Falhas do tipo CWE-200

4.948 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2025-24373MEDIUMUnrestricted Access to PDF Documents via URL Manipulation in woocommerce-pdf-invoices-packing-slipsEPSS 0.4%CVE-2025-70829MEDIUMAn information exposure vulnerability in Datart v1.0.0-rc.3 allows authenticated attackers to access sensitive data via a custom H2 JDBC conEPSS 0.4%CVE-2024-12140MEDIUMElementor AI Addons – 70 Widgets, Premium Templates, Ultimate Elements <= 2.2.1 - Authenticated (Contributor+) Private Templates Content DisclosureEPSS 0.4%CVE-2021-46891—Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affeEPSS 0.4%CVE-2021-36096MEDIUMSupport Bundle includes S/Mime and PGP secret or PINEPSS 0.4%CVE-2023-41676MEDIUMAn exposure of sensitive information to an unauthorized actor [CWE-200] in FortiSIEM version 7.0.0 and before 6.7.5 may allow an attacker wEPSS 0.4%CVE-2026-9836LOWIBM DataStage Flow Designer application is affected by an information disclosure vulnerabilityEPSS 0.4%CVE-2020-9846—A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.0.1. A malicious application may be ablEPSS 0.4%CVE-2024-6570MEDIUMGlossary <= 2.2.26 - Unauthenticated Full Path DisclosureEPSS 0.4%CVE-2026-84135CRITICALOther issue in Firefox Focus for AndroidEPSS 0.4%CVE-2026-54553MEDIUMStarlette-Admin: Unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoSEPSS 0.4%CVE-2024-6567MEDIUMEbook Store <= 5.8001 - Unauthenticated Full Path DisclosureEPSS 0.4%CVE-2026-34984HIGHExternal Secrets Operator has DNS exfiltration via getHostByName in its v2 template engineEPSS 0.4%CVE-2024-6546MEDIUMOne Click Close Comments <= 2.7.1 - Unauthenticated Full Path DisclosureEPSS 0.4%CVE-2024-43289HIGHWordPress wpForo Forum plugin <= 2.3.4 - Unauthenticated Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2023-3455—Key management vulnerability on system. Successful exploitation of this vulnerability may affect service availability and integrity.EPSS 0.4%CVE-2026-78378MEDIUMRedis Glob Pattern Injection Allows Unauthorized Enumeration of Private Ransomlook DataEPSS 0.4%CVE-2024-38761HIGHWordPress Zephyr Project Manager plugin <= 3.3.99 - Sensitive Data Exposure via Export File vulnerabilityEPSS 0.4%CVE-2024-38747HIGHWordPress HitPay Payment Gateway for WooCommerce plugin <= 4.1.3 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.4%CVE-2024-13525MEDIUMCustomer Email Verification for WooCommerce <= 2.9.4 - Authenticated (Contributor+) Sensitive Information ExposureEPSS 0.4%