Fallos del tipo CWE-310

89 resultados

Divulgação de informações sensíveis

Fraqueza genérica que descreve quando uma aplicação expõe dados sensíveis (senhas, tokens, dados pessoais, chaves criptográficas) a usuários não autorizados. O risco está em não proteger adequadamente informações críticas em trânsito, em repouso ou em logs/erros.

Ejemplo

Uma API retorna mensagens de erro detalhadas que revelam paths internos do servidor; um arquivo de configuração com credenciais é commitado no repositório público; dados sensíveis são logados em texto plano e ficam acessíveis em arquivos de log do servidor.

Cómo mitigar

Implemente criptografia para dados em trânsito (HTTPS/TLS) e em repouso; sanitize mensagens de erro para não expor detalhes técnicos; audite logs e variáveis de ambiente para remover credenciais; use gerenciadores de secrets (Vault, AWS Secrets Manager) em vez de hardcoding.

CVE-2026-2966MEDIUMCesanta Mongoose DNS Transaction ID dns.c mg_sendnsreq random valuesEPSS 0.4%CVE-2022-40675MEDIUMSome cryptographic issues in Fortinet FortiNAC versions 9.4.0 through 9.4.1, 9.2.0 through 9.2.7, 9.1.0 through 9.1.8, 8.8.0 through 8.8.11,EPSS 0.4%CVE-2021-4258LOWwhohas Package Information cleartext transmissionEPSS 0.4%CVE-2020-8173A too small set of random characters being used for encryption in Nextcloud Server 18.0.4 allowed decryption in shorter time than intended.EPSS 0.4%CVE-2025-8741MEDIUMmacrozheng mall login cleartext transmissionEPSS 0.4%CVE-2026-2618MEDIUMBeetel 777VR1 SSH Service risky encryptionEPSS 0.4%CVE-2025-3329LOWConsumer Comanda Mobile Restaurant Order cleartext transmissionEPSS 0.3%CVE-2025-9828MEDIUMTenda CP6 uhttp sub_2B7D04 risky encryptionEPSS 0.3%CVE-2026-7610MEDIUMTRENDnet TEW-821DAP Firmware Update ssi cleartext transmissionEPSS 0.3%CVE-2026-19896MEDIUMmangroup dtale Flask Session Cookie app.py build_secret_key random valuesEPSS 0.3%CVE-2022-45453MEDIUMTLS/SSL weak cipher suites enabled. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 30984.EPSS 0.3%CVE-2026-77151MEDIUMlin-snow Ech0 crypto.go MD5Encrypt risky encryptionEPSS 0.3%CVE-2020-8150A cryptographic issue in Nextcloud Server 19.0.1 allowed an attacker to downgrade the encryption scheme and break the integrity of encryptedEPSS 0.3%CVE-2022-23719HIGHPingID Windows Login prior to 2.8 does not authenticate communication with a local Java service used to capture security key requestsEPSS 0.3%CVE-2026-17616MEDIUMSecurity vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify AccessEPSS 0.3%CVE-2017-13094The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), including modification of the encryption key and insertion of hardware trojans in any IPEPSS 0.3%CVE-2017-20200MEDIUMCoinomi cleartext transmissionEPSS 0.3%CVE-2025-1953LOWvLLM AIBrix Prefix Caching hash.go random valuesEPSS 0.3%CVE-2025-4894MEDIUMcalmkart Django-sso-server crypto.py gen_rsa_keys inadequate encryptionEPSS 0.3%CVE-2018-0412A vulnerability in the implementation of Extensible Authentication Protocol over LAN (EAPOL) functionality in Cisco Small Business 100 SerieEPSS 0.3%