Weaknesses of type CWE-202

40 results

Exposição de informações sensíveis através de consultas de dados

A aplicação expõe dados confidenciais (senhas, tokens, PII) ao responder consultas que deveriam ser restritas ou filtradas. O problema ocorre quando o sistema não valida ou sanitiza adequadamente quais dados um usuário pode acessar, permitindo que requisições retornem informações que não deveriam estar visíveis.

Example

Uma API de busca de usuários retorna campos como senha hash ou token de reset mesmo quando o cliente não tem permissão para vê-los. Ou um endpoint de listagem de pedidos expõe dados de clientes de outras contas porque não há verificação de ownership na query.

How to mitigate

Implemente filtros de saída (output filtering) baseados em permissões: cada resultado deve passar por validação de acesso do usuário. Use princípio do menor privilégio nas queries, selecionando apenas colunas necessárias, e adicione testes automatizados que verificam se dados sensíveis vazam em respostas não autorizadas.

CVE-2026-42797MEDIUMApache Syncope: JexlContextBuilder Information DisclosureEPSS 0.4%CVE-2021-1372MEDIUMCisco Webex Meetings Desktop App and Webex Productivity Tools for Windows Shared Memory Information Disclosure VulnerabilityEPSS 0.4%CVE-2024-20388MEDIUMA vulnerability in the password change feature of Cisco Firepower Management Center (FMC) software could allow an unauthenticated, remote atEPSS 0.4%CVE-2024-38897MEDIUMWAVLINK WN551K1'live_check.shtml enables attackers to obtain sensitive router information.EPSS 0.4%CVE-2024-38895MEDIUMWAVLINK WN551K1'live_mfg.shtml enables attackers to obtain sensitive router information.EPSS 0.4%CVE-2024-38892MEDIUMAn issue in Wavlink WN551K1 allows a remote attacker to obtain sensitive information via the ExportAllSettings.sh component.EPSS 0.4%CVE-2026-16520HIGHImproper input validation and Exposure of sensitive information through data queries vulnerability in Genians Genian NAC V4.0, Genians GeniaEPSS 0.4%CVE-2025-29981HIGHDell Wyse Management Suite, versions prior to WMS 5.1, contains an Exposure of Sensitive Information Through Data Queries vulnerability. An EPSS 0.4%CVE-2026-25050LOWVendure vulnerable to timing attack that enables user enumeration in NativeAuthenticationStrategyEPSS 0.4%CVE-2026-77883MEDIUMApache Syncope: Information disclosure via one-hop JEXL navigation past the JexlContextBuilder name denylistEPSS 0.4%CVE-2024-2088HIGHNextScripts: Social Networks Auto-Poster <= 4.4.3 - Authenticated(Subscriber+) Sensitive Information ExposureEPSS 0.3%CVE-2025-36575HIGHDell Wyse Management Suite, versions prior to WMS 5.2, contain an Exposure of Sensitive Information Through Data Queries vulnerability. An uEPSS 0.3%CVE-2025-64504MEDIUMLangfuse vulnerable to cross‑organization enumeration of member & invitation lists via project membership APIsEPSS 0.3%CVE-2026-70473HIGHFlowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert historyEPSS 0.3%CVE-2026-40533MEDIUMAn exposure of sensitive information through data queries vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69EPSS 0.3%CVE-2025-64528MEDIUMUsers are able to find users by name even when `enable_names` is offEPSS 0.3%CVE-2021-4159A vulnerability was found in the Linux kernel's EBPF verifier when handling internal data structures. Internal memory locations could be retEPSS 0.2%CVE-2026-3546MEDIUMe-shot <= 1.0.2 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via API Token via 'eshot_form_builder_get_account_data' AJAX ActionEPSS 0.2%CVE-2026-25703HIGHPotential information leakage from manager /network/graph API in NeuVectorEPSS 0.2%CVE-2026-33530HIGHInvenTree Vulnerable to ORM Filter InjectionEPSS 0.2%