Falhas do tipo CWE-201

411 resultados

Exposição de informações sensíveis em dados enviados

A aplicação inclui dados sensíveis (senhas, tokens, chaves API, PII) em comunicações que não deveriam conter essa informação — logs, requisições HTTP não criptografadas, emails, respostas de erro, ou cache. O atacante consegue interceptar ou acessar esses dados sem autorização.

Exemplo

Um sistema de e-commerce que envia a senha do usuário em texto plano no email de confirmação de cadastro, ou uma API que registra tokens de autenticação em logs acessíveis. Outro caso comum: formulário enviado via HTTP (não HTTPS) contendo dados de cartão de crédito.

Como mitigar

Nunca inclua dados sensíveis em logs, mensagens de erro ou comunicações não criptografadas. Use HTTPS obrigatoriamente, implemente tratamento de exceções que não expõe detalhes, e revise sistematicamente o que é transmitido em cada canal (emails, APIs, respostas). Ferramentas de análise estática ajudam a detectar vazamentos de credenciais no código.

CVE-2026-65812MEDIUMMicrosoft Teams for Android Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-82837MEDIUMInsertion of Sensitive Information Into Sent Data in GitLabEPSS 0.5%CVE-2025-66388MEDIUMApache Airflow: Secrets in rendered templates not redacted properly and exposed in the UIEPSS 0.5%CVE-2025-47775MEDIUMBullfrog's DNS over TCP bypasses domain filteringEPSS 0.5%CVE-2024-47569MEDIUMA insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 through 7.4.2, FortiMail 7.2.0 through 7.2.6, EPSS 0.5%CVE-2025-24858HIGHDevelocity (formerly Gradle Enterprise) before 2024.3.1 allows an attacker who has network access to a Develocity server to obtain the hasheEPSS 0.5%CVE-2025-32594HIGHWordPress Simple WP Events plugin <= 1.8.17 - Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2025-32635HIGHWordPress Hive Support plugin <= 1.2.6 - Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2025-24639MEDIUMWordPress Korea for WooCommerce plugin <= 1.1.11 - Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2026-54649LOWpunchin-email: Operator inbox (FORWARD_TO) disclosed to correspondents on reply — Cloudflare forward() drops the relay Reply-ToEPSS 0.5%CVE-2026-63481MEDIUMHurl: Cookies in Cookies section leak when redirecting to a different hostEPSS 0.5%CVE-2024-38372LOWUndici vulnerable to data leak when using response.arrayBuffer()EPSS 0.5%CVE-2020-14514MEDIUMTrailer Power Line Communications vulnerabilityEPSS 0.5%CVE-2026-1365MEDIUMInformation Disclosure in Sayax's OSOSEPSS 0.5%CVE-2024-5213MEDIUMExposure of Sensitive Information in mintplex-labs/anything-llmEPSS 0.5%CVE-2025-27244MEDIUMAssetView and AssetView CLOUD contain an issue with acquiring sensitive information from sent data to the developer. If exploited, sensitiveEPSS 0.5%CVE-2025-23774HIGHWordPress WPDB to Sql plugin <= 1.2 - Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2023-5831LOWInsertion of Sensitive Information Into Sent Data in GitLabEPSS 0.5%CVE-2025-64407MEDIUMApache OpenOffice: URL fetching can be used to exfiltrate arbitrary INI file values and environment variablesEPSS 0.5%CVE-2026-34226HIGHHappy DOM's fetch credentials include uses page-origin cookies instead of target-origin cookiesEPSS 0.5%