Falhas do tipo CWE-200

4.952 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2025-32789LOWEspoCRM Allows Potential Disclosure of Sensitive Information in the User Sorting FunctionEPSS 0.4%CVE-2025-47417MEDIUMEnable Debug ImagesEPSS 0.4%CVE-2024-6336MEDIUMSecurity misconfiguration was identified in GitHub Enterprise Server that allowed sensitive data exposureEPSS 0.4%CVE-2026-44786HIGHDiscourse: Public chat MessageBus broadcasts are not restricted to chat-eligible usersEPSS 0.4%CVE-2026-7041MEDIUM666ghj MiroFish Werkzeug Debugger PIN console information disclosureEPSS 0.4%CVE-2025-43449HIGHThe issue was addressed with improved handling of caches. This issue is fixed in iOS 26.1 and iPadOS 26.1. A malicious app may be able to trEPSS 0.4%CVE-2026-87225HIGHVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.4%CVE-2026-76706MEDIUMUnauthenticated Information Disclosure in EdgeConnect SD-WAN Orchestrator API allows exposure of sensitive dataEPSS 0.4%CVE-2025-15625CRITICALUnauthenticated execution of arbitrary SQL queries in Sparx Pro Cloud ServerEPSS 0.4%CVE-2023-1831HIGHUser password logged in audit logsEPSS 0.4%CVE-2025-67274HIGHAn issue in continuous.software aangine v.2025.2 allows a remote attacker to obtain sensitive information via the excel-integration-service EPSS 0.4%CVE-2024-37150HIGHPrivate npm registry support used scope auth token for downloading tarballsEPSS 0.4%CVE-2026-87209HIGHVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.4%CVE-2026-44979MEDIUM@hapi/wreck : Sensitive `Proxy-Authorization` header leaked across cross-hostname redirectsEPSS 0.4%CVE-2026-60176HIGHVulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affecteEPSS 0.4%CVE-2026-9583MEDIUMSourceCodester CET Automated Grading System with AI Predictive Analytics SQL index.php information exposureEPSS 0.4%CVE-2026-76717MEDIUMUnauthenticated Remote Sensitive Information Disclosure Vulnerability in HPE Networking Analytics and Location Engine (ALE)EPSS 0.4%CVE-2023-3349HIGHInformation exposure on IBERMATICA RPSEPSS 0.4%CVE-2026-17457MEDIUMmf-yang openclaw-cn Scheme navigation-guard.ts assertBrowserNavigationAllowed information disclosureEPSS 0.4%CVE-2026-15329MEDIUMzhayujie CowAgent Browser Tool browser_tool.py BrowserTool._do_navigate information disclosureEPSS 0.4%