Weaknesses of type CWE-497

406 results

Divulgação de Informações Sensíveis

A aplicação expõe dados sensíveis (senhas, tokens, chaves criptográficas, dados pessoais) através de canais inseguros ou em contextos onde não deveria — logs, mensagens de erro, cache, memória ou tráfego de rede desencriptado. O risco é um atacante interceptar ou acessar esses dados e comprometer contas, sistemas ou privacidade.

Example

Uma API retorna a senha do usuário em texto plano dentro de um JSON de resposta de erro; um servidor expõe tokens de autenticação em arquivos de log acessíveis publicamente; uma página web carrega chaves de API dentro de variáveis JavaScript visíveis no código-fonte.

How to mitigate

Nunca exponha dados sensíveis em logs, mensagens de erro visíveis ao usuário ou código cliente. Criptografe dados em trânsito (HTTPS/TLS), use variáveis de ambiente ou vaults para armazenar credenciais, e revise regularmente o que é registrado ou retornado em respostas. Implemente redação de dados sensíveis (masking) em logs e erros.

CVE-2025-43471MEDIUMThe issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.EPSS 0.2%CVE-2025-59447LOWThe YoSmart YoLink Smart Hub device 0382 exposes a UART debug interface. An attacker with direct physical access can leverage this interfaceEPSS 0.2%CVE-2022-34458MEDIUM Dell Command | Update, Dell Update, and Alienware Update versions prior to 4.7 contain a Exposure of Sensitive System Information to an UnaEPSS 0.2%CVE-2026-39469MEDIUMWordPress PageLayer plugin <= 2.0.8 - Sensitive Data Exposure vulnerabilityEPSS 0.2%CVE-2024-52582MEDIUMcachi2 allows traceback prints localsEPSS 0.2%CVE-2025-4235HIGHUser-ID Credential Agent: Cleartext Exposure of Service Account passwordEPSS 0.2%CVE-2026-24618MEDIUMWordPress Hash Elements plugin <= 1.5.4 - Sensitive Data Exposure vulnerabilityEPSS 0.2%CVE-2025-2236LOWExposure of Sensitive System Information vulnerability during configuration affecting OpenText Advanced Authentication.EPSS 0.2%CVE-2026-0239MEDIUMChronosphere Chronocollector Information Disclosure VulnerabilityEPSS 0.2%CVE-2024-22037MEDIUMDatabase password leaked by systemd uyuni-server-attestation serviceEPSS 0.2%CVE-2026-27349MEDIUMWordPress Mail Mint plugin <= 1.19.5 - Sensitive Data Exposure vulnerabilityEPSS 0.2%CVE-2026-0231MEDIUMCortex XDR Broker VM: Sensitive Information Disclosure VulnerabilityEPSS 0.2%CVE-2026-6373MEDIUMSensitive Data Exposure in Zyxel WAH7601 RouterEPSS 0.2%CVE-2025-36238MEDIUMPower System Exposure of Sensitive System InformationEPSS 0.2%CVE-2023-5081LOWAn information disclosure vulnerability was reported in the Lenovo Tab M8 HD that could allow a local application to gather a non-resettableEPSS 0.2%CVE-2025-32026LOWElement Web could load a malicious instance of Element Call leaking media encryption keysEPSS 0.2%CVE-2025-23287LOWNVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker may access sensitive system-level information. A successfulEPSS 0.2%CVE-2024-11035LOWCarbon Black Cloud Windows Sensor Information LeakEPSS 0.2%CVE-2025-15680LOWInformation Disclosure via UARTEPSS 0.2%CVE-2026-10588MEDIUMA potential vulnerability could allow a local privileged attacker to disclose the address of protected System Management Mode memory.EPSS 0.2%