Weaknesses of type CWE-209

433 results

Exposição de Informações Sensíveis em Mensagens de Erro

A aplicação retorna mensagens de erro que revelam detalhes internos do sistema — como caminhos de arquivo, nomes de banco de dados, versões de software ou stack traces — para usuários não autorizados. Um atacante usa essas informações para mapear a infraestrutura e planejar exploits direcionados.

Example

Um formulário de login mostra 'Erro SQL: usuário não encontrado em tabela users_prod' ao invés de 'Credenciais inválidas'. O atacante descobre o nome exato da tabela e começa testes de SQL injection. Ou um erro de exceção expõe '/var/www/html/config.php:42', revelando a estrutura do servidor.

How to mitigate

Exiba mensagens de erro genéricas ao usuário final ('Operação não permitida'), e registre os detalhes técnicos apenas em logs internos do servidor. Desabilite stack traces e debug info em produção, use tratamento centralizado de exceções e valide/sanitize todo output antes de devolvê-lo ao cliente.

CVE-2026-47622MEDIUMNVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause the generation of error messages that contain sensitive inforEPSS 0.3%CVE-2026-66009MEDIUMParse Server 9.0.0 Information Disclosure via GraphQL Error MessagesEPSS 0.3%CVE-2025-41076MEDIUMMultiple vulnerabilities in LimesurveyEPSS 0.3%CVE-2026-2752MEDIUMNavtor NavBox allows information disclosure via the /api/ais-data endpoint. A remote, unauthenticated attacker can send crafted requests to EPSS 0.3%CVE-2025-54791MEDIUMOMERO.web displays unecessary user information when requesting to reset the passwordEPSS 0.3%CVE-2026-74879HIGHopenssl_encrypt before 1.4.0 Information Disclosure via /ready endpointEPSS 0.3%CVE-2025-0049LOWDisclosure of sensitive information in an error message in GoAnywhere prior to version 7.8.0EPSS 0.3%CVE-2026-73555MEDIUMvLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error MessagesEPSS 0.3%CVE-2026-43873HIGHWWBN AVideo: Unauthenticated Disclosure of CloneSite `myKey` via Error Echo in `cloneClient.json.php` Enables Cross-Site DB Dump of the Configured Clone ServerEPSS 0.3%CVE-2025-61959MEDIUMVertikal Systems Hospital Manager Backend Services Generation of Error Message Containing Sensitive InformationEPSS 0.3%CVE-2026-55375MEDIUMcanto-saas-api: OAuth credentials exposed in URL query string and exception messagesEPSS 0.3%CVE-2026-28675MEDIUMOpenSift: Sensitive implementation details exposed via raw exception messages and token-returning endpointsEPSS 0.3%CVE-2026-41931MEDIUMVvveb < 1.0.8.2 Information Disclosure via Debug Exception HandlerEPSS 0.2%CVE-2026-47893HIGHSpring Framework Request Headers Included in Exception Reasons in HandshakeWebsocketServiceEPSS 0.2%CVE-2022-22162HIGHJunos OS: A low privileged user can elevate their privileges to the ones of the highest privileged j-web user logged inEPSS 0.2%CVE-2026-1262MEDIUMIBM InfoSphere Information Server Information DisclosureEPSS 0.2%CVE-2026-9583MEDIUMSourceCodester CET Automated Grading System with AI Predictive Analytics SQL index.php information exposureEPSS 0.2%CVE-2026-44002MEDIUMvm2: Host File Path Disclosure via Stack Trace Information LeakEPSS 0.2%CVE-2025-31960MEDIUMHCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its reporting moduleEPSS 0.2%CVE-2026-79777MEDIUMrclone before v1.75.0 Information Disclosure via RC APIEPSS 0.2%