Weaknesses of type CWE-310

91 results

Divulgação de informações sensíveis

É quando a aplicação expõe dados confidenciais (senhas, tokens, dados pessoais, chaves criptográficas) através de canais inseguros, logs, mensagens de erro ou respostas HTTP. O risco é que um atacante capture essas informações e as use para comprometer contas, roubar identidades ou acessar sistemas.

Example

Uma API retorna mensagens de erro que revelam a estrutura do banco de dados ('Usuário não encontrado na tabela users_v2'), ou uma página de login exibe a senha em um campo de texto visível em ferramentas de desenvolvedor, ou credenciais são registradas em logs com acesso público.

How to mitigate

Use HTTPS/TLS para todo tráfego sensível, nunca exponha detalhes técnicos em mensagens de erro (logs generalizados só para o usuário, detalhes internos apenas em logs do servidor), implemente sanitização de dados sensíveis antes de registrá-los, e revise regularmente quem tem acesso a logs e backups.

CVE-2026-2966MEDIUMCesanta Mongoose DNS Transaction ID dns.c mg_sendnsreq random valuesEPSS 0.4%CVE-2022-40675MEDIUMSome cryptographic issues in Fortinet FortiNAC versions 9.4.0 through 9.4.1, 9.2.0 through 9.2.7, 9.1.0 through 9.1.8, 8.8.0 through 8.8.11,EPSS 0.4%CVE-2021-4258LOWwhohas Package Information cleartext transmissionEPSS 0.4%CVE-2020-8173A too small set of random characters being used for encryption in Nextcloud Server 18.0.4 allowed decryption in shorter time than intended.EPSS 0.4%CVE-2025-8741MEDIUMmacrozheng mall login cleartext transmissionEPSS 0.4%CVE-2026-2618MEDIUMBeetel 777VR1 SSH Service risky encryptionEPSS 0.4%CVE-2025-3329LOWConsumer Comanda Mobile Restaurant Order cleartext transmissionEPSS 0.3%CVE-2025-9828MEDIUMTenda CP6 uhttp sub_2B7D04 risky encryptionEPSS 0.3%CVE-2026-7610MEDIUMTRENDnet TEW-821DAP Firmware Update ssi cleartext transmissionEPSS 0.3%CVE-2026-19896MEDIUMmangroup dtale Flask Session Cookie app.py build_secret_key random valuesEPSS 0.3%CVE-2022-45453MEDIUMTLS/SSL weak cipher suites enabled. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 30984.EPSS 0.3%CVE-2026-77151MEDIUMlin-snow Ech0 crypto.go MD5Encrypt risky encryptionEPSS 0.3%CVE-2020-8150A cryptographic issue in Nextcloud Server 19.0.1 allowed an attacker to downgrade the encryption scheme and break the integrity of encryptedEPSS 0.3%CVE-2022-23719HIGHPingID Windows Login prior to 2.8 does not authenticate communication with a local Java service used to capture security key requestsEPSS 0.3%CVE-2026-17616MEDIUMSecurity vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify AccessEPSS 0.3%CVE-2017-13094The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), including modification of the encryption key and insertion of hardware trojans in any IPEPSS 0.3%CVE-2017-20200MEDIUMCoinomi cleartext transmissionEPSS 0.3%CVE-2025-1953LOWvLLM AIBrix Prefix Caching hash.go random valuesEPSS 0.3%CVE-2025-4894MEDIUMcalmkart Django-sso-server crypto.py gen_rsa_keys inadequate encryptionEPSS 0.3%CVE-2018-0412A vulnerability in the implementation of Extensible Authentication Protocol over LAN (EAPOL) functionality in Cisco Small Business 100 SerieEPSS 0.3%