Weaknesses of type CWE-294

213 results

Exposição de informação sensível a usuário não autorizado

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves API) para alguém que não deveria ter acesso. Isso ocorre por falha de controle de acesso, logging inadequado, erro em configuração ou vazamento em comunicação desprotegida. O risco é direto: credenciais ou dados privados caem em mãos erradas.

Example

Um endpoint de API retorna o hash de senha do usuário na resposta JSON, ou um arquivo de configuração com credenciais de banco de dados fica acessível publicamente no repositório git, ou um log de erro exibe o token de autenticação completo na tela do usuário final.

How to mitigate

Implemente controle de acesso baseado em papéis (RBAC/ABAC); nunca exponha segredos em respostas HTTP, logs ou versionamento; use variáveis de ambiente para credenciais; valide e sanitize erros antes de retornar ao cliente; revise regularmente permissões de arquivos e endpoints.

CVE-2022-2226MEDIUMAn OpenPGP digital signature includes information about the date when the signature was created. When displaying an email that contains a diEPSS 0.4%CVE-2026-67581HIGHOn-chain transfer proof is not single-use in mpp EVM payment method, enabling cross-challenge replayEPSS 0.4%CVE-2025-65552CRITICALD3D Wi-Fi Home Security System ZX-G12 v2.1.1 is vulnerable to RF replay attacks on the 433 MHz sensor communication channel. The system doesEPSS 0.4%CVE-2026-90997HIGHKeycloak-services: keycloak: replay protection bypass leads to unauthorized access via database driver semantics mismatchEPSS 0.4%CVE-2026-68079CRITICALApache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization code replayEPSS 0.4%CVE-2026-46369HIGHNimiq: Validity store off by one errorEPSS 0.4%CVE-2026-44946CRITICALSAML Authentication Replay in RancherEPSS 0.4%CVE-2026-1743LOWDJI Mavic Mini/Air/Spark/Mini SE Enhanced Wi-Fi Pairing authentication replayEPSS 0.4%CVE-2022-48507Vulnerability of identity verification being bypassed in the storage module. Successful exploitation of this vulnerability may affect servicEPSS 0.4%CVE-2025-35061HIGHNewforma Info Exchange (NIX) forced NTLMv2 authentication via /NPCSRemoteWeb/LegacyIntegrationServices.asmxEPSS 0.4%CVE-2025-35058HIGHNewforma Info Exchange (NIX) forced NTLMv2 authentication via /UserWeb/Common/MarkupServices.ashxEPSS 0.4%CVE-2026-73311CRITICALXenForo < 2.3.13 OAuth2 Authorization Code ReuseEPSS 0.4%CVE-2022-25836HIGHBluetooth® Low Energy Pairing in Bluetooth Core Specification v4.0 through v5.3 may permit an unauthenticated MITM to acquire credentials wiEPSS 0.4%CVE-2022-25837HIGHBluetooth® Pairing in Bluetooth Core Specification v1.0B through v5.3 may permit an unauthenticated MITM to acquire credentials with two paiEPSS 0.4%CVE-2025-67135CRITICALWeak Security in the PF-50 1.2 keyfob of PGST PG107 Alarm System 1.25.05.hf allows attackers to compromise access control via a code replay EPSS 0.4%CVE-2025-69822HIGHAn issue in Atomberg Atomberg Erica Smart Fan Firmware Version: V1.0.36 allows an attacker to obtain sensitive information and escalate privEPSS 0.4%CVE-2026-84306MEDIUMFilament: Multi-factor authentication (app) codes can still be used after a newer code has been usedEPSS 0.4%CVE-2025-69197MEDIUMPterodactyl TOTPs can be reused during validity windowEPSS 0.4%CVE-2026-34209HIGHmppx: Tempo has a session close voucher bypass vulnerability due to settled amount equalityEPSS 0.4%CVE-2026-55088MEDIUMEtherpad: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author tokenEPSS 0.4%