Fallos del tipo CWE-200

4970 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2025-13526HIGHOneClick Chat to Order <= 1.0.8 - Insecure Direct Object Reference to Unauthenticated Sensitive Information ExposureEPSS 0.4%CVE-2026-45739LOWStrawberry GraphQL: Default GraphiQL may expose HTTP headers in URLsEPSS 0.4%CVE-2026-61782HIGH@rsdoctor/rspack-plugin has Unauthenticated HTTP API that Exposes Project Source Code and Build MetadataEPSS 0.4%CVE-2023-43995MEDIUMAn issue in picot.golf mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access tEPSS 0.4%CVE-2023-43992MEDIUMAn issue in STOCKMAN GROUP mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel acceEPSS 0.4%CVE-2023-43997MEDIUMAn issue in Yoruichi hobby base mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channelEPSS 0.4%CVE-2023-48130MEDIUMAn issue in GINZA CAFE mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access tEPSS 0.4%CVE-2025-20325LOWSensitive Information Disclosure in the SHCConfig logging channel in Clustered Deployments in Splunk EnterpriseEPSS 0.4%CVE-2025-14574MEDIUMweDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= 2.1.15 - Unauthenticated Sensitive Information ExposureEPSS 0.4%CVE-2023-48129MEDIUMAn issue in kimono-oldnew mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel accesEPSS 0.4%CVE-2023-48132MEDIUMAn issue in kosei entertainment esportsstudioLegends mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via lEPSS 0.4%CVE-2023-48131MEDIUMAn issue in CHIGASAKI BAKERY mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel acEPSS 0.4%CVE-2023-48135MEDIUMAn issue in mimasaka_farm mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel accesEPSS 0.4%CVE-2024-1405MEDIUMLinksys WRT54GL Web Management Interface wlaninfo.htm information disclosureEPSS 0.4%CVE-2026-50105MEDIUMRSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)EPSS 0.4%CVE-2019-1815HIGHCisco Meraki MX67 and MX68 Sensitive Information Disclosure VulnerabilityEPSS 0.4%CVE-2022-4862MEDIUMXSS vulnerability in M-Files WebEPSS 0.4%CVE-2026-6728MEDIUMSlider Revolution <= 7.0.9 - Unauthenticated Sensitive Information Exposure via 'sliders/stream'EPSS 0.4%CVE-2026-53949MEDIUMGhost Content API filter bypass reveals private fieldsEPSS 0.4%CVE-2025-63212MEDIUMGatesAir Flexiva-LX devices on firmware 1.0.13 and 2.0, including models LX100, LX300, LX600, and LX1000, expose sensitive session identifieEPSS 0.4%