Falhas do tipo CWE-200

4.952 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2025-50708HIGHAn issue in Perplexity AI GPT-4 v.2.51.0 allows a remote attacker to obtain sensitive information via the token component in the shared chatEPSS 0.4%CVE-2025-0226MEDIUMTsinghua Unigroup Electronic Archives System downLoad.html download information disclosureEPSS 0.4%CVE-2026-17457MEDIUMmf-yang openclaw-cn Scheme navigation-guard.ts assertBrowserNavigationAllowed information disclosureEPSS 0.4%CVE-2023-50950LOWIBM QRadar information disclosureEPSS 0.4%CVE-2026-15329MEDIUMzhayujie CowAgent Browser Tool browser_tool.py BrowserTool._do_navigate information disclosureEPSS 0.4%CVE-2018-10599—IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) REPSS 0.4%CVE-2024-43251MEDIUMWordPress Bit Form Pro plugin <= 2.6.4 - Authenticated Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2024-43257MEDIUMWordPress Leopard plugin <= 2.0.36 - Subscriber+ Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2024-24845MEDIUMWordPress Post Thumbnail Editor plugin <= 2.4.8 - Unauthenticated Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2024-7128MEDIUMOpenshift-console: unauthenticated data exposureEPSS 0.4%CVE-2022-43890MEDIUMIBM Security Verify Privilege On-Premises information disclosureEPSS 0.4%CVE-2022-32933MEDIUMAn information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in macOS Monterey 12.5. A website may be EPSS 0.4%CVE-2024-20396MEDIUMA vulnerability in the protocol handlers of Cisco Webex App could allow an unauthenticated, remote attacker to gain access to sensitive infoEPSS 0.4%CVE-2026-50554MEDIUMNote Mark: Unauthenticated disclosure of soft-deleted note metadata via deleted=true on public books in note-markEPSS 0.4%CVE-2024-39817MEDIUMInsertion of sensitive information into sent data issue exists in Cybozu Office 10.0.0 to 10.8.6, which may allow a user who can login to thEPSS 0.4%CVE-2026-27131MEDIUMSprig Plugin for Craft CMS potentially discloses sensitive information via Sprig PlaygroundEPSS 0.4%CVE-2025-32700LOWAbuseFilter log interfaces expose global private and hidden filters when central DB is not availableEPSS 0.4%CVE-2024-13829MEDIUMWordPress form builder plugin for contact forms, surveys and quizzes – Tripetto <= 8.0.8 - Unauthenticated Sensitive Information ExposureEPSS 0.4%CVE-2024-33626MEDIUMThe LevelOne WBR-6012 router contains a vulnerability within its web application that allows unauthenticated disclosure of sensitive informaEPSS 0.4%CVE-2024-11153MEDIUMContent Control – The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More <= 2.5.0 - Unauthenticated Content Restriction Bypass to Sensitive Information ExposureEPSS 0.4%