Weaknesses of type CWE-312

468 results

Divulgação de informações sensíveis

A aplicação expõe dados sensíveis (senhas, tokens, chaves, dados pessoais) através de mecanismos que não deveria — logs, mensagens de erro, respostas HTTP, cache ou armazenamento inseguro. O risco é que um atacante, desenvolvedor ou qualquer pessoa com acesso ao sistema consegue extrair informações que comprometerem segurança ou privacidade.

Example

Uma API retorna mensagem de erro com detalhes da query SQL executada, ou logs de produção armazenam senhas em texto plano, ou resposta HTTP carrega um token JWT sem flag HttpOnly — em todos os casos, dados que deveriam ser secretos ficam acessíveis a quem não deveria.

How to mitigate

Sanitize mensagens de erro (retorne genéricas ao cliente, detalhe apenas em logs privados); nunca registre senhas, tokens ou PII em logs; use flags seguras em cookies (HttpOnly, Secure, SameSite); implemente controle de acesso a logs e artifacts; criptografe dados em repouso e em trânsito; revise regularmente o que está sendo exposto em respostas HTTP e exceções.

CVE-2025-59409HIGHFlock Safety Falcon and Sparrow License Plate Readers OPM1.171019.026 ship with development Wi-Fi credentials (test_flck) stored in cleartexEPSS 0.3%CVE-2024-40582HIGHPentaminds CuroVMS v2.0.1 was discovered to contain exposed sensitive information.EPSS 0.3%CVE-2026-27877MEDIUMPublic dashboards discloses all direct mode datasourcesEPSS 0.3%CVE-2024-51175HIGHAn issue in H3C switch h3c-S1526 allows a remote attacker to obtain sensitive information via the S1526.cfg component.EPSS 0.3%CVE-2023-27243HIGHAn access control issue in Makves DCAP v3.0.0.122 allows unauthenticated attackers to obtain cleartext credentials via a crafted web requestEPSS 0.3%CVE-2023-2335MEDIUMPlaintext Password in RegistryEPSS 0.3%CVE-2025-25758HIGHAn issue in KukuFM Android v1.12.7 (11207) allows attackers to access sensitive cleartext data via the android:allowBackup="true" in the ANdEPSS 0.3%CVE-2025-8528MEDIUMExrick xboot getMenuList sensitive information in a cookieEPSS 0.3%CVE-2025-59792MEDIUMApache Kvrocks: MONITOR command reveals plaintext credentials to non-adminsEPSS 0.3%CVE-2025-51055HIGHInsecure Data Storage of credentials has been found in /api_vedo/configuration/config.yml file in Vedo Suite version 2024.17. This file contEPSS 0.3%CVE-2022-35279MEDIUM"IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, 19.0.0.3, 20.0.0.1, 20.0.0.2, 21.0.2, 21.0.3, and 22.0.1EPSS 0.3%CVE-2025-65826CRITICALThe mobile application was found to contain stored credentials for the network it was developed on. If an attacker retrieved this, and foundEPSS 0.3%CVE-2024-46505CRITICALInfoblox BloxOne v2.4 was discovered to contain a business logic flaw due to thick client vulnerabilities.EPSS 0.3%CVE-2024-11159MEDIUMUsing remote content in OpenPGP encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird < 128.4.3EPSS 0.3%CVE-2024-34891MEDIUMInsufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to read Exchange aEPSS 0.3%CVE-2025-4537LOWyangzongzhuan RuoYi-Vue Password login.vue sensitive information in a cookieEPSS 0.3%CVE-2019-14886MEDIUMA vulnerability was found in business-central, as shipped in rhdm-7.5.1 and rhpam-7.5.1, where encoded passwords are stored in errai_securitEPSS 0.3%CVE-2022-22302MEDIUMA clear text storage of sensitive information (CWE-312) vulnerability in both FortiGate version 6.4.0 through 6.4.1, 6.2.0 through 6.2.9 andEPSS 0.3%CVE-2020-11918MEDIUMAn issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. When a backup file is created through the web interface, information on aEPSS 0.3%CVE-2025-30124CRITICALAn issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. When a new SD card is inserted into the dashcam, the existing password isEPSS 0.3%