Fallos del tipo CWE-200

5017 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2026-28682MEDIUMGokapi: Data Leak in Upload Status StreamEPSS 0.2%CVE-2024-2728MEDIUMInformation exposure vulnerability in the CIGESv2 systemEPSS 0.2%CVE-2026-35143LOWHCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability.EPSS 0.2%CVE-2023-32476MEDIUM Dell Hybrid Client version 2.0 contains a Sensitive Data Exposure vulnerability. An unauthenticated malicious user on the device can accessEPSS 0.2%CVE-2025-8886MEDIUMAuthorization Bypass in Usta Information Systems' Aybs InteraktifEPSS 0.2%CVE-2026-84576MEDIUMThis issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app mayEPSS 0.2%CVE-2026-17515MEDIUMMLS Import < 7.0.4 - Subscriber+ Sensitive Information Disclosure via mlsimport_logger_per_itemEPSS 0.2%CVE-2021-26279MEDIUMInformation disclosure vulnerability in Weather moduleEPSS 0.2%CVE-2025-64312MEDIUMPermission control vulnerability in the file management module. Impact: Successful exploitation of this vulnerability may affect service conEPSS 0.2%CVE-2025-9036HIGHRockwell Automation FactoryTalk® Action Manager v1.0.0 Runtime VulnerabilityEPSS 0.2%CVE-2026-73230MEDIUMEnte: 2of3 cards v1 contain a checksum that enables offline guessing of low-entropy secretsEPSS 0.2%CVE-2025-33045HIGHLegacy Serial Redirection SMRAM VulnerabilitiesEPSS 0.2%CVE-2026-90503MEDIUMChengdu Qilu Technology Ludashi ComputerZ_x64.sys sub_11008 information disclosureEPSS 0.2%CVE-2021-22529MEDIUMSensitive Data Exposure leaks potential information in NetIQ Advance AuthenticationEPSS 0.2%CVE-2026-20674MEDIUMA privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 26.3 and iPadOS 26.3. An attacker with physical access EPSS 0.2%CVE-2025-31985LOWHCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” headerEPSS 0.2%CVE-2025-43345MEDIUMA correctness issue was addressed with improved checks. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS SequoiaEPSS 0.2%CVE-2026-43756MEDIUMA logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. AnEPSS 0.2%CVE-2026-102267HIGHPyJWT: PyJWKClient follows redirects when fetching JWKSEPSS 0.2%CVE-2026-86887LOWA privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, visionOS 27EPSS 0.2%