Fallos del tipo CWE-200

4959 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2024-23493MEDIUM Team associated AD/LDAP Groups Leaked due to missing authorizationEPSS 0.4%CVE-2025-28235HIGHAn information disclosure vulnerability in the component /socket.io/1/websocket/ of Soundcraft Ui Series Model(s) Ui12 and Ui16 Firmware v1.EPSS 0.4%CVE-2026-8993MEDIUMImproper URL Handler Processing in D.Launcher 2 enables NTLM Credential Disclosure and SSRF attacksEPSS 0.4%CVE-2026-32814MEDIUMlibheif: Uninitialized Heap Memory Information Leak via Failed Grid TilesEPSS 0.4%CVE-2024-43258MEDIUMWordPress Store Locator Plus® for WordPress plugin <= 2311.17.01 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2025-9774MEDIUMRemoteClinic edit-patient.php information disclosureEPSS 0.4%CVE-2022-24886LOWExposure of Sensitive Information to an Unauthorized Actor in com.nextcloud.clientEPSS 0.4%CVE-2026-27481MEDIUMDiscourse: Hidden tag visibility bypass on tag routesEPSS 0.4%CVE-2025-20336MEDIUMCisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Firmware Information Disclosure VulnerabilityEPSS 0.4%CVE-2017-12361—A vulnerability in Cisco Jabber for Windows could allow an unauthenticated, local attacker to access sensitive communications made by the JaEPSS 0.4%CVE-2026-58511LOWWebhook Authorization Header Returned in Plaintext via APIEPSS 0.4%CVE-2026-6756HIGHMitigation bypass in Firefox for AndroidEPSS 0.4%CVE-2025-13683MEDIUMExposure of credentials in unintended requests in Devolutions Server, Remote Desktop Manager on Windows.This issue affects Devolutions ServeEPSS 0.4%CVE-2024-26132MEDIUMElement Android can be asked to share internal files.EPSS 0.4%CVE-2026-19992LOWOrange View Limited DualSafe Password Manager & Digital Vault Extension postMessage-based Bridge information disclosureEPSS 0.4%CVE-2026-62473HIGHVulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that arEPSS 0.4%CVE-2026-7382MEDIUMInformation Disclosure in MeWare Software's PDKSEPSS 0.4%CVE-2026-84195HIGHKyverno before 1.16.4 Credential Leak via apiCallEPSS 0.4%CVE-2026-27892MEDIUMFacturaScripts: Unstripped Image Metadata (EXIF) Leakage via Library Module File Upload/DownloadEPSS 0.4%CVE-2025-2578MEDIUMBooking for Appointments and Events Calendar – Amelia <= 1.2.19 - Unauthenticated Full Path DisclosureEPSS 0.4%