Weaknesses of type CWE-201

411 results

Exposição de informações sensíveis em dados transmitidos

A aplicação envia informações sensíveis (senhas, tokens, dados pessoais, chaves) em comunicações que não deveriam conter essas informações. O desenvolvedor inclui acidentalmente ou por falha de lógica dados confidenciais em respostas, logs, cookies ou requisições que podem ser interceptadas ou expostas.

Example

Um sistema de e-commerce retorna a senha do usuário em uma resposta JSON após login, ou inclui o token de autenticação em um parâmetro GET visível na URL, permitindo que seja capturada em logs de servidor ou histórico do navegador.

How to mitigate

Revise todo dado enviado em respostas HTTP, cookies e headers para eliminar informações sensíveis; use variáveis de ambiente para credenciais, nunca as codifique; aplique sanitização antes de escrever em logs; utilize HTTPS obrigatoriamente e tokens seguros com ciclo de vida limitado.

CVE-2024-8429MEDIUMImproper Authentication in Digital Operation Services' WiFiBuradaEPSS 0.4%CVE-2026-66443HIGHWordPress REST API Log plugin <= 1.7.1 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2025-59010HIGHWordPress Permalink Manager Lite Plugin <= 2.5.1.3 - Sensitive Data Exposure VulnerabilityEPSS 0.4%CVE-2026-27406HIGHWordPress My Tickets plugin <= 2.1.0 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2025-30609MEDIUMWordPress AppExperts plugin <= 1.4.3 - Sensitive Data Exposure VulnerabilityEPSS 0.4%CVE-2026-42505MEDIUMInvoking Encrypted Client Hello privacy leak in crypto/tlsEPSS 0.4%CVE-2026-56460MEDIUMHCL DevOps Deploy / HCL Launch is susceptible to an Insertion of Sensitive Information Into Sent Data vulnerabilityEPSS 0.4%CVE-2024-6747MEDIUMInformation leak in mknotifydEPSS 0.4%CVE-2024-45653MEDIUMIBM Sterling Connect:Direct Web Services information disclosureEPSS 0.4%CVE-2026-12085MEDIUMIBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptable to an Insertion of Sensitive Information Into Sent Data vulnerabilityEPSS 0.4%CVE-2026-39480HIGHWordPress Backup Migration plugin <= 2.1.1 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2026-27372MEDIUMWordPress PeproDev Ultimate Invoice plugin <= 2.2.6 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2025-55715HIGHWordPress Otter - Gutenberg Block Plugin <= 3.1.0 - Sensitive Data Exposure VulnerabilityEPSS 0.4%CVE-2026-44970LOWdbt-mcp: All MCP Tool Arguments Including Raw SQL and --vars Credentials Transmitted to dbt Labs Telemetry by Default Without RedactionEPSS 0.4%CVE-2024-13276HIGHFile Entity (fieldable files) - Moderately critical - Information Disclosure - SA-CONTRIB-2024-040EPSS 0.4%CVE-2025-69132MEDIUMWordPress Corpkit theme <= 1.0.5 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2026-57347MEDIUMWordPress Hotel Booking Lite plugin <= 6.0.3 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2026-57318MEDIUMWordPress Site Reviews plugin <= 8.0.11 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2026-55553HIGHurllib: Cross-origin redirects preserve credential-bearing request headers, leading to potential credential leakageEPSS 0.4%CVE-2025-53987MEDIUMWordPress JetMenu <= 2.4.11.1 - Sensitive Data Exposure VulnerabilityEPSS 0.4%