Weaknesses of type CWE-497

406 results

Divulgação de Informações Sensíveis

A aplicação expõe dados sensíveis (senhas, tokens, chaves criptográficas, dados pessoais) através de canais inseguros ou em contextos onde não deveria — logs, mensagens de erro, cache, memória ou tráfego de rede desencriptado. O risco é um atacante interceptar ou acessar esses dados e comprometer contas, sistemas ou privacidade.

Example

Uma API retorna a senha do usuário em texto plano dentro de um JSON de resposta de erro; um servidor expõe tokens de autenticação em arquivos de log acessíveis publicamente; uma página web carrega chaves de API dentro de variáveis JavaScript visíveis no código-fonte.

How to mitigate

Nunca exponha dados sensíveis em logs, mensagens de erro visíveis ao usuário ou código cliente. Criptografe dados em trânsito (HTTPS/TLS), use variáveis de ambiente ou vaults para armazenar credenciais, e revise regularmente o que é registrado ou retornado em respostas. Implemente redação de dados sensíveis (masking) em logs e erros.

CVE-2026-58246MEDIUMInformation Disclosure vulnerability in SAP NetWeaver Application Server for ABAP and ABAP PlatformEPSS 0.1%CVE-2024-6388MEDIUMMarco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivileged users by passinEPSS 0.1%CVE-2025-59178MEDIUMExposure of Sensitive System Information to an Unauthorized Control Sphere VulnerabilityEPSS 0.1%CVE-2025-0036LOWIn AMD Versal Adaptive SoC devices, the incorrect configuration of the SSS during runtime (post-boot) cryptographic operations could cause dEPSS 0.1%CVE-2025-8700MEDIUMPrivilege Escalation via get-task-allow entitlement in Invoice NinjaEPSS 0.1%CVE-2025-8597MEDIUMPrivilege Escalation via get-task-allow entitlement in MacVim.appEPSS 0.1%CVE-2025-6390MEDIUMCleartext storage of sensitive information in Brocade SANnav server audit logs.EPSS 0.1%CVE-2025-4662MEDIUMPlaintext security passwords are logged in the audit logs while executing openssl cmdEPSS 0.1%CVE-2025-24334LOWThe Nokia Single RAN baseband reveals its software version through the MNO internal RAN management networkEPSS 0.1%CVE-2025-23288LOWNVIDIA GPU Display Driver for Windows contains a vulnerability  where an attacker may cause an exposure of sensitive system information withEPSS 0.1%CVE-2026-0466MEDIUMImproper access control in AMD uProf may allow a local attacker with user privileges to write to the kernel-shared memory section, potentialEPSS 0.1%CVE-2026-53682MEDIUMPki-core: dogtag-pki: unauthenticated dogtag ca rest api exposes security domain hostsEPSS 0.1%CVE-2026-80119HIGHPassMark PerformanceTest, BurnInTest, and OSForensics Physical Memory Disclosure via DirectIo64.sys IOCTLEPSS 0.1%CVE-2026-22537MEDIUMINFORMATION DISCLOSURE WITHIN THE OPERATING SYSTEMEPSS 0.1%CVE-2024-45549HIGHExposure of Sensitive System Information to an Unauthorized Control Sphere in KERNELEPSS 0.1%CVE-2024-0053LOWIn getCustomPrinterIcon of PrintManagerService.java, there is a possible way to view other user's images due to a confused deputy. This coulEPSS 0.1%CVE-2026-80118HIGHPassMark PerformanceTest, BurnInTest, and OSForensics Kernel Null Pointer Dereference via DirectIo64.sys IOCTLEPSS 0.1%CVE-2026-67267MEDIUMDell Command Update (DCU), versions prior to 5.7.1, contain an Exposure of Sensitive System Information to an Unauthorized Control Sphere vuEPSS 0.1%CVE-2026-56569MEDIUMHCL iControl is affected by multiple security vulnerabilities.EPSS 0.1%CVE-2025-47319MEDIUMExposure of Sensitive System Information to an Unauthorized Control Sphere in HLOSEPSS 0.1%