Fallos del tipo CWE-200

4993 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2022-3743MEDIUMA potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevatEPSS 0.2%CVE-2026-82850MEDIUMMasteriyo LMS < 3.4.2 - Subscriber+ Quiz Answer Key DisclosureEPSS 0.2%CVE-2026-70917MEDIUMVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.2%CVE-2026-70916MEDIUMVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.2%CVE-2022-38689MEDIUMIn telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privEPSS 0.2%CVE-2026-90953MEDIUMImage Optimizer by Elementor < 1.7.7 - Subscriber+ Attachment Metadata and Site Statistics Disclosure via Discarded REST Permission CallbacksEPSS 0.2%CVE-2026-10864MEDIUMMISP Dashboard widget field selection may expose restricted user and organisation dataEPSS 0.2%CVE-2026-10854MEDIUMUnauthorized exposure of private galaxies in MISP event template creationEPSS 0.2%CVE-2026-93662MEDIUMEvents Manager 7.4.1 - 7.4.4 - Subscriber+ Unpublished Event and Location Disclosure via 'owner' ParameterEPSS 0.2%CVE-2026-16557MEDIUMNimble Builder <= 3.3.8 - Subscriber+ Non-Public Content Disclosure via sek_get_nimble_content_for_seo_pluginsEPSS 0.2%CVE-2026-86602MEDIUMWP Recipe Maker 10.3.0 - 10.8.1 - Subscriber+ Draft and Private Recipe Content Disclosure via wprm_shortcode_previewEPSS 0.2%CVE-2021-26281MEDIUMInformation disclosure vulnerability in Alarm clock moduleEPSS 0.2%CVE-2026-86603MEDIUMWP Recipe Maker < 10.8.2 - Subscriber+ Non-Public List Title Disclosure via wprm_search_listsEPSS 0.2%CVE-2022-43540MEDIUMA vulnerability exists in the ClearPass OnGuard macOS agent that allows for an attacker with local macOS instance access to potentially obtaEPSS 0.2%CVE-2025-22895MEDIUMExposure of sensitive information to an unauthorized actor for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow aEPSS 0.2%CVE-2025-40646MEDIUMExposure of sensitive information in VidayEPSS 0.2%CVE-2025-57837LOWTileservice module is affected by information leak vulnerability, successful exploitation of this vulnerability may affect service confidentEPSS 0.2%CVE-2023-45219MEDIUMBIG-IP tmsh vulnerabilityEPSS 0.2%CVE-2025-40803LOWA vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions). The affected device exposes certain non-critical iEPSS 0.2%CVE-2026-45683LOWOpenTelemetry eBPF Instrumentation: Java TLS ioctl kprobe allows kernel memory disclosureEPSS 0.2%