Weaknesses of type CWE-497

402 results

Divulgação de Informações Sensíveis

A aplicação expõe dados sensíveis (senhas, tokens, chaves criptográficas, dados pessoais) através de canais inseguros ou em contextos onde não deveria — logs, mensagens de erro, cache, memória ou tráfego de rede desencriptado. O risco é um atacante interceptar ou acessar esses dados e comprometer contas, sistemas ou privacidade.

Example

Uma API retorna a senha do usuário em texto plano dentro de um JSON de resposta de erro; um servidor expõe tokens de autenticação em arquivos de log acessíveis publicamente; uma página web carrega chaves de API dentro de variáveis JavaScript visíveis no código-fonte.

How to mitigate

Nunca exponha dados sensíveis em logs, mensagens de erro visíveis ao usuário ou código cliente. Criptografe dados em trânsito (HTTPS/TLS), use variáveis de ambiente ou vaults para armazenar credenciais, e revise regularmente o que é registrado ou retornado em respostas. Implemente redação de dados sensíveis (masking) em logs e erros.

CVE-2026-57753MEDIUMWordPress Kit (formerly ConvertKit) for WooCommerce plugin <= 2.1.5 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2026-65474MEDIUMWordPress Ninja Tables plugin <= 5.2.10 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2026-65490MEDIUMWordPress Create by Mediavine plugin <= 2.6.0 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2026-25325MEDIUMWordPress rtMedia for WordPress, BuddyPress and bbPress plugin <= 4.7.8 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2024-22124MEDIUMInformation Disclosure vulnerability in SAP NetWeaver Internet Communication ManagerEPSS 0.3%CVE-2022-28651HIGHIn JetBrains IntelliJ IDEA before 2021.3.3 it was possible to get passwords from protected fieldsEPSS 0.3%CVE-2025-64270MEDIUMWordPress Masteriyo - LMS plugin <= 2.0.3 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2025-64272MEDIUMWordPress Email marketing for WordPress by GetResponse Official plugin <= 1.5.3 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2024-45640MEDIUMIBM Security QRadar EDR information disclosureEPSS 0.3%CVE-2025-49147MEDIUMUmbraco.Cms Vulnerable to Disclosure of Configured Password RequirementsEPSS 0.3%CVE-2024-32732MEDIUMInformation Disclosure vulnerability in SAP BusinessObjects Business Intelligence platformEPSS 0.3%CVE-2026-3075MEDIUMWordPress Simple Ajax Chat plugin <= 20251121 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2025-47699CRITICALExposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497) in the Gallagher Morpho integration could allow an authEPSS 0.3%CVE-2023-42010LOWIBM Sterling B2B Integrator Standard Edition information disclosureEPSS 0.3%CVE-2022-43852MEDIUMIBM Aspera Console information disclosureEPSS 0.3%CVE-2025-6769MEDIUMExposure of Sensitive System Information to an Unauthorized Control Sphere in GitLabEPSS 0.3%CVE-2025-46747MEDIUMExposure of Sensitive System InformationEPSS 0.3%CVE-2023-37525MEDIUMHCL BigFix Compliance is vulnerable to a sensitive information disclosureEPSS 0.3%CVE-2025-3506MEDIUMPotentially senitive path exposed via unauthenticated http routeEPSS 0.3%CVE-2025-13160MEDIUMIQ Service International|IQ-Support - Exposure of Sensitive InformationEPSS 0.3%