Fallos del tipo CWE-200

4958 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2025-2882MEDIUMGreenPay(tm) by Green.Money 3.0.0 - 3.0.9 - Unauthenticated Information ExposureEPSS 0.4%CVE-2025-14197MEDIUMVerysync 微力同步 Web Administration f96956469e7be39d information disclosureEPSS 0.4%CVE-2026-56456MEDIUMHCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability.EPSS 0.4%CVE-2025-52467CRITICALpgai secrets exfiltration via `pull_request_target`EPSS 0.4%CVE-2025-2883MEDIUMAccept SagePay Payments Using Contact Form 7 <= 2.0 - Unauthenticated Information ExposureEPSS 0.4%CVE-2025-49845MEDIUMDiscourse users are able to see their own whispers even after being removed from a group that has been configured to see whispersEPSS 0.4%CVE-2024-41696HIGHPriority PRI WEB Portal Add-On for Priority ERP on prem – CWE-200: Exposure of Sensitive Information to an Unauthorized ActorEPSS 0.4%CVE-2026-59209HIGHn8n: Shared Credential Header Leak via HTTP Request Pagination ExpressionEPSS 0.4%CVE-2026-12203MEDIUMHKUDS AI-Trader Research Export agents.csv information disclosureEPSS 0.4%CVE-2024-23568MEDIUMHCL Aftermarket EPC is vulnerable to attacks since the server software version used by the application is revealed by the web server. DisplaEPSS 0.4%CVE-2026-6770MEDIUMOther issue in the Storage: IndexedDB componentEPSS 0.4%CVE-2026-4733MEDIUMInformation disclosure in ixray-1.6-stcopEPSS 0.4%CVE-2026-67410HIGHRabbitMQ: OAuth2 Client Secret Exposed via Unauthenticated JavaScript EndpointEPSS 0.4%CVE-2025-57430HIGHCreacast Creabox Manager 4.4.4 exposes sensitive configuration data via a publicly accessible endpoint /get. When accessed, this endpoint reEPSS 0.4%CVE-2024-9530MEDIUMQi Addons For Elementor <= 1.8.0 - Sensitive Information ExposureEPSS 0.4%CVE-2025-45994HIGHAn issue in Aranda PassRecovery v1.0 allows attackers to enumerate valid user accounts in Active Directory via sending a crafted POST requesEPSS 0.4%CVE-2026-72539MEDIUMWindmill Labs Windmill - Information DisclosureEPSS 0.4%CVE-2022-1353—A vulnerability was found in the pfkey_register function in net/key/af_key.c in the Linux kernel. This flaw allows a local, unprivileged useEPSS 0.4%CVE-2025-34072CRITICALAnthropic Slack MCP Server Data Exfiltration via Link UnfurlingEPSS 0.4%CVE-2026-21880MEDIUMKanboard LDAP Injection Vulnerability can Lead to User Enumeration and Information DisclosureEPSS 0.4%