Weaknesses of type CWE-201

411 results

Exposição de informações sensíveis em dados transmitidos

A aplicação envia informações sensíveis (senhas, tokens, dados pessoais, chaves) em comunicações que não deveriam conter essas informações. O desenvolvedor inclui acidentalmente ou por falha de lógica dados confidenciais em respostas, logs, cookies ou requisições que podem ser interceptadas ou expostas.

Example

Um sistema de e-commerce retorna a senha do usuário em uma resposta JSON após login, ou inclui o token de autenticação em um parâmetro GET visível na URL, permitindo que seja capturada em logs de servidor ou histórico do navegador.

How to mitigate

Revise todo dado enviado em respostas HTTP, cookies e headers para eliminar informações sensíveis; use variáveis de ambiente para credenciais, nunca as codifique; aplique sanitização antes de escrever em logs; utilize HTTPS obrigatoriamente e tokens seguros com ciclo de vida limitado.

CVE-2020-37150HIGHEdimax Technology EW-7438RPn-v3 Mini 1.27 - Unauthorized Access: Wi-Fi Password DisclosureEPSS 0.7%CVE-2025-62126MEDIUMWordPress Varnish/Nginx Proxy Caching plugin <= 1.8.3 - Sensitive Data Exposure vulnerabilityEPSS 0.7%CVE-2023-48240CRITICALXWiki Platform sends cookies to external images in rendered diff and is vulnerable to server side request forgeryEPSS 0.7%CVE-2026-44487HIGHAxios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP AdapterEPSS 0.7%CVE-2025-59136MEDIUMWordPress Gerencianet Oficial plugin <= 3.1.3 - Sensitive Data Exposure vulnerabilityEPSS 0.7%CVE-2026-80255HIGHsecure cookie attribute bypass with tabEPSS 0.7%CVE-2026-44486HIGHAxios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connectionEPSS 0.7%CVE-2022-45428LOWSome Dahua software products have a vulnerability of sensitive information leakage. After obtaining the permissions of administrators, by seEPSS 0.7%CVE-2024-54309MEDIUMWordPress PostBox plugin <= 1.0.4 - Sensitive Data Exposure vulnerabilityEPSS 0.7%CVE-2026-8924CRITICALtrailing dot domain super cookieEPSS 0.7%CVE-2025-66035HIGHAngular HTTP Client Has XSRF Token Leakage via Protocol-Relative URLsEPSS 0.7%CVE-2023-28117HIGHSentry SDK leaks sensitive session information when `sendDefaultPII` is set to `True`EPSS 0.6%CVE-2025-48045HIGHMICI Network Co. Ltd. NetFax Server Default Administrator Credentials DisclosureEPSS 0.6%CVE-2024-50633NONEA Broken Object Level Authorization (BOLA) vulnerability in Indico through 3.3.5 allows attackers to read information by sending a crafted PEPSS 0.6%CVE-2023-3413MEDIUMInsertion of Sensitive Information Into Sent Data in GitLabEPSS 0.6%CVE-2026-32829HIGHlz4_flex: Decompression can leak information from uninitialized memory or reused output bufferEPSS 0.6%CVE-2025-23781HIGHWordPress WM Options Import Export plugin <= 1.0.1 - Sensitive Data Exposure vulnerabilityEPSS 0.6%CVE-2025-66566HIGHyawkat LZ4 Java has a possible information leak in Java safe decompressorEPSS 0.6%CVE-2023-3299LOWNomad Caller ACL Token's Secret ID is Exposed to SentinelEPSS 0.6%CVE-2023-3949MEDIUMInsertion of Sensitive Information Into Sent Data in GitLabEPSS 0.6%