Fallos del tipo CWE-200

4959 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2026-21626CRITICALExtension - stackideas.com - Information disclosure in post custom fields in EasyDiscuss 1.0.0-5.0.15 for JoomlaEPSS 0.4%CVE-2026-72834MEDIUMfilebrowser before 2.63.19 Permission Bypass via checksumEPSS 0.4%CVE-2026-45351MEDIUMOpen WebUI: Exposure of System Prompt to Regular User [Non-Admin]EPSS 0.4%CVE-2026-61165HIGHVulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge). The supported version EPSS 0.4%CVE-2022-42843HIGHThis issue was addressed with improved data protection. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watcEPSS 0.4%CVE-2025-26309MEDIUMA memory leak has been identified in the parseSWF_DEFINESCENEANDFRAMEDATA function in util/parser.c of libming v0.4.8, which allows attackerEPSS 0.4%CVE-2025-26310MEDIUMMultiple memory leaks have been identified in the ABC file parsing functions (parseABC_CONSTANT_POOL and `parseABC_FILE) in util/parser.c ofEPSS 0.4%CVE-2022-34351MEDIUMIBM QRadar SIEM information disclosureEPSS 0.4%CVE-2026-1556MEDIUMInformation disclosure via file URI overwrite in File (Field) PathsEPSS 0.4%CVE-2025-2881MEDIUMDeveloper Toolbar <= 1.0.3 - Unauthenticated Information ExposureEPSS 0.4%CVE-2025-26167HIGHBuffalo LS520D 4.53 is vulnerable to Arbitrary file read, which allows unauthenticated attackers to access the NAS web UI and read arbitraryEPSS 0.4%CVE-2026-33220MEDIUMWeblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repositoryEPSS 0.4%CVE-2026-54264HIGHAngular: Sensitive Header Leakage on Cross-Origin Redirects in Angular Service WorkerEPSS 0.4%CVE-2025-0659HIGHPath Traversal and Rockwell Automation Third-party Vulnerability in DataMosaix™ Private CloudEPSS 0.4%CVE-2026-56882HIGHIn Cellular Modem, there is a possible information disclosure due to a logic error in the code. This could lead to remote code execution witEPSS 0.4%CVE-2024-38749MEDIUMWordPress Olive One Click Demo Import plugin <= 1.1.2 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2025-2880MEDIUMYame | Link In Bio <= 0.9.0 - Unauthenticated Information ExposureEPSS 0.4%CVE-2026-4409MEDIUMSubscribe To Comments Reloaded <= 240119 - Improper Authorization to Unauthenticated Arbitrary Subscription ManagementEPSS 0.4%CVE-2026-56235MEDIUMCapgo - Unauthenticated Cross-Tenant Metrics Disclosure via RPC FunctionsEPSS 0.4%CVE-2026-8993MEDIUMImproper URL Handler Processing in D.Launcher 2 enables NTLM Credential Disclosure and SSRF attacksEPSS 0.4%