Fallos del tipo CWE-200

4949 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2023-52148MEDIUMWordPress Affiliates Manager Plugin <= 2.9.30 is vulnerable to Sensitive Data ExposureEPSS 0.4%CVE-2023-52237HIGHA vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i802, RUGGEDCOM i802NC,EPSS 0.4%CVE-2026-61175CRITICALVulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported verEPSS 0.4%CVE-2024-33538MEDIUMWordPress Assistant – Every Day Productivity Apps plugin <= 1.4.9.1 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2023-4877MEDIUMExposure of Sensitive Information to an Unauthorized Actor in hamza417/inureEPSS 0.4%CVE-2024-37504MEDIUMWordPress FileBird Document Library plugin <= 2.0.6 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2023-52208MEDIUMWordPress Constant Contact Forms Plugin <= 2.4.2 is vulnerable to Sensitive Data ExposureEPSS 0.4%CVE-2024-1436MEDIUMWordPress WooCommerce Coupon Popup, SmartBar, Slide In | MyShopKit Plugin <= 1.0.9 is vulnerable to Sensitive Data ExposureEPSS 0.4%CVE-2023-44115HIGHVulnerability of improper permission control in the Booster module. Impact: Successful exploitation of this vulnerability may affect serviceEPSS 0.4%CVE-2025-25951HIGHAn information disclosure vulnerability in the component /rest/cb/executeBasicSearch of Serosoft Solutions Pvt Ltd Academia Student InformatEPSS 0.4%CVE-2023-49162MEDIUMWordPress BigCommerce Plugin <= 5.0.6 is vulnerable to Sensitive Data ExposureEPSS 0.4%CVE-2023-46757—The remote PIN module has a vulnerability that causes incorrect information storage locations.Successful exploitation of this vulnerability EPSS 0.4%CVE-2024-37498MEDIUMWordPress Tablesome plugin <= 1.0.33 - Sensitive Data Exposure via API vulnerabilityEPSS 0.4%CVE-2024-13562HIGHImport WP – Export and Import CSV and XML files to WordPress <= 2.14.5 - Unauthenticated Sensitive Information Exposure Through Unprotected DirectoryEPSS 0.4%CVE-2024-8483MEDIUMMAS Static Content <= 1.0.8 - Authenticated (Contributor+) Private Static Content Page DisclosureEPSS 0.4%CVE-2024-13796MEDIUMPost Grid and Gutenberg Blocks – ComboBlocks <= 2.3.6 - Unauthenticated User Information ExposureEPSS 0.4%CVE-2026-36719HIGHAn information disclosure vulnerability in the /api/v1/user/info endpoint of AgentChat v2.3.0 allows unauthenticated attackers to obtain senEPSS 0.4%CVE-2026-14943HIGHPassword Protected < 2.8.4 - Unauthenticated Sensitive Information Exposure via REST APIEPSS 0.4%CVE-2024-20445MEDIUMCisco IP Phone 7800, 8800, and 9800 Series Information Disclosure VulnerabilityEPSS 0.4%CVE-2026-74948MEDIUMInformation disclosure in the Graphics componentEPSS 0.4%