Fallos del tipo CWE-200

4985 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2025-55342MEDIUMQuipux 4.0.1 through e1774ac allows enumeration of usernames, and accessing the Ecuadorean identification number for all registered users viEPSS 0.2%CVE-2026-0905CRITICALInsufficient policy enforcement in Network in Google Chrome prior to 144.0.7559.59 allowed an attack who obtained a network log file to poteEPSS 0.2%CVE-2025-5281MEDIUMInappropriate implementation in BFCache in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially obtain user informaEPSS 0.2%CVE-2026-100710MEDIUMFroxlor before 2.3.12 DKIM Private Key Disclosure via APIEPSS 0.2%CVE-2026-20682MEDIUMA logic issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. AEPSS 0.2%CVE-2026-95312LOWInformation leak in Passwords in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to EPSS 0.2%CVE-2021-3736—A flaw was found in the Linux kernel. A memory leak problem was found in mbochs_ioctl in samples/vfio-mdev/mbochs.c in Virtual Function I/O EPSS 0.2%CVE-2024-54463MEDIUMThis issue was addressed with improved entitlements. This issue is fixed in macOS Sequoia 15. An app may be able to access removable volumesEPSS 0.2%CVE-2026-21999MEDIUMVulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.1. Difficult tEPSS 0.2%CVE-2024-36955HIGHALSA: hda: intel-sdw-acpi: fix usage of device_get_named_child_node()EPSS 0.2%CVE-2026-36602MEDIUMMercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 discloses kernel memory layout via the UPnP GetStatusInfo action. An unautheEPSS 0.2%CVE-2026-100528MEDIUMOpenClaw before 2026.8.1 Credential Disclosure via Provider EndpointEPSS 0.2%CVE-2026-55824LOWContao crawler leaks auth credentials to external hostsEPSS 0.2%CVE-2026-22015MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions that are affected areEPSS 0.2%CVE-2026-36615MEDIUMMercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 exposes an undocumented /agileconfigreset endpoint that returns internal buffer conEPSS 0.2%CVE-2025-43455MEDIUMA privacy issue was addressed with improved checks. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOEPSS 0.2%CVE-2025-64427HIGHZimaOS is vulnerable to Server-Side Request Forgery (SSRF)EPSS 0.2%CVE-2026-21784MEDIUMHCL IntelliOps Event Management is affected by multiple security vulnerabilities.EPSS 0.2%CVE-2026-64892MEDIUM- Exposure of Sensitive Information vulnerability in Johnson Controls Easy IO Neo allows Collect Data from Common Resource Locations. This EPSS 0.2%CVE-2026-100594HIGHOpenClaw before 2026.7.1 Authorization Bypass via trajectory exportEPSS 0.2%