Fallos del tipo CWE-200

5021 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2026-41980MEDIUMPermission control vulnerability in the file preview module. Impact: Successful exploitation of this vulnerability may affect service confidEPSS 0.1%CVE-2026-22007LOWVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: SecuritEPSS 0.1%CVE-2025-10222MEDIUMSensitive Information Disclosure in Diagnostic Dumps in AxxonSoft Axxon One VMSEPSS 0.1%CVE-2026-49301MEDIUMPermission control vulnerability in the Gallery module. Impact: Successful exploitation of this vulnerability may affect service confidentiaEPSS 0.1%CVE-2026-78957MEDIUMInformation leak in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to obtain sensitive information via a EPSS 0.1%CVE-2026-79146MEDIUMInformation leak in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to obtain cross-origin data viEPSS 0.1%CVE-2024-58252MEDIUMVulnerability of insufficient information protection in the media library module Impact: Successful exploitation of this vulnerability may aEPSS 0.1%CVE-2022-39856MEDIUMImproper access control vulnerability in imsservice application prior to SMR Oct-2022 Release 1 allows local attackers to access call informEPSS 0.1%CVE-2026-20681LOWA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Tahoe 26.3. An app may be aEPSS 0.1%CVE-2025-66963MEDIUMAn issue in Hitron HI3120 v.7.2.4.5.2b1 allows a local attacker to obtain sensitive information via the Logout option in the index.htmlEPSS 0.1%CVE-2022-22075MEDIUMInformation Exposure in GraphicsEPSS 0.1%CVE-2025-8304MEDIUMInformation Disclosure in Identity Agent Registry KeysEPSS 0.1%CVE-2026-73732MEDIUMLocal Authenticated Sensitive Information Disclosure in HPE Networking Fabric ComposerEPSS 0.1%CVE-2025-8305MEDIUMInformation Disclosure in Identity Agent Debug FilesEPSS 0.1%CVE-2026-20737MEDIUMExposure of sensitive information to an unauthorized actor for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: DeviceEPSS 0.1%CVE-2025-65951HIGHInside Track / Entropy Derby Timelock Encryption Bypassed via Pre-Computed VDF Output LeakageEPSS 0.1%CVE-2022-0882MEDIUMIllegal access to Kernel log in Fuchsia EPSS 0.1%CVE-2024-53011HIGHPermissions, Privileges, and Access Controls in Video Analytics and ProcessingEPSS 0.1%CVE-2022-39903MEDIUMImproper access control vulnerability in RCS call prior to SMR Dec-2022 Release 1 allows local attackers to access RCS incoming call number.EPSS 0.1%CVE-2026-73738MEDIUMAuthenticated Sensitive Information Disclosure in HPE Networking Fabric ComposerEPSS 0.1%