Weaknesses of type CWE-294

213 results

Exposição de informação sensível a usuário não autorizado

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves API) para alguém que não deveria ter acesso. Isso ocorre por falha de controle de acesso, logging inadequado, erro em configuração ou vazamento em comunicação desprotegida. O risco é direto: credenciais ou dados privados caem em mãos erradas.

Example

Um endpoint de API retorna o hash de senha do usuário na resposta JSON, ou um arquivo de configuração com credenciais de banco de dados fica acessível publicamente no repositório git, ou um log de erro exibe o token de autenticação completo na tela do usuário final.

How to mitigate

Implemente controle de acesso baseado em papéis (RBAC/ABAC); nunca exponha segredos em respostas HTTP, logs ou versionamento; use variáveis de ambiente para credenciais; valide e sanitize erros antes de retornar ao cliente; revise regularmente permissões de arquivos e endpoints.

CVE-2026-27855MEDIUMDovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and username is altered in paEPSS 0.3%CVE-2023-36857MEDIUMBaker Hughes Bently Nevada 3500 System Authentication Bypass by Capture-replayEPSS 0.3%CVE-2011-20002HIGHA vulnerability has been identified in SIMATIC S7-1200 CPU V1 family (incl. SIPLUS variants) (All versions < V2.0.2), SIMATIC S7-1200 CPU V2EPSS 0.3%CVE-2026-17045HIGHIBM i is Affected By Multiple Vulnerabilities in Digital Certificate ManagerEPSS 0.3%CVE-2024-52534MEDIUMDell ECS, version(s) prior to ECS 3.8.1.3, contain(s) an Authentication Bypass by Capture-replay vulnerability. A low privileged attacker wiEPSS 0.3%CVE-2025-40807MEDIUMA vulnerability has been identified in Gridscale X Prepay (All versions < V4.2.1). The affected application is vulnerable to capture-replay EPSS 0.3%CVE-2026-49319MEDIUMAlps Electric Co., Ltd. R53R0 Remote Keyless Entry System (RKES) Replay AttackEPSS 0.3%CVE-2026-56130LOWApache Shiro: Remember-me cookie isn't checked for expiry on the serverEPSS 0.3%CVE-2026-9095HIGHCVE-2026-9095EPSS 0.3%CVE-2024-22066HIGHThere is a privilege escalation vulnerability in ZTE ZXR10 ZSR V2 intelligent multi service router . An authenticated attacker could use theEPSS 0.3%CVE-2026-9398LOWBesen BS20 EV Charging Station BLE/WiFi authentication replayEPSS 0.3%CVE-2026-76214CRITICALphpMyFAQ before 4.1.7 WebAuthn Replay Attack via ChallengeEPSS 0.3%CVE-2026-4583LOWShenzhen HCC Technology MPOS M6 PLUS Bluetooth authentication replayEPSS 0.3%CVE-2023-31759HIGHWeak Security in the 433MHz keyfob of Kerui W18 Alarm System v1.0 allows attackers to gain full access via a code replay attack.EPSS 0.3%CVE-2023-31763HIGHWeak security in the transmitter of AGShome Smart Alarm v1.0 allows attackers to gain full access to the system via a code replay attack.EPSS 0.3%CVE-2025-56448MEDIUMThe Positron PX360BT SW REV 8 car alarm system is vulnerable to a replay attack due to a failure in implementing rolling code security. The EPSS 0.3%CVE-2023-31761HIGHWeak security in the transmitter of Blitzwolf BW-IS22 Smart Home Security Alarm v1.0 allows attackers to gain full access to the system via EPSS 0.3%CVE-2023-31762HIGHWeak security in the transmitter of Digoo DG-HAMB Smart Home Security System v1.0 allows attackers to gain full access to the system via a cEPSS 0.3%CVE-2024-43099HIGHAutomationDirect DirectLogic H2-DM1E Authentication Bypass by Capture-replayEPSS 0.3%CVE-2026-35618HIGHOpenClaw < 2026.3.23 - Replay Identity Drift via Query-Only Variants in Plivo V2 VerificationEPSS 0.3%