Fallos del tipo CWE-200

5032 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2026-43942MEDIUMelecterm: Full process.env exposed to renderer via window.pre.env in electermEPSS 0.1%CVE-2025-68467LOWDark Reader gives users the ability to request style sheets from local web serversEPSS 0.1%CVE-2026-58554MEDIUMPermission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiEPSS 0.1%CVE-2023-21267—In multiple functions of KeyguardViewMediator.java, there is a possible way to bypass lockdown mode with screen pinning due to a logic errorEPSS 0.1%CVE-2024-20292MEDIUMA vulnerability in the logging component of Cisco Duo Authentication for Windows Logon and RDP could allow an authenticated, local attacker EPSS 0.1%CVE-2026-63269MEDIUMLFI and GET SSRF via GStreamer and HLS playlistsEPSS 0.1%CVE-2026-79055MEDIUMInformation leak in Sharing in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker leveraging social engineering to EPSS 0.1%CVE-2026-78806MEDIUMAn issue in Matter Standard Specification-Implementation gap v1.5.1 Matter Project Chip V1.5.1 allows a local attacker to obtain sensitive iEPSS 0.1%CVE-2025-54615MEDIUMVulnerability of insufficient information protection in the media library module. Impact: Successful exploitation of this vulnerability may EPSS 0.1%CVE-2024-20503MEDIUMCisco Duo Epic for Hyperdrive Information Disclosure VulnerabilityEPSS 0.1%CVE-2021-25357MEDIUMA pendingIntent hijacking vulnerability in Create Movie prior to SMR APR-2021 Release 1 in Android O(8.x) and P(9.0), 3.4.81.1 in Android Q(EPSS 0.1%CVE-2024-0020MEDIUMIn onActivityResult of NotificationSoundPreference.java, there is a possible way to hear audio files belonging to a different user due to a EPSS 0.1%CVE-2025-65104HIGHFirebird: Information leak vulnerability in firebird3 client when used with newer serverEPSS 0.1%CVE-2025-58278MEDIUMIdentity authentication bypass vulnerability in the Gallery app. Successful exploitation of this vulnerability may affect service confidentiEPSS 0.1%CVE-2025-48635HIGHIn multiple functions of TaskFragmentOrganizerController.java, there is a possible activity token leak due to a logic error in the code. ThiEPSS 0.1%CVE-2026-11459MEDIUMSecureAge CatchPulse IOCTL saappctl.sys information disclosureEPSS 0.1%CVE-2026-0025HIGHIn hasImage of Notification.java, there is a possible way to reveal information across users due to a permissions bypass. This could lead toEPSS 0.1%CVE-2026-102709HIGHImproper validation of non-secure (NS) pointers in multiple TrustZone-M non-secure callable (NSC) entry functions allows an attacker executiEPSS 0.1%CVE-2024-58049MEDIUMPermission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service cEPSS 0.1%CVE-2018-9384MEDIUMIn multiple locations, there is a possible way to bypass KASLR due to an unusual root cause. This could lead to local information disclosureEPSS 0.1%