Weaknesses of type CWE-312

470 results

Divulgação de informações sensíveis

A aplicação expõe dados sensíveis (senhas, tokens, chaves, dados pessoais) através de mecanismos que não deveria — logs, mensagens de erro, respostas HTTP, cache ou armazenamento inseguro. O risco é que um atacante, desenvolvedor ou qualquer pessoa com acesso ao sistema consegue extrair informações que comprometerem segurança ou privacidade.

Example

Uma API retorna mensagem de erro com detalhes da query SQL executada, ou logs de produção armazenam senhas em texto plano, ou resposta HTTP carrega um token JWT sem flag HttpOnly — em todos os casos, dados que deveriam ser secretos ficam acessíveis a quem não deveria.

How to mitigate

Sanitize mensagens de erro (retorne genéricas ao cliente, detalhe apenas em logs privados); nunca registre senhas, tokens ou PII em logs; use flags seguras em cookies (HttpOnly, Secure, SameSite); implemente controle de acesso a logs e artifacts; criptografe dados em repouso e em trânsito; revise regularmente o que está sendo exposto em respostas HTTP e exceções.

CVE-2026-86443MEDIUMCleartext Storage of Sensitive Information VulnerabilityEPSS 0.1%CVE-2026-93764HIGHPlaintext storage of encrypted fields via skipped embedded models in encryption schema generationEPSS 0.1%CVE-2025-54855MEDIUMAutomationDirect CLICK PLUS Cleartext Storage of Sensitive InformationEPSS 0.1%CVE-2026-75847MEDIUMSensitive attribute values stored in a non-sensitive public changes map in AshPaperTrailEPSS 0.1%CVE-2024-9432MEDIUMCleartext Storage of Sensitive Information vulnerability has been discovered in OpenText™ Vertica.EPSS 0.1%CVE-2026-77970MEDIUMSensitive fields nested in embedded values are not redacted in AshPaperTrail versionsEPSS 0.1%CVE-2025-7215LOWFNKvision FNK-GU2 wpa_supplicant.conf cleartext storageEPSS 0.1%CVE-2025-48428MEDIUMCleartext Storage of Sensitive Information (CWE-312) in the Gallagher Morpho integration could allow an authenticated user with access to thEPSS 0.1%CVE-2025-3395HIGHIncorrect Permission Assignment for Critical Resource, Cleartext Storage of Sensitive Information vulnerability in ABB Automation Builder.ThEPSS 0.1%CVE-2025-41647MEDIUMLenze: Plaintext Password Disclosure in PLC Designer V4 InterfaceEPSS 0.1%CVE-2026-45362LOWSangoma Switchvox before 8.4 places cleartext SIP authentication credentials in a backup file.EPSS 0.1%CVE-2025-40752MEDIUMA vulnerability has been identified in POWER METER SICAM Q100 (7KG9501-0AA01-0AA1) (All versions >= V2.60 < V2.62), POWER METER SICAM Q100 (EPSS 0.1%CVE-2025-40753MEDIUMA vulnerability has been identified in POWER METER SICAM Q100 (7KG9501-0AA01-0AA1) (All versions >= V2.60 < V2.62), POWER METER SICAM Q100 (EPSS 0.1%CVE-2025-7397MEDIUMCLI history displays inline passwordsEPSS 0.1%CVE-2025-11009MEDIUMInformation Disclosure Vulnerability in GT Designer3EPSS 0.1%CVE-2024-39674MEDIUMPlaintext vulnerability in the Gallery search module. Impact: Successful exploitation of this vulnerability will affect availability.EPSS 0.1%CVE-2026-36176HIGHGNCC GP5 v7.1.76 was discovered to store pre-signed Backblaze B2 upload URLs (PUT requests) in plaintext to the serial console. This allows EPSS 0.1%CVE-2025-33081LOWMultiple Vulnerabilities in IBM Concert Software.EPSS 0.1%CVE-2026-76385MEDIUMInformation Disclosure through Action Parameters in Venafi app for Splunk SOAREPSS 0.1%CVE-2025-53755MEDIUMCleartext Storage Vulnerability in Digisol DG-GR6821AC RouterEPSS 0.1%