Fallos del tipo CWE-200

4959 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2025-51040HIGHElectrolink FM/DAB/TV Transmitter Web Management System Unauthorized access vulnerability via the /FrameSetCore.html endpoint in ElectrolinkEPSS 0.4%CVE-2024-34991HIGHIn the module "Axepta" (axepta) before 1.3.4 from Quadra Informatique for PrestaShop, a guest can download partial credit card information (EPSS 0.4%CVE-2026-8405MEDIUMIBM Guardium Data Protection is affected by Exposure of Sensitive Information vulnerabilityEPSS 0.4%CVE-2026-56839HIGHPraisonAI Code agent tools fail open without a workspace boundaryEPSS 0.4%CVE-2026-10128MEDIUMLangflow is affected by weaknesses in secret handling and sensitive configuration accessEPSS 0.4%CVE-2017-15112—keycloak-httpd-client-install versions before 0.8 allow users to insecurely pass password through command line, leaking it via command histoEPSS 0.4%CVE-2023-41354MEDIUMChunghwa Telecom NOKIA G-040W-Q - Exposure of Sensitive InformationEPSS 0.4%CVE-2023-52101CRITICALComponent exposure vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect service availability and inteEPSS 0.4%CVE-2025-10744MEDIUMFile Manager, Code editor, backup by Managefy <= 1.6.1 - Unauthenticated Information ExposureEPSS 0.4%CVE-2026-84143CRITICALInternally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15EPSS 0.4%CVE-2023-23629MEDIUMMetabase subject to Improper Privilege ManagementEPSS 0.4%CVE-2024-8902MEDIUMElementor Addon Elements <= 1.13.8 - Authenticated (Contributor+) Sensitive Information Exposure via table_saved_sectionsEPSS 0.4%CVE-2025-2331MEDIUMGiveWP – Donation Plugin and Fundraising Platform <= 3.22.1 - Authenticated (Subscriber+) Sensitive Information ExposureEPSS 0.4%CVE-2024-8913MEDIUMThe Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.6.11 - Authenticated (Contributor+) Sensitive Information Exposure via content_templateEPSS 0.4%CVE-2026-56729LOWZammad: Titles of knowledge base answers will be shown across all categories via the global searchEPSS 0.4%CVE-2024-32037NONEGeoNetwork vulnerable to search end-point information disclosure in response headersEPSS 0.4%CVE-2023-5515MEDIUM The responses for web queries with certain parameters disclose internal path of resources. This information can be used to learn internal sEPSS 0.4%CVE-2026-87076MEDIUMTanium addressed an information disclosure vulnerability in Discover.EPSS 0.4%CVE-2023-28900MEDIUMNickname Disclosure on the Backend Automotive ServerEPSS 0.4%CVE-2026-31262MEDIUMCross Site Scripting vulnerability in Altenar Sportsbook Software Platform (SB2) v.2.0 allows a remote attacker to obtain sensitive informatEPSS 0.4%