Fallos del tipo CWE-200

4960 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2024-36122LOWDiscourse doesn't limit reviewable user serializer payloadEPSS 0.4%CVE-2026-55180MEDIUMpnpm: Repository config can expand victim environment secrets into registry requests before scripts runEPSS 0.4%CVE-2025-62721HIGHLinkAce: Authorization Bypass Allows Unauthorized Access to All Private Links, Lists, and TagsEPSS 0.4%CVE-2024-12159MEDIUMOptimize Your Campaigns – Google Shopping – Google Ads – Google Adwords <= 3.1 - Information ExposureEPSS 0.4%CVE-2026-8026MEDIUMFlowiseAI Flowise API Response account.service.ts login information disclosureEPSS 0.4%CVE-2025-40940MEDIUMA vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected application exhibits inconsistent SNMP behaviorEPSS 0.4%CVE-2015-7946HIGHMTP service exposed during emergency dialerEPSS 0.4%CVE-2025-13765MEDIUMExposure of email service credentials to users without administrative rights in Devolutions Server.This issue affects Devolutions Server: beEPSS 0.4%CVE-2022-32540HIGHInformation Disclosure in Operator Client application in BVMS 10.1.1, 11.0 and 11.1.0 and VIDEOJET Decoder VJD-7513 versions 10.23 and 10.30EPSS 0.4%CVE-2021-37192MEDIUMA vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The affected software has an information discEPSS 0.4%CVE-2024-35710MEDIUMWordPress Podlove Web Player plugin <= 5.7.3 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2025-1714MEDIUMUsername Enumeration in GliffyEPSS 0.4%CVE-2024-53245LOWInformation Disclosure due to Username Collision with a Role that has the same Name as the UserEPSS 0.4%CVE-2021-37190MEDIUMA vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The affected software has an information discEPSS 0.4%CVE-2024-38742MEDIUMWordPress MBE eShip plugin <= 2.1.2 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2025-22227MEDIUMCVE-2025-22227: Authentication Leak On Redirect With Reactor Netty HTTP ClientEPSS 0.4%CVE-2024-47344MEDIUMWordPress uListing plugin <= 2.1.5 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2026-33041MEDIUMAVideo has an Unauthenticated Password Hash Oracle via encryptPass.json.phpEPSS 0.4%CVE-2024-38756MEDIUMWordPress Coming Soon Page – Responsive Coming Soon & Maintenance Mode plugin <= 1.6.3 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2026-2207MEDIUMWeKan Activity Publication activities.js LinkedBoardActivitiesBleed information disclosureEPSS 0.4%