Falhas do tipo CWE-310

89 resultados

Divulgação de informações sensíveis

Ocorre quando o software expõe dados sensíveis (credenciais, tokens, chaves, PII) através de logs, mensagens de erro, URLs, memória ou canais inseguros. O risco é que um atacante intercepte ou acesse esses dados sem autorização, comprometendo confidencialidade.

Exemplo

Uma API retorna a senha em hash no JSON de resposta de erro, ou um sistema registra números de cartão de crédito em logs de aplicação acessíveis a múltiplos usuários. Um atacante com acesso aos logs ou à resposta HTTP intercepta as credenciais.

Como mitigar

Nunca exponha secrets em logs, respostas de erro ou URLs; use variáveis de ambiente ou vaults para credenciais; implemente mascaramento de dados sensíveis; revise mensagens de erro para não revelar detalhes da infraestrutura; criptografe dados em trânsito (HTTPS/TLS).

CVE-2026-2966MEDIUMCesanta Mongoose DNS Transaction ID dns.c mg_sendnsreq random valuesEPSS 0.4%CVE-2022-40675MEDIUMSome cryptographic issues in Fortinet FortiNAC versions 9.4.0 through 9.4.1, 9.2.0 through 9.2.7, 9.1.0 through 9.1.8, 8.8.0 through 8.8.11,EPSS 0.4%CVE-2021-4258LOWwhohas Package Information cleartext transmissionEPSS 0.4%CVE-2020-8173A too small set of random characters being used for encryption in Nextcloud Server 18.0.4 allowed decryption in shorter time than intended.EPSS 0.4%CVE-2025-8741MEDIUMmacrozheng mall login cleartext transmissionEPSS 0.4%CVE-2026-2618MEDIUMBeetel 777VR1 SSH Service risky encryptionEPSS 0.4%CVE-2025-3329LOWConsumer Comanda Mobile Restaurant Order cleartext transmissionEPSS 0.3%CVE-2025-9828MEDIUMTenda CP6 uhttp sub_2B7D04 risky encryptionEPSS 0.3%CVE-2026-7610MEDIUMTRENDnet TEW-821DAP Firmware Update ssi cleartext transmissionEPSS 0.3%CVE-2026-19896MEDIUMmangroup dtale Flask Session Cookie app.py build_secret_key random valuesEPSS 0.3%CVE-2022-45453MEDIUMTLS/SSL weak cipher suites enabled. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 30984.EPSS 0.3%CVE-2026-77151MEDIUMlin-snow Ech0 crypto.go MD5Encrypt risky encryptionEPSS 0.3%CVE-2020-8150A cryptographic issue in Nextcloud Server 19.0.1 allowed an attacker to downgrade the encryption scheme and break the integrity of encryptedEPSS 0.3%CVE-2022-23719HIGHPingID Windows Login prior to 2.8 does not authenticate communication with a local Java service used to capture security key requestsEPSS 0.3%CVE-2026-17616MEDIUMSecurity vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify AccessEPSS 0.3%CVE-2017-13094The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), including modification of the encryption key and insertion of hardware trojans in any IPEPSS 0.3%CVE-2017-20200MEDIUMCoinomi cleartext transmissionEPSS 0.3%CVE-2025-1953LOWvLLM AIBrix Prefix Caching hash.go random valuesEPSS 0.3%CVE-2025-4894MEDIUMcalmkart Django-sso-server crypto.py gen_rsa_keys inadequate encryptionEPSS 0.3%CVE-2018-0412A vulnerability in the implementation of Extensible Authentication Protocol over LAN (EAPOL) functionality in Cisco Small Business 100 SerieEPSS 0.3%