Fallos del tipo CWE-200

4974 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2020-4927MEDIUMIBM Spectrum Scale information disclosureEPSS 0.3%CVE-2026-100543HIGHOpenClaw before 2026.8.1 Information Disclosure via Configuration HashEPSS 0.3%CVE-2024-37991MEDIUMA vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6EPSS 0.3%CVE-2025-12468MEDIUMFunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce <= 3.6.4.1 - Unauthenticated Sensitive Information ExposureEPSS 0.3%CVE-2024-23557LOWHCL Connections is vulnerable to a user enumeration vulnerabilityEPSS 0.3%CVE-2026-74971MEDIUMInformation disclosure in the DOM: UI Events & Focus Handling componentEPSS 0.3%CVE-2025-59833HIGHFlagForgeCTF Hint Exposure via APIEPSS 0.3%CVE-2026-74972MEDIUMInformation disclosure in the DOM: Push Subscriptions componentEPSS 0.3%CVE-2025-11145HIGHUser Enumeration in CBK Soft's enVisionEPSS 0.3%CVE-2026-13402MEDIUMRoyal Elementor Addons < 1.7.1063 - Unauthenticated Private Mega Menu Template DisclosureEPSS 0.3%CVE-2026-81197MEDIUMMasterStudy LMS < 3.7.46 - Unauthenticated Unpublished Course Title Disclosure via course-list REST RouteEPSS 0.3%CVE-2026-61392MEDIUMThere is a information disclosure vulnerability in some Hikvision cameras, allowing unauthenticated attackers to obtain partial information EPSS 0.3%CVE-2026-16612MEDIUMFiboSearch < 1.34.1 - Unauthenticated Password-Protected Product Information DisclosureEPSS 0.3%CVE-2026-78151MEDIUMFormLayer < 1.0.9 - Unauthenticated Form Configuration Disclosure via Form Submission ResponseEPSS 0.3%CVE-2026-81195MEDIUMMasterStudy LMS < 3.7.46 - Unauthenticated Student Enrollment Disclosure via student-courses REST RouteEPSS 0.3%CVE-2026-87916MEDIUMWPBot 8.4.9 - 8.5.9 - Unauthenticated Chat Visitor PII DisclosureEPSS 0.3%CVE-2026-77758MEDIUMStripe Payment Forms by WP Full Pay < 8.5.1 - Unauthenticated Customer Portal Subscription and Billing Data Disclosure via Unconfirmed SessionEPSS 0.3%CVE-2024-23228MEDIUMThis issue was addressed through improved state management. This issue is fixed in iOS 17.3 and iPadOS 17.3. Locked Notes content may have bEPSS 0.3%CVE-2026-86449MEDIUMLearnPress < 4.4.7 - Unauthenticated Unpublished Course Disclosure via REST APIEPSS 0.3%CVE-2026-82124MEDIUMSchema & Structured Data for WP & AMP < 1.66 - Unauthenticated Password-Protected Post Content Disclosure via JSON-LD Schema OutputEPSS 0.3%