Fallos del tipo CWE-200

4941 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2026-32265MEDIUMAmazon S3 for Craft CMS has an Information Disclosure vulnerabilityEPSS 0.5%CVE-2026-53553HIGHGoploy: Arbitrary File Read via Path Traversal in /deploy/fileDiff allows Remote Server CompromiseEPSS 0.5%CVE-2024-6568MEDIUMFlamix: Bitrix24 and Contact Form 7 integrations <= 3.1.0 - Unauthenticated Full Path DisclosureEPSS 0.5%CVE-2020-36850HIGHSitecore JSS React Sample Application 11.0.0 - 14.0.1 Information DisclosureEPSS 0.5%CVE-2025-69755HIGHAn issue in Neterbit NW-431F Router vNW-431F-20241014-IR03 allows a remote attacker to obtain sensitive information and execute arbitrary coEPSS 0.5%CVE-2023-1562LOWFull name revealed via /plugins/focalboard/api/v2/usersEPSS 0.5%CVE-2025-25975HIGHAn issue in parse-git-config v.3.0.0 allows an attacker to obtain sensitive information via the expandKeys functionEPSS 0.5%CVE-2024-41264HIGHAn issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the ssh.InsecureIgnoreHostKey() method.EPSS 0.5%CVE-2024-8969MEDIUMThe SYSCOM Group OMFLOW - Exposure of Sensitive DataEPSS 0.5%CVE-2025-25281HIGHOutback Power Mojave Inverter Exposure of Sensitive Information to an Unauthorized ActorEPSS 0.5%CVE-2025-22973HIGHAn issue in QiboSoft QiboCMS X1.0 allows a remote attacker to obtain sensitive information via the http_curl() function in the '/applicationEPSS 0.5%CVE-2026-33355MEDIUMDiscourse filters whisper posts from private-posts feedEPSS 0.5%CVE-2026-87792HIGHMultiple authorization bypass in WordPress theme design-scuole-wordpress-themeEPSS 0.5%CVE-2026-101055MEDIUMThinkware U3000 TCP Service GET_STATUS information disclosureEPSS 0.5%CVE-2026-73775HIGHAuthenticated Sensitive Information Disclosure Vulnerabilities in AOS-CXEPSS 0.5%CVE-2026-28492HIGHFile Browser: Path Traversal in Public Share Links Exposes Files Outside Shared DirectoryEPSS 0.5%CVE-2022-0854—A memory leak flaw was found in the Linux kernel’s DMA subsystem, in the way a user calls DMA_FROM_DEVICE. This flaw allows a local user to EPSS 0.5%CVE-2023-2749HIGHA Gain Information vulnerability was found on Download Center.EPSS 0.5%CVE-2026-76697MEDIUMAuthenticated Information Disclosure in HPE Networking EdgeConnect Enterprise Web-Based Management InterfaceEPSS 0.5%CVE-2026-59222MEDIUMOpen WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentialsEPSS 0.5%