Falhas do tipo CWE-200

4.953 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2026-73308MEDIUMBudibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other BuildersEPSS 0.4%CVE-2025-12558MEDIUMBeaver Builder – WordPress Page Builder <= 2.9.4 - Authenticated (Contributor+) Sensitive Information ExposureEPSS 0.4%CVE-2022-22447MEDIUMIBM Disconnected Log Collector information disclosureEPSS 0.4%CVE-2024-26312MEDIUMArcher Platform 6 before 2024.03 contains a sensitive information disclosure vulnerability. An authenticated attacker could potentially obtaEPSS 0.4%CVE-2024-5813MEDIUMSSH Private Key Leak in BeyondInsight PasswordSafeEPSS 0.4%CVE-2026-30847CRITICALWekan Credential Leak via notificationUsers Publication Exposes Password Hashes and Session TokensEPSS 0.4%CVE-2026-61783HIGHWazuh: RBAC permission-effect check in mask_sensitive_config allows low-privilege users to read cluster.keyEPSS 0.4%CVE-2022-3611HIGHAn information disclosure vulnerability has been identified in the Lenovo App Store which may allow some applications to gain unauthorized aEPSS 0.4%CVE-2025-36601MEDIUMDell PowerScale OneFS, versions 9.5.0.0 through 9.11.0.0, contains an exposure of sensitive information to an unauthorized actor vulnerabiliEPSS 0.4%CVE-2022-46310HIGHThe TelephonyProvider module has a vulnerability in obtaining values.Successful exploitation of this vulnerability may affect data confidentEPSS 0.4%CVE-2026-34518LOWAIOHTTP: Cookie and Proxy-Authorization headers leaked on cross-origin redirectEPSS 0.4%CVE-2024-40597HIGHAn issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. It can expose suppressed information for log events. (The lEPSS 0.4%CVE-2025-60949CRITICALCensus CSWeb leaked configuration filesEPSS 0.4%CVE-2022-30736MEDIUMImproper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of contact and gallery wiEPSS 0.4%CVE-2025-58059CRITICALValtimo scripting engine can be used to gain access to sensitive data or resourcesEPSS 0.4%CVE-2026-68520MEDIUMGlances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/configEPSS 0.4%CVE-2025-22960HIGHA session hijacking vulnerability exists in the web-based management interface of GatesAir Maxiva UAXT, VAXT transmitters. Unauthenticated aEPSS 0.4%CVE-2022-30743MEDIUMImproper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of contact and gallery wiEPSS 0.4%CVE-2025-46813MEDIUMPrivate data leak on login-required Discourse sitesEPSS 0.4%CVE-2024-29885MEDIUMReports are still accessible even when `canView()` returns false in silverstripe/reportsEPSS 0.4%