Fallos del tipo CWE-200

4976 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2026-79125MEDIUMInformation leak in XR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML EPSS 0.3%CVE-2026-9912MEDIUMInappropriate implementation in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensEPSS 0.3%CVE-2026-84348MEDIUMInformation leak in MediaCapture in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to potentially leak sensitive informationEPSS 0.3%CVE-2025-12363CRITICALEmail Password DisclosureEPSS 0.3%CVE-2025-15482MEDIUMChapa Payment Gateway Plugin for WooCommerce <= 1.0.3 - Unauthenticated Sensitive Information ExposureEPSS 0.3%CVE-2023-5579LOWyhz66 Sandbox User Data information disclosureEPSS 0.3%CVE-2026-19406LOWEasy Appointments < 4.0.1 - Contributor+ Sensitive Information Disclosure via REST Appointments ListingEPSS 0.3%CVE-2025-24244MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, mEPSS 0.3%CVE-2026-14188LOWEasy Appointments < 3.12.28 - Contributor+ Customer Data DisclosureEPSS 0.3%CVE-2026-84926LOWEmbedPress 4.6.0 - 4.6.3 - Contributor+ Administrator Email Disclosure via Google Reviews REST RouteEPSS 0.3%CVE-2026-19858HIGHJetFormBuilder < 3.6.5.2 - Unauthenticated Password Hash and Arbitrary Metadata Disclosure via Dynamic PresetEPSS 0.3%CVE-2026-92423LOWMeow Gallery < 5.5.5 - Author+ Draft and Private Post Disclosure via fetch_postsEPSS 0.3%CVE-2026-61240HIGHVulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: eSettlements). The supporEPSS 0.3%CVE-2026-87836LOWComments Import & Export 2.1.11 - 2.5.3 - Author+ Comment PII Disclosure via ExportEPSS 0.3%CVE-2026-100723MEDIUMvm2 before 3.12.2 Memory Disclosure via zlib Buffer PoolEPSS 0.3%CVE-2026-89008LOWBookit < 2.6.0.5 - Bookit Staff+ Appointment PII DisclosureEPSS 0.3%CVE-2026-84903LOWKing Addons for Elementor < 51.1.81 - Contributor+ Private Post Content Disclosure via kng_maintenance_page ShortcodeEPSS 0.3%CVE-2024-9945MEDIUMLimited Information Disclosure in GoAnywhere MFT Prior to 7.7.0EPSS 0.3%CVE-2025-58458MEDIUMIn Jenkins Git client Plugin 6.3.2 and earlier, except 6.1.4 and 6.2.1, Git URL field form validation responses differ based on whether the EPSS 0.3%CVE-2026-6392LOWTanium addressed an information disclosure vulnerability in Threat Response.EPSS 0.3%