Fallos del tipo CWE-200

4960 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2026-46370MEDIUMFleet has observer-level enrollment secret extraction via ORDER BY oracle on labels host-listing endpointEPSS 0.4%CVE-2026-13168MEDIUMEventin < 4.1.20 - Contributor+ Customer PII Disclosure via REST APIEPSS 0.4%CVE-2026-18943MEDIUMWPC Admin Columns < 2.3.4 - Subscriber+ Arbitrary User/Post/Term Meta DisclosureEPSS 0.4%CVE-2026-83287HIGHVulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Presentation Services). SupporEPSS 0.4%CVE-2026-16108MEDIUMKeycloak-services: keycloak-services: realm default-group reads disclose hidden groups under fgap v2EPSS 0.4%CVE-2024-13042MEDIUMTsinghua Unigroup Electronic Archives Management System download.html download information disclosureEPSS 0.4%CVE-2021-22783HIGHA CWE-200: Information Exposure vulnerability exists which could allow a session hijack when the door panel is communicating with the door. EPSS 0.4%CVE-2024-39919LOWCapture screenshot of localhost web services (unauthenticated pages) in @jmondi/url-to-pngEPSS 0.4%CVE-2025-22956CRITICALOPSI before 4.3 allows any client to retrieve any ProductPropertyState, including those of other clients. This can lead to privilege escalatEPSS 0.4%CVE-2025-43323HIGHThis issue was addressed with additional entitlement checks. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS EPSS 0.4%CVE-2026-58026NONE$wgNonincludableNamespaces can be bypassed by embedding redirect in other namespacesEPSS 0.4%CVE-2025-6590MEDIUMComplete content leak of private wikis due to PasswordReset Wikitext injection in error messageEPSS 0.4%CVE-2026-46443HIGHFlowise: Credential Data LeakEPSS 0.4%CVE-2025-13785MEDIUMyungifez Skuul School Management System Image profile information disclosureEPSS 0.4%CVE-2025-30352MEDIUMDirectus `search` query parameter allows enumeration of non permitted fieldsEPSS 0.4%CVE-2025-11997MEDIUMDocument Pro Elementor – Documentation & Knowledge Base <= 1.0.9 - Unauthenticated Information ExposureEPSS 0.4%CVE-2026-58024MEDIUMAPI identification of users on private wikisEPSS 0.4%CVE-2025-62720HIGHLinkAce: Data Exfiltration via Export Functions Allow Access to All Users' Private LinksEPSS 0.4%CVE-2026-85188MEDIUMJoomla Extension - regularlabs.com - Database data disclosure in Advanced Module Manager (Free, Pro) < 12.1.0, Conditional Content (Free, Pro) < 8.0.0, Content Templater (Pro) < 14.2.0, ReReplacer (Pro) < 16.2.0 for JoomlaEPSS 0.4%CVE-2025-8738MEDIUMzlt2000 microservices-platform Spring Actuator Interface actuator information disclosureEPSS 0.4%