Falhas do tipo CWE-200

4.951 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2026-19717HIGHCatFolders Document Gallery < 2.0.7 - Unauthenticated Attachment Disclosure via REST APIEPSS 0.4%CVE-2026-16988HIGHGeoDirectory < 2.8.169 - Unauthenticated Pending/Draft Listing Disclosure via markers REST EndpointEPSS 0.4%CVE-2026-15048HIGHGeekyBot < 1.2.8 - Unauthenticated Sensitive Information Exposure via Chat HistoryEPSS 0.4%CVE-2026-15236HIGHGallery for Google Photos < 1.2.1 - Unauthenticated Google OAuth Token DisclosureEPSS 0.4%CVE-2026-18470HIGHLogin & Register Forms < 4.0.2 - Unauthenticated Registered User Email Address Disclosure via Lost Password ResponseEPSS 0.4%CVE-2026-16604HIGHContent Protector (Passster) < 4.3.6 - Unauthenticated Protected Content Disclosure via Content-Lock Block data-content AttributeEPSS 0.4%CVE-2026-16602HIGHContent Protector (Passster) < 4.3.6 - Unauthenticated Non-Public Post Content Disclosure via Captcha REST EndpointEPSS 0.4%CVE-2026-18049HIGHWP Photo Album Plus < 9.2.07.002 - Unauthenticated Option Disclosure via gettogoEPSS 0.4%CVE-2026-16253HIGHTotal Upkeep < 1.17.3 - Unauthenticated Sensitive Data Disclosure and Forced Site Restore via Predictable cron_secretEPSS 0.4%CVE-2024-8553MEDIUMForeman: read-only access to entire db from templatesEPSS 0.4%CVE-2026-58432MEDIUMMissing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/giteaEPSS 0.4%CVE-2025-8525MEDIUMExrick xboot Spring Boot Admin/Spring Actuator information disclosureEPSS 0.4%CVE-2026-27611HIGHFileBrowser Quantum: Password Protection Not Enforced on Shared File LinksEPSS 0.4%CVE-2026-56259HIGHCrawl4AI - LLM Credential Exfiltration via base_url and Environment Variable ResolutionEPSS 0.4%CVE-2025-59184MEDIUMStorage Spaces Direct Information Disclosure VulnerabilityEPSS 0.4%CVE-2025-59188MEDIUMMicrosoft Failover Cluster Information Disclosure VulnerabilityEPSS 0.4%CVE-2025-41230HIGHVMware Cloud Foundation Information Disclosure VulnerabilityEPSS 0.4%CVE-2024-1477MEDIUMEasy Maintenance Mode <= 1.4.2 - Information ExposureEPSS 0.4%CVE-2026-41032HIGHPhoenix Contact: Unauthenticated log download vulnerability in the firmware of CHARX SEC-3xxx charging controllersEPSS 0.4%CVE-2026-88893HIGHOpenPanel Unauthenticated Share Lookup Information DisclosureEPSS 0.4%