Falhas do tipo CWE-200

4.959 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2025-59427LOWCloudflare vite plugin exposes secrets over the built-in dev serverEPSS 0.4%CVE-2024-24755MEDIUMdiscourse-group-membership-ip-block is exposing potentially sensitive custom fieldsEPSS 0.4%CVE-2025-2842MEDIUMTempo-operator: tempo operator token exposition lead to read sensitive dataEPSS 0.4%CVE-2025-12010MEDIUMAuthors List <= 2.0.6.1 - Authenticated (Contributor+) Sensitive Information Exposure via Limited Method Call in Plugin's ShortcodeEPSS 0.4%CVE-2023-23499—This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.6.3, macOS Ventura 13.2, watchOS 9.3, macOS EPSS 0.4%CVE-2025-49150MEDIUMCursor Agent Potentially Leaks Information using JSON schemaEPSS 0.4%CVE-2026-72760MEDIUMcti-transmute Following List Exposes User Email Addresses to Authenticated UsersEPSS 0.4%CVE-2025-13596LOWImproper Error Handling Leading to Sensitive Information Disclosure in CIGES ≤ 2.15.6EPSS 0.4%CVE-2025-53003HIGHJanssen Config API returns results without scope verificationEPSS 0.4%CVE-2026-5266LOWExposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Echo. This vulnerability is associated wiEPSS 0.4%CVE-2026-54396MEDIUMMISP AuthKey edit endpoint allows authenticated user email enumerationEPSS 0.4%CVE-2026-94050MEDIUMD-Link DIR-X1860Z ubus JSON-RPC interface routerd.get_rand_key information disclosureEPSS 0.4%CVE-2025-23174HIGHYoel Geva - CWE-200: Exposure of Sensitive Information to an Unauthorized ActorEPSS 0.4%CVE-2024-21040MEDIUMVulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versioEPSS 0.4%CVE-2023-37232HIGHLoftware Spectrum through 4.6 exposes Sensitive Information (Logs) to an Unauthorized Actor.EPSS 0.4%CVE-2026-32244MEDIUMDiscourse: Cached outdated summaries can leak removed contentEPSS 0.4%CVE-2026-28920MEDIUMAn information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26EPSS 0.4%CVE-2018-16883LOWsssd versions from 1.13.0 to before 2.0.0 did not properly restrict access to the infopipe according to the "allowed_uids" configuration parEPSS 0.4%CVE-2026-54304HIGHn8n: SecurityScorecard Node Leaks API Token to User-Controlled HostEPSS 0.4%CVE-2015-8553MEDIUMXen allows guest OS users to obtain sensitive information from uninitialized locations in host OS kernel memory by not enabling memory and IEPSS 0.4%