Falhas do tipo CWE-200

4.951 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2026-35442HIGHDirectus: Authenticated Users Can Extract Concealed Fields via Aggregate QueriesEPSS 0.4%CVE-2026-48766HIGHTypeBot vulnerable to OpenAI API key exfiltration in listModels via attacker-controlled baseUrlEPSS 0.4%CVE-2026-79776MEDIUMrclone before 1.75.0 Authentication Bypass via pprofEPSS 0.4%CVE-2026-77017HIGHWorkeera Remote Tech Job Board < 1.0.6 - Subscriber+ Arbitrary File Read via Candidate Profile Mass AssignmentEPSS 0.4%CVE-2025-52898HIGHFrappe account takeover via password reset token leakageEPSS 0.4%CVE-2025-49177MEDIUMXorg-x11-server-xwayland: xorg-x11-server: tigervnc: data leak in xfixes extension's xfixessetclientdisconnectmodeEPSS 0.4%CVE-2026-41278HIGHFlowise: Public chatflow endpoints return unsanitized flowData including plaintext API keys, passwords, and credential IDsEPSS 0.4%CVE-2024-10356MEDIUMElementsReady Addons for Elementor <= 6.4.8 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor TemplatesEPSS 0.4%CVE-2026-16954MEDIUMAI Engine < 3.6.4 - Editor+ Sensitive Information Disclosure of API Key and Bearer TokensEPSS 0.4%CVE-2024-22301MEDIUMWordPress Albo Pretorio Online Plugin <= 4.6.6 is vulnerable to Sensitive Data ExposureEPSS 0.4%CVE-2026-78174CRITICALWatchGuard Dimension Session Hijack via Exposed Session Tokens in Diagnostic LogsEPSS 0.4%CVE-2026-42564HIGHjotty·page: Unauthenticated Path Traversal leads to sensitive file disclosure and session-token reuse impactEPSS 0.4%CVE-2026-47193HIGHOpenProject: Journal diff endpoint bypasses object, journal, and field visibility checksEPSS 0.4%CVE-2025-27845CRITICALIn ESPEC North America Web Controller 3 before 3.3.4, /api/v4/auth/ with any invalid authentication request results in exposing a JWT secretEPSS 0.4%CVE-2025-54118MEDIUMNamelessMC allows sensitive information disclosure in member list componentEPSS 0.4%CVE-2026-77246HIGHMCP Atlassian: MCP HTTP Client Server-Local File Exfiltration via Unvalidated Attachment Upload PathEPSS 0.4%CVE-2022-20953MEDIUMCisco TelePresence Collaboration Endpoint and RoomOS Software VulnerabilitiesEPSS 0.4%CVE-2026-42871MEDIUMWeGIA: Error Handling familiar_docfamiliarEPSS 0.4%CVE-2026-44206MEDIUMFrappe: DB Schema Enumeration via Frappe-Authorization-SourceEPSS 0.4%CVE-2025-14280MEDIUMPixelYourSite <= 11.1.5 - Sensitive Information Exposure via Log FileEPSS 0.4%