Fallos del tipo CWE-200

4988 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2025-52372MEDIUMAn issue in hMailServer v.5.8.6 allows a local attacker to obtain sensitive information via the hmailserver/installation/hMailServerInnoExteEPSS 0.2%CVE-2026-13343MEDIUMUninitialised stack memory disclosure in the MIDI 2.0 UMP Stream responderEPSS 0.2%CVE-2025-26710LOWThere is an an information disclosure vulnerability in ZTE T5400. Due to improper configuration of the access control mechanism, attackers cEPSS 0.2%CVE-2025-52613MEDIUMHCL BigFix Service Management (SM) is affected by use of a vulnerable componentEPSS 0.2%CVE-2025-30291MEDIUMColdFusion | Information Exposure (CWE-200)EPSS 0.2%CVE-2025-46294MEDIUMTo enhance security, the FileMaker Server 22.0.4 installer now includes an option to disable IIS short filename enumeration by setting NtfsDEPSS 0.2%CVE-2026-100680HIGHBudibase before 3.45.0 Arbitrary Local File Read via OpenAPI ImportEPSS 0.2%CVE-2023-23500—The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.2, iOS 16.3 and iPadOS 16.3, iOS 15.7.3 and iEPSS 0.2%CVE-2022-22668—A logic issue was addressed with improved restrictions. This issue is fixed in iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3. A malicious apEPSS 0.2%CVE-2026-36618MEDIUMMercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 responds to version.bind CHAOS TXT queries, disclosing the DNS resolver software veEPSS 0.2%CVE-2020-9082LOWThere is an information disclosure vulnerability in several smartphones. The system has a logic judging error under certain scenario, the atEPSS 0.2%CVE-2026-19251MEDIUMUltimate Member < 2.13.0 - Unauthenticated Unapproved Comment Disclosure via Profile ActivityEPSS 0.2%CVE-2024-44163MEDIUMThe issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7. A malicious apEPSS 0.2%CVE-2026-76707MEDIUMUnauthenticated Information Disclosure in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.2%CVE-2026-8706MEDIUMSensitive user data could be leaked to other applications through Reader modeEPSS 0.2%CVE-2026-83560MEDIUMNew User Approve 3.1.0 - 3.2.9 - Unauthenticated PII Disclosure via Zapier API Key BypassEPSS 0.2%CVE-2025-54971LOWAn exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiADC 7.4.0, FortiADC 7.2 all versions, FortiADC EPSS 0.2%CVE-2024-44180LOWThe issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18. An attacker with physical access may be able to aEPSS 0.2%CVE-2024-54469MEDIUMThe issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, macOS VenturEPSS 0.2%CVE-2019-1762MEDIUMCisco IOS and IOS XE Software Information Disclosure VulnerabilityEPSS 0.2%