Fallos del tipo CWE-200

4941 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2026-84625CRITICALA permissions issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, vEPSS 0.5%CVE-2024-25114LOWSensitive Information Disclosure (JailID) to users in Collabora OnlineEPSS 0.5%CVE-2025-10750MEDIUMPowerBI Embed Reports <= 1.2.0 - Unauthenticated Sensitive Information DisclosureEPSS 0.5%CVE-2023-38494MEDIUMThe cloud version of the MeterSphere interface leaks some sensitive data without authenticationEPSS 0.5%CVE-2024-34382MEDIUMWordPress Photo Gallery, Images, Slider in Rbs Image Gallery plugin <= 3.2.18 - Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2025-6593LOW"{{SITENAME}} registered email address has been changed" email sent to unverified email addressesEPSS 0.5%CVE-2024-53244MEDIUMRisky command safeguards bypass in “/en-US/app/search/report“ endpoint through “s“ parameterEPSS 0.5%CVE-2023-3361HIGHS3 credentials included when exporting elyra notebookEPSS 0.5%CVE-2025-34059HIGHDahua Smart Cloud Gateway Registration Management Platform SQL InjectionEPSS 0.5%CVE-2024-34358MEDIUMTYPO3 vulnerable to an Uncontrolled Resource Consumption in the ShowImageControllerEPSS 0.5%CVE-2023-38685MEDIUMDiscourse's restricted tag information visible to unauthenticated usersEPSS 0.5%CVE-2024-31302MEDIUMWordPress Contact Form Email plugin <= 1.3.44 - Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2024-24720MEDIUMAn issue was discovered in the Forgot password function in Innovaphone PBX before 14r1 devices. It provides information about whether a userEPSS 0.5%CVE-2022-27490MEDIUMA exposure of sensitive information to an unauthorized actor in Fortinet FortiManager version 6.0.0 through 6.0.4, FortiAnalyzer version 6.0EPSS 0.5%CVE-2025-4222MEDIUMDatabase Toolset <= 1.8.4 - Unauthenticated Sensitive Information Exposure via Backup FilesEPSS 0.5%CVE-2024-13613HIGHWise Chat <= 3.3.3 - Unauthenticated Sensitive Information Exposure Through Unprotected DirectoryEPSS 0.5%CVE-2024-48824HIGHAn issue in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a remote attacker to obtain sensitiEPSS 0.5%CVE-2026-52888MEDIUMNocoBase: Sensitive Data Exposure via SQL Blacklist BypassEPSS 0.5%CVE-2026-48080HIGHOpenReception's tenant detail endpoint discloses live PostgreSQL connection string, superuser-scoped in the tested official deploymentEPSS 0.5%CVE-2024-0615MEDIUMContent Control <= 2.1.0 - Missing Authorization to Sensitive Information ExposureEPSS 0.5%