenticação em arquivos de log acessíveis publicamente; uma página web carrega chaves de API dentro de variáveis JavaScript visíveis no código-fonte.

How to mitigate

Nunca exponha dados sensíveis em logs, mensagens de erro visíveis ao usuário ou código cliente. Criptografe dados em trânsito (HTTPS/TLS), use variáveis de ambiente ou vaults para armazenar credenciais, e revise regularmente o que é registrado ou retornado em respostas. Implemente redação de dados sensíveis (masking) em logs e erros.

CVE-2022-4985HIGHVodafone H500s WiFi Password Disclosure via activation.jsonEPSS 0.4%CVE-2025-10264CRITICALDigiever|NVR - Exposure of Sensitive InformationEPSS 0.4%CVE-2023-32550CRITICALLandscape's Apache server-status is accessible by defaultEPSS 0.4%CVE-2024-53814MEDIUMWordPress Analytify plugin <= 5.4.3 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2024-50528HIGHWordPress Stacks Mobile App Builder plugin <= 5.2.3 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2024-6389MEDIUMExposure of Sensitive System Information to an Unauthorized Control Sphere in GitLabEPSS 0.4%CVE-2025-4229MEDIUMPAN-OS: Traffic Information Disclosure VulnerabilityEPSS 0.4%CVE-2023-34209MEDIUMExposure of Sensitive System Information to an Unauthorized Control Sphere in EasyUse MailHunter UltimateEPSS 0.4%CVE-2024-50425MEDIUMWordPress WP Booking System – Booking Calendar plugin <= 2.0.19.10 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2024-53867MEDIUMSynapse Matrix has a partial room state leak via Sliding SyncEPSS 0.4%CVE-2024-36554CRITICALForever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me KW-60 R36CW_YDE_S4_A29_2_V1.0EPSS 0.4%CVE-2024-48024HIGHWordPress Keep Backup Daily plugin <= 2.1.3 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2025-9110LOWQTS, QuTS heroEPSS 0.4%CVE-2025-5893CRITICALHonding Technology Smart Parking Management System - Exposure of Sensitive InformationEPSS 0.4%CVE-2026-41928MEDIUMVvveb < 1.0.8.2 Information Disclosure via Cron ControllerEPSS 0.4%CVE-2024-52033MEDIUMExposure of sensitive system information to an unauthorized control sphere issue exists in Rakuten Turbo 5G firmware version V1.3.18 and earEPSS 0.4%CVE-2023-37487MEDIUMSecurity misconfiguration vulnerability in SAP Business One (Service Layer)EPSS 0.4%CVE-2024-8687MEDIUMPAN-OS: Cleartext Exposure of GlobalProtect Portal PasscodesEPSS 0.4%CVE-2024-53768MEDIUMWordPress Content Audit Exporter plugin <= 1.1 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2025-54459HIGHVertikal Systems Hospital Manager Backend Services Exposure of Sensitive System Information to an Unauthorized Control SphereEPSS 0.4%