Fallos del tipo CWE-200

4939 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2026-26069CRITICALScraparr Readarr Integration exposes sensitive values as metric labels.EPSS 0.5%CVE-2024-13622HIGHFile Uploads Addon for WooCommerce <= 1.7.1 - Unauthenticated Sensitive Information Exposure Through Unprotected DirectoryEPSS 0.5%CVE-2024-48789HIGHAn issue in INATRONIC com.inatronic.drivedeck.home 2.6.23 allows a remote attacker to obtain sensitve information via the firmware update prEPSS 0.5%CVE-2026-7071MEDIUMCodeAstro Online Job Portal user-cvs file information disclosureEPSS 0.5%CVE-2023-5968MEDIUMPassword hash in response body after username updateEPSS 0.5%CVE-2026-62316HIGHMicrosoft UFO: DNS Rebinding → Unauthenticated File Read / Command ExecutionEPSS 0.5%CVE-2023-22019HIGHVulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). The supported version that is affecEPSS 0.5%CVE-2026-5650MEDIUMcode-projects Online Application System for Admission oas.sql sensitive informationEPSS 0.5%CVE-2020-1753MEDIUMA security flaw was found in Ansible Engine, all Ansible 2.7.x versions prior to 2.7.17, all Ansible 2.8.x versions prior to 2.8.11 and all EPSS 0.5%CVE-2026-5666MEDIUMcode-projects Online FIR System SQL Database Backup File complaints.sql sensitive informationEPSS 0.5%CVE-2025-3966MEDIUMitwanger paicoding Browsing History home information disclosureEPSS 0.5%CVE-2026-95693MEDIUMMISP Information Disclosure via Forged Upload PathEPSS 0.5%CVE-2023-45834MEDIUMWordPress Libsyn Publisher Hub Plugin <= 1.4.4 is vulnerable to Sensitive Data ExposureEPSS 0.5%CVE-2026-6160MEDIUMcode-projects Simple ChatBox Endpoint chatbox.sql SimpleChatbox_PHP file information disclosureEPSS 0.5%CVE-2026-27604CRITICALFOSSBilling: Improper API Role Validation (system) Enables Unauthenticated Access to Privileged Admin FunctionsEPSS 0.5%CVE-2026-88065HIGH`tts-be` application has a Broken Access Control vulnerabilityEPSS 0.5%CVE-2023-35900MEDIUMIBM Robotic Process Automation information disclosureEPSS 0.5%CVE-2023-48288HIGHWordPress WordPress Job Board and Recruitment Plugin – JobWP Plugin <= 2.1 is vulnerable to Sensitive Data ExposureEPSS 0.5%CVE-2026-61233CRITICALVulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Integration). The supported EPSS 0.5%CVE-2026-73406HIGHBudibase: Unauthenticated user information disclosure via public tenant user lookup endpointEPSS 0.5%