Fallos del tipo CWE-200

4959 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2026-69189HIGHHoppscotch: Cross-user private data exposure and UserHistory IDOR via team GraphQL resolversEPSS 0.4%CVE-2024-7319MEDIUMOpenstack-heat: incomplete fix for cve-2023-1625EPSS 0.4%CVE-2026-78474MEDIUMNi WooCommerce Sales Report < 4.2.0 - Unauthenticated Order and Customer Data Disclosure via 'btn_print' ParameterEPSS 0.4%CVE-2026-66272MEDIUMDell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Missing Authentication for Critical Function vulnerability. An unautEPSS 0.4%CVE-2023-43996MEDIUMAn issue in Q co ltd mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access tokEPSS 0.4%CVE-2026-3131MEDIUMImproper access control in multiple DVLS REST API endpoints in Devolutions Server 2025.3.14.0 and earlier allows an authenticated user witEPSS 0.4%CVE-2026-47389HIGHMastodon: SSRF protection bypass on older Ruby versionsEPSS 0.4%CVE-2026-92357MEDIUMa2ui-project a2ui Model Processor model-processor.ts information disclosureEPSS 0.4%CVE-2025-52493MEDIUMPagerDuty Runbook through 2025-06-12 exposes stored secrets directly in the webpage DOM at the configuration page. Although these secrets apEPSS 0.4%CVE-2026-76390MEDIUMInformation Disclosure through Splunk Web in Cisco Talos Intelligence for Enterprise Security CloudEPSS 0.4%CVE-2026-35452MEDIUMWWBN AVideo has Unauthenticated Information Disclosure via Missing Auth on CloneSite client.log.phpEPSS 0.4%CVE-2023-43993MEDIUMAn issue in smaregi_app_market mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel EPSS 0.4%CVE-2026-66018MEDIUMJFrog Artifactory build environment properties exposureEPSS 0.4%CVE-2022-48514—The Sepolicy module has inappropriate permission control on the use of Netlink.Successful exploitation of this vulnerability may affect confEPSS 0.4%CVE-2023-4876HIGHExposure of Sensitive Information to an Unauthorized Actor in hamza417/inureEPSS 0.4%CVE-2026-60899MEDIUMVulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Rapid Implementation). Supported verEPSS 0.4%CVE-2026-60835MEDIUMVulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations). Supported versions that aEPSS 0.4%CVE-2026-61014HIGHVulnerability in the Oracle Inventory Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions thEPSS 0.4%CVE-2026-62470MEDIUMVulnerability in the Oracle Self-Service Human Resources product of Oracle E-Business Suite (component: Manager Self-Service). Supported veEPSS 0.4%CVE-2024-36986MEDIUMRisky command safeguards bypass through Search ID query in Analytics WorkspaceEPSS 0.4%