Weaknesses of type CWE-497

369 results

Divulgação de Informações Sensíveis

A aplicação expõe dados sensíveis (senhas, tokens, chaves criptográficas, dados pessoais) através de canais inseguros ou em contextos onde não deveria — logs, mensagens de erro, cache, memória ou tráfego de rede desencriptado. O risco é um atacante interceptar ou acessar esses dados e comprometer contas, sistemas ou privacidade.

Example

Uma API retorna a senha do usuário em texto plano dentro de um JSON de resposta de erro; um servidor expõe tokens de autenticação em arquivos de log acessíveis publicamente; uma página web carrega chaves de API dentro de variáveis JavaScript visíveis no código-fonte.

How to mitigate

Nunca exponha dados sensíveis em logs, mensagens de erro visíveis ao usuário ou código cliente. Criptografe dados em trânsito (HTTPS/TLS), use variáveis de ambiente ou vaults para armazenar credenciais, e revise regularmente o que é registrado ou retornado em respostas. Implemente redação de dados sensíveis (masking) em logs e erros.

CVE-2025-58585MEDIUMSensitive Information Disclosure Through Missing AuthenticationEPSS 0.4%CVE-2025-13651MEDIUMLEAK OF SENSITIVE INFORMATION ON MICROCOM'S ZEUSWEBEPSS 0.4%CVE-2026-59528HIGHWordPress ShipTime: Discounted Shipping Rates plugin <= 1.1.1 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2024-31419MEDIUMCnv: information disclosure through the usage of vm-dump-metricsEPSS 0.4%CVE-2026-24222HIGHNVIDIA NeMoClaw contains a vulnerability in the sandbox environment initialization component, where a remote attacker could cause improper aEPSS 0.4%CVE-2026-55726MEDIUMGardyn IoT Hub Exposure of Sensitive System Information to an Unauthorized Control SphereEPSS 0.4%CVE-2025-3606HIGHVestel AC Charger Exposure of Sensitive System Information to an Unauthorized Control SphereEPSS 0.4%CVE-2025-39589MEDIUMWordPress Essential Addons for Elementor plugin <= 6.1.9 - Sensitive Data Exposure VulnerabilityEPSS 0.4%CVE-2026-49068HIGHWordPress Coupon Affiliates plugin <= 7.8.1 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2025-4364HIGHExposure of Sensitive System Information to an Unauthorized Control SphereEPSS 0.4%CVE-2025-31045HIGHWordPress elfsight Contact Form widget plugin <= 2.3.1 - Sensitive Data Exposure VulnerabilityEPSS 0.4%CVE-2026-42047HIGHInngest TypeScript SDK exposes environment variables via serve() handler on unhandled HTTP methodsEPSS 0.4%CVE-2024-9470MEDIUMCortex XSOAR: Information Disclosure VulnerabilityEPSS 0.4%CVE-2025-58579MEDIUMUsername Disclosure Through Missing AuthenticationEPSS 0.4%CVE-2024-40706MEDIUMIBM InfoSphere Information Server information disclosureEPSS 0.4%CVE-2026-22915MEDIUMAn attacker with low privileges may be able to read files from specific directories on the device, potentially exposing sensitive informatioEPSS 0.4%CVE-2026-50294MEDIUMWindows Kernel Information Disclosure VulnerabilityEPSS 0.4%CVE-2024-39740MEDIUMIBM Datacap Navigator information disclosureEPSS 0.4%CVE-2025-26758MEDIUMWordPress Spotlight Social Feeds plugin <= 1.7.1 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2025-47540MEDIUMWordPress weMail plugin <= 1.14.13 - Sensitive Data Exposure VulnerabilityEPSS 0.4%