Falhas do tipo CWE-200

4.940 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2026-68852MEDIUMMicrosoft Account Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-47394HIGHPraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validateEPSS 0.5%CVE-2026-18995MEDIUMnetease-youdao LobsterAI MEDIA Path artifactParser.ts parseMediaTokensFromText information disclosureEPSS 0.5%CVE-2025-43986CRITICALAn issue was discovered on KuWFi GC111 GC111-GL-LM321_V3.0_20191211 devices. The TELNET service is enabled by default and exposed over the WEPSS 0.5%CVE-2024-45043MEDIUMOpenTelemetry Collector AWS Firehose Receiver Authentication Bypass VulnerabilityEPSS 0.5%CVE-2025-49184HIGHInformation disclosure to unauthorized userEPSS 0.5%CVE-2026-57095MEDIUMWin32k Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2023-28221HIGHWindows Error Reporting Service Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2020-13523LOWAn exploitable information disclosure vulnerability exists in SoftPerfect’s RAM Disk 4.1 spvve.sys driver. A specially crafted I/O request pEPSS 0.5%CVE-2026-71424CRITICALOnyx: Cross-user OAuth-token leak via /api/mcp/servers* for per-user MCP serversEPSS 0.5%CVE-2024-1302HIGHMultiple Vulnerabilities in Badger Meter's MonitoolEPSS 0.5%CVE-2025-29629CRITICALGardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 use weak defaEPSS 0.5%CVE-2026-30233MEDIUMOliveTin: View permission not being checked when returning dashboardsEPSS 0.5%CVE-2023-38718LOWIBM Robotic Process Automation information disclosureEPSS 0.5%CVE-2026-86059CRITICALDokploy: Git Provider Credential Exposure via Unprotected .one Endpoints and application.oneEPSS 0.5%CVE-2022-48510—Input verification vulnerability in the AMS module. Successful exploitation of this vulnerability will cause unauthorized operations.EPSS 0.5%CVE-2025-9398MEDIUMYiFang CMS Migrate.php exportInstallTable information disclosureEPSS 0.5%CVE-2025-9842MEDIUMDas Parking Management System 停车场管理系统 Search information disclosureEPSS 0.5%CVE-2023-51787HIGHAn issue was discovered in Wind River VxWorks 7 22.09 and 23.03. If a VxWorks task or POSIX thread that uses OpenSSL exits, limited per-taskEPSS 0.5%CVE-2025-9843MEDIUMDas Parking Management System 停车场管理系统 FindAll information disclosureEPSS 0.5%