Fallos del tipo CWE-200

4948 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2026-81101MEDIUMAirtable MCP CLI before 0.2.5 Credential Disclosure via Unvalidated Configured EndpointEPSS 0.4%CVE-2024-38747HIGHWordPress HitPay Payment Gateway for WooCommerce plugin <= 4.1.3 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.4%CVE-2024-33506LOWAn exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiManager 7.4.2 and below, 7.2.5 and below, 7.0.EPSS 0.4%CVE-2026-84481MEDIUMWWBN AVideo through 30.0 Information Disclosure via MobileManagerEPSS 0.4%CVE-2026-5847MEDIUMcode-projects Movie Ticketing System SQL Database Backup File moviedb.sql information disclosureEPSS 0.4%CVE-2026-75163MEDIUMAn information disclosure vulnerability in the ugw-deviceinfo method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_EPSS 0.4%CVE-2025-3059MEDIUMProfile Private - Critical - Unsupported - SA-CONTRIB-2025-002EPSS 0.4%CVE-2026-46410HIGHFileBrowser Quantum: unauthenticated user share share infoEPSS 0.4%CVE-2026-82809MEDIUMvidIQ Vision for YouTube Extension postMessage window.addEventListener information disclosureEPSS 0.4%CVE-2024-52282MEDIUMRancher Helm Applications may have sensitive values leakedEPSS 0.4%CVE-2026-2803HIGHInformation disclosure, mitigation bypass in the Settings UI componentEPSS 0.4%CVE-2026-6000MEDIUMcode-projects Online Library Management System SQL Database Backup File library.sql information disclosureEPSS 0.4%CVE-2026-5960MEDIUMcode-projects Patient Record Management System SQL Database Backup File hcpms.sql information disclosureEPSS 0.4%CVE-2026-40584MEDIUMRansomLook - Improper Filtering of Private Location Entries in API Endpoints Leads to Information ExposureEPSS 0.4%CVE-2022-48519—Unauthorized access vulnerability in the SystemUI module. Successful exploitation of this vulnerability may affect confidentiality.EPSS 0.4%CVE-2026-86190CRITICALWWBN AVideo Broken Access Control via videoViewsInfo hash ParameterEPSS 0.4%CVE-2023-52151MEDIUMWordPress Uncanny Automator Plugin <= 5.1.0.2 is vulnerable to Sensitive Data ExposureEPSS 0.4%CVE-2026-25146CRITICALOpenEMR's payments gateway_api_key secret rendered into client JS codeEPSS 0.4%CVE-2023-52148MEDIUMWordPress Affiliates Manager Plugin <= 2.9.30 is vulnerable to Sensitive Data ExposureEPSS 0.4%CVE-2026-43687MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden GEPSS 0.4%