Weaknesses of type CWE-312

468 results

Divulgação de informações sensíveis

A aplicação expõe dados sensíveis (senhas, tokens, chaves, dados pessoais) através de mecanismos que não deveria — logs, mensagens de erro, respostas HTTP, cache ou armazenamento inseguro. O risco é que um atacante, desenvolvedor ou qualquer pessoa com acesso ao sistema consegue extrair informações que comprometerem segurança ou privacidade.

Example

Uma API retorna mensagem de erro com detalhes da query SQL executada, ou logs de produção armazenam senhas em texto plano, ou resposta HTTP carrega um token JWT sem flag HttpOnly — em todos os casos, dados que deveriam ser secretos ficam acessíveis a quem não deveria.

How to mitigate

Sanitize mensagens de erro (retorne genéricas ao cliente, detalhe apenas em logs privados); nunca registre senhas, tokens ou PII em logs; use flags seguras em cookies (HttpOnly, Secure, SameSite); implemente controle de acesso a logs e artifacts; criptografe dados em repouso e em trânsito; revise regularmente o que está sendo exposto em respostas HTTP e exceções.

CVE-2024-54127MEDIUMExposure of Wi-Fi Credentials in Plaintext in TP-Link Archer C50EPSS 0.2%CVE-2024-9991HIGHCleartext Storage of Sensitive Information Vulnerability in Philips Lighting DevicesEPSS 0.2%CVE-2020-10053—A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.12). The affected application writes sensitive data,EPSS 0.2%CVE-2025-12679HIGHPlain text pbe key visible in audit log during Brocade SANnav migration from 2.4.0a to 3.0.0EPSS 0.2%CVE-2024-12094MEDIUMInformation Disclosure Vulnerability in TinxyEPSS 0.2%CVE-2026-82699MEDIUMsambitraj Student Management System Password aca.sql cleartext storageEPSS 0.2%CVE-2025-50777HIGHThe firmware of the AZIOT 2MP Full HD Smart Wi-Fi CCTV Home Security Camera (version V1.00.02) contains an Incorrect Access Control vulnerabEPSS 0.2%CVE-2025-0418MEDIUMValmet DNA user passwords in plain textEPSS 0.2%CVE-2026-3221MEDIUMSensitive user account information is not encrypted in the database in Devolutions Server 2025.3.14 and earlier, which allows an attacker wEPSS 0.2%CVE-2024-56362HIGHNavidrome Stores JWT Secret in Plaintext in navidrome.dbEPSS 0.2%CVE-2024-56428MEDIUMThe local iLabClient database in itech iLabClient 3.7.1 allows local attackers to read cleartext credentials (from the CONFIGS table) for thEPSS 0.2%CVE-2026-38571MEDIUMCleartext storage and exposure of WPA2 credentials, and missing authentication on the rr/wr memory read/write commands, in the unauthenticatEPSS 0.2%CVE-2026-76383MEDIUMInformation Disclosure through Action Parameters in RSA SecurID Authentication Manager app for Splunk SOAREPSS 0.2%CVE-2026-65599MEDIUMn8n before 1.123.64, 2.29.8, and 2.30.1 Credential Exposure via JWT HeaderEPSS 0.2%CVE-2026-45040MEDIUMRustFS: Sensitive Information Leakage (SessionToken and SecretAccessKey) in RustFS Logs [Debug Mode]EPSS 0.2%CVE-2026-6598MEDIUMlangflow-ai langflow Project Creation Endpoint projects.py encrypt_auth_settings cleartext storage in fileEPSS 0.2%CVE-2024-41691HIGHInsecure Storage of Sensitive Information VulnerabilityEPSS 0.2%CVE-2024-41690HIGHDefault Credential Storage in Plaintext VulnerabilityEPSS 0.2%CVE-2026-33867CRITICALAVideo has Plaintext Video Password StorageEPSS 0.2%CVE-2023-29471MEDIUMLightbend Alpakka Kafka before 5.0.0 logs its configuration as debug information, and thus log files may contain credentials (if plain clearEPSS 0.2%