Fallos del tipo CWE-200

4981 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2026-62525MEDIUMVulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Quality Workbench HTML system). Supported versions that EPSS 0.3%CVE-2025-65957HIGHCore Bot is Leaking Sensitive Credentials in Logs, Errors, and MessagesEPSS 0.3%CVE-2025-13804MEDIUMnutzam NutzBoot Ethereum Wallet EthModule.java information disclosureEPSS 0.3%CVE-2025-61764MEDIUMVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.3%CVE-2026-61304MEDIUMVulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations). Supported versions that aEPSS 0.3%CVE-2025-62524MEDIUMPILOS Exposes PHP versionEPSS 0.3%CVE-2026-12117MEDIUMImproper access control in the social login connection endpoint in Devolutions Server 2026.2.5 allows an authenticated vault member to enuEPSS 0.3%CVE-2025-53840LOWIcinga DB Web Exposure of Sensitive Information to an Unauthorized Actor vulnerabilityEPSS 0.3%CVE-2025-24282MEDIUMA library injection issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4. An app may be able to modifEPSS 0.3%CVE-2021-20320—A flaw was found in s390 eBPF JIT in bpf_jit_insn in arch/s390/net/bpf_jit_comp.c in the Linux kernel. In this flaw, a local attacker with sEPSS 0.3%CVE-2025-30435MEDIUMThis issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.4. A sandboxed app may beEPSS 0.3%CVE-2025-51643LOWMeitrack T366G-L GPS Tracker devices contain an SPI flash chip (Winbond 25Q64JVSIQ) that is accessible without authentication or tamper protEPSS 0.3%CVE-2026-84127MEDIUMInformation disclosure in the WebExtensions component in Firefox for AndroidEPSS 0.3%CVE-2026-17928MEDIUMInappropriate implementation in DataTransfer in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data viaEPSS 0.3%CVE-2026-7999MEDIUMInappropriate implementation in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtain potentially sensitive informaEPSS 0.3%CVE-2026-79095MEDIUMInformation leak in Payments in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTMEPSS 0.3%CVE-2025-24226MEDIUMThe issue was addressed with improved checks. This issue is fixed in Xcode 16.3. A malicious app may be able to access private information.EPSS 0.3%CVE-2022-32825MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tEPSS 0.3%CVE-2026-87495MEDIUMInformation leak in Scroll in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to leaEPSS 0.3%CVE-2026-22001LOWVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions that are affected areEPSS 0.3%