Fallos del tipo CWE-200

4953 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2026-7542MEDIUMSlider Revolution 7.0 - 7.0.10 - Authenticated (Subscriber+) Sensitive Information DisclosureEPSS 0.4%CVE-2026-45378HIGHDecidim: Verification documents can be downloaded through reusable linksEPSS 0.4%CVE-2026-23983LOWApache Superset: Sensitive Data Exposure via REST API (disabled by default)EPSS 0.4%CVE-2026-83326HIGHVulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versions that are affecteEPSS 0.4%CVE-2026-50210MEDIUMWeak Static Cryptographic Initialization VectorsEPSS 0.4%CVE-2025-30218LOWNext.js may leak x-middleware-subrequest-id to external hostsEPSS 0.4%CVE-2026-83424HIGHVulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Oracle JDeveloper). Supported versions that are affeEPSS 0.4%CVE-2026-17542HIGHBit File Manager < 6.9.1 - Subscriber+ Sensitive Data Disclosure via bitapps_fm_connectorEPSS 0.4%CVE-2026-49187HIGHHard-coded APK Resource Credentials & SceptersEPSS 0.4%CVE-2026-2747MEDIUMPGP Mixed Plaintext and Encrypted ContentEPSS 0.4%CVE-2026-83167HIGHVulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are afEPSS 0.4%CVE-2026-65881HIGHJoomla Extension - joomdle.com - Insecure default configuration allows read/write user account access in Joomdle < 3.1.1EPSS 0.4%CVE-2026-59499HIGHPriority – CWE-200: Exposure of Sensitive Information to an Unauthorized ActorEPSS 0.4%CVE-2026-49269HIGHApple M1 GPUs retain register file data between compute shader dispatches from different processes. A sandboxed Metal attacker app can run aEPSS 0.4%CVE-2026-86419HIGHMISP Insufficient Outbound URL Validation Allows SSRF and Credential Disclosure via Feed Redirects and TAXII DiscoveryEPSS 0.4%CVE-2026-65430HIGHJoomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extensionEPSS 0.4%CVE-2026-16594HIGHWP Directory Kit < 1.5.5 - Subscriber+ Plugin Settings and API Key DisclosureEPSS 0.4%CVE-2022-0494—A kernel information leak flaw was identified in the scsi_ioctl function in drivers/scsi/scsi_ioctl.c in the Linux kernel. This flaw allows EPSS 0.4%CVE-2026-49193HIGHPublicly Readable AWS S3 Telemetry BucketsEPSS 0.4%CVE-2011-4327MEDIUMssh-keysign.c in ssh-keysign in OpenSSH before 5.8p2 on certain platforms executes ssh-rand-helper with unintended open file descriptors, whEPSS 0.4%