Weaknesses of type CWE-201

411 results

Exposição de informações sensíveis em dados transmitidos

A aplicação envia informações sensíveis (senhas, tokens, dados pessoais, chaves) em comunicações que não deveriam conter essas informações. O desenvolvedor inclui acidentalmente ou por falha de lógica dados confidenciais em respostas, logs, cookies ou requisições que podem ser interceptadas ou expostas.

Example

Um sistema de e-commerce retorna a senha do usuário em uma resposta JSON após login, ou inclui o token de autenticação em um parâmetro GET visível na URL, permitindo que seja capturada em logs de servidor ou histórico do navegador.

How to mitigate

Revise todo dado enviado em respostas HTTP, cookies e headers para eliminar informações sensíveis; use variáveis de ambiente para credenciais, nunca as codifique; aplique sanitização antes de escrever em logs; utilize HTTPS obrigatoriamente e tokens seguros com ciclo de vida limitado.

CVE-2026-54841HIGHWordPress Vitepos plugin <= 3.4.2 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2026-7488HIGHSensitive Data Exposure in IKAS Technologies' E-CommerceEPSS 0.4%CVE-2025-68006MEDIUMWordPress Booking Ultra Pro plugin <= 1.1.23 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2026-78336HIGHApache Syncope: OIDCC4UI provider list discloses client secrets to any authenticated userEPSS 0.4%CVE-2024-4536MEDIUMEclipse EDC: OAuth2 Credential Exfiltration VulnerabilityEPSS 0.4%CVE-2025-66304MEDIUMGrav Exposes Password Hashes Leading to privilege escalationEPSS 0.4%CVE-2024-3502CRITICALExposure of Sensitive Information in lunary-ai/lunaryEPSS 0.4%CVE-2025-41118CRITICALSensitive COS `SecretKey` exposed in plaintext via configuration API due to missing type protectionEPSS 0.4%CVE-2024-7698MEDIUMPhoenix Contact: Access to CSRF tokens of higher privileged users in MGUARD productsEPSS 0.4%CVE-2026-4525HIGHVault Token Leaked to Backends via Authorization: Bearer Passthrough HeaderEPSS 0.4%CVE-2025-59268MEDIUMBIG-IP Configuration utility vulnerabilityEPSS 0.4%CVE-2025-3529HIGHWordPress Simple PayPal Shopping Cart <= 5.1.2 - Unauthenticated Information Exposure via file_url ParameterEPSS 0.4%CVE-2025-24567MEDIUMWordPress WP Mailster plugin <= 1.8.16.0 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2024-8890HIGHInsertion of Sensitive Information Into Sent Data vulnerability on CIRCUTOR Q-SMTEPSS 0.4%CVE-2025-63019MEDIUMWordPress Cookies and Content Security Policy plugin <= 2.34 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2026-65543HIGHWordPress Vimeo plugin <= 1.2.2 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2026-16637MEDIUMOPeNDAP Hyrax SSRF and Credential Disclosure via Unvalidated RedirectsEPSS 0.4%CVE-2026-27868MEDIUMPUBLICATION OF SENSITIVE INFORMATION ON REGESTA SMART HD-PLC OF TELDATEPSS 0.4%CVE-2023-32275MEDIUMAn information disclosure vulnerability exists in the CtEnumCa() functionality of SoftEther VPN 4.41-9782-beta and 5.01.9674. Specially crafEPSS 0.4%CVE-2025-59579HIGHWordPress Simple Job Board plugin <= 2.13.7 - Sensitive Data Exposure vulnerabilityEPSS 0.4%