Weaknesses of type CWE-201

411 results

Exposição de informações sensíveis em dados transmitidos

A aplicação envia informações sensíveis (senhas, tokens, dados pessoais, chaves) em comunicações que não deveriam conter essas informações. O desenvolvedor inclui acidentalmente ou por falha de lógica dados confidenciais em respostas, logs, cookies ou requisições que podem ser interceptadas ou expostas.

Example

Um sistema de e-commerce retorna a senha do usuário em uma resposta JSON após login, ou inclui o token de autenticação em um parâmetro GET visível na URL, permitindo que seja capturada em logs de servidor ou histórico do navegador.

How to mitigate

Revise todo dado enviado em respostas HTTP, cookies e headers para eliminar informações sensíveis; use variáveis de ambiente para credenciais, nunca as codifique; aplique sanitização antes de escrever em logs; utilize HTTPS obrigatoriamente e tokens seguros com ciclo de vida limitado.

CVE-2026-65812MEDIUMMicrosoft Teams for Android Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-82837MEDIUMInsertion of Sensitive Information Into Sent Data in GitLabEPSS 0.5%CVE-2025-66388MEDIUMApache Airflow: Secrets in rendered templates not redacted properly and exposed in the UIEPSS 0.5%CVE-2025-47775MEDIUMBullfrog's DNS over TCP bypasses domain filteringEPSS 0.5%CVE-2024-47569MEDIUMA insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 through 7.4.2, FortiMail 7.2.0 through 7.2.6, EPSS 0.5%CVE-2025-24858HIGHDevelocity (formerly Gradle Enterprise) before 2024.3.1 allows an attacker who has network access to a Develocity server to obtain the hasheEPSS 0.5%CVE-2025-32594HIGHWordPress Simple WP Events plugin <= 1.8.17 - Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2025-32635HIGHWordPress Hive Support plugin <= 1.2.6 - Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2025-24639MEDIUMWordPress Korea for WooCommerce plugin <= 1.1.11 - Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2026-54649LOWpunchin-email: Operator inbox (FORWARD_TO) disclosed to correspondents on reply — Cloudflare forward() drops the relay Reply-ToEPSS 0.5%CVE-2026-63481MEDIUMHurl: Cookies in Cookies section leak when redirecting to a different hostEPSS 0.5%CVE-2024-38372LOWUndici vulnerable to data leak when using response.arrayBuffer()EPSS 0.5%CVE-2020-14514MEDIUMTrailer Power Line Communications vulnerabilityEPSS 0.5%CVE-2026-1365MEDIUMInformation Disclosure in Sayax's OSOSEPSS 0.5%CVE-2024-5213MEDIUMExposure of Sensitive Information in mintplex-labs/anything-llmEPSS 0.5%CVE-2025-27244MEDIUMAssetView and AssetView CLOUD contain an issue with acquiring sensitive information from sent data to the developer. If exploited, sensitiveEPSS 0.5%CVE-2025-23774HIGHWordPress WPDB to Sql plugin <= 1.2 - Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2023-5831LOWInsertion of Sensitive Information Into Sent Data in GitLabEPSS 0.5%CVE-2025-64407MEDIUMApache OpenOffice: URL fetching can be used to exfiltrate arbitrary INI file values and environment variablesEPSS 0.5%CVE-2026-34226HIGHHappy DOM's fetch credentials include uses page-origin cookies instead of target-origin cookiesEPSS 0.5%