Fallos del tipo CWE-200

4975 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2025-68718MEDIUMKAYSUS KS-WR1200 routers with firmware 107 expose SSH and TELNET services on the LAN interface with hardcoded root credentials (root:1234567EPSS 0.3%CVE-2025-24270MEDIUMThis issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4EPSS 0.3%CVE-2026-25125MEDIUMOctober CMS: Environment Variable Exfiltration via INI Parser InterpolationEPSS 0.3%CVE-2020-3541MEDIUMCisco Webex Meetings Client for Windows, Webex Meetings Desktop App, and Webex Teams Information Disclosure VulnerabilityEPSS 0.3%CVE-2026-9129CRITICALPath Traversal in Altium Enterprise Server Viewer StorageController Allows Arbitrary File ReadEPSS 0.3%CVE-2017-12315—A vulnerability in system logging when replication is being configured with the Cisco HyperFlex System could allow an authenticated, local aEPSS 0.3%CVE-2026-28506MEDIUMOutline's Information Disclosure in Activity Logs allows User Enumeration of Private DraftsEPSS 0.3%CVE-2026-34244MEDIUMWeblate: SSRF via Project-Level Machinery ConfigurationEPSS 0.3%CVE-2024-28164MEDIUMInformation Disclosure vulnerability in SAP NetWeaver AS Java (Guided Procedures)EPSS 0.3%CVE-2026-34092LOWBlock UI elements in 'tools'-sidebar shows presence of an autoblocked IPEPSS 0.3%CVE-2025-3104MEDIUMWP Staging Pro <= 6.1.2 - Unauthenticated Information Exposure via getOutdatedPluginsRequest FunctionEPSS 0.3%CVE-2026-21928MEDIUMVulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exEPSS 0.3%CVE-2025-12585MEDIUMMxChat – AI Chatbot for WordPress <= 2.5.5 - Unauthenticated Information ExposureEPSS 0.3%CVE-2026-18486HIGHIBM ContextForge MCP Gateway is affected by credential disclosure and privilege escalation via jq filter executionEPSS 0.3%CVE-2025-6722MEDIUMBitFire <= 4.5 - Unauthenticated Information ExposureEPSS 0.3%CVE-2025-29992HIGHMahara before 24.04.9 exposes database connection information if the database becomes unreachable, e.g., due to the database server being teEPSS 0.3%CVE-2025-52268HIGHStarCharge Artemis AC Charger 7-22 kW v1.0.4 was discovered to contain a hardcoded AES key which allows attackers to forge or decrypt valid EPSS 0.3%CVE-2025-60739CRITICALCross Site Request Forgery (CSRF) vulnerability in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before, Logic Version v6.00 - 20EPSS 0.3%CVE-2026-20298MEDIUMSensitive Information Disclosure through the storage/passwords REST Endpoint in Splunk EnterpriseEPSS 0.3%CVE-2026-50009MEDIUMNetty QUIC stateless reset token material exposed through header-visible connection IDsEPSS 0.3%