Falhas do tipo CWE-200

4.959 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2025-22918HIGHPolycom RealPresence Group 500 <=20 has Insecure Permissions due to automatically loaded cookies. This allows for the use of administrator fEPSS 0.4%CVE-2024-48125HIGHAn issue in the AsDB service of HI-SCAN 6040i Hitrax HX-03-19-I allows attackers to enumerate user credentials via crafted GIOP protocol reqEPSS 0.4%CVE-2026-73229MEDIUMDjango REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requestsEPSS 0.4%CVE-2025-25333HIGHAn issue in IKEA CN iOS 4.13.0 allows attackers to access sensitive user information via supplying a crafted link.EPSS 0.4%CVE-2024-6571MEDIUMOptimize Images ALT Text (alt tag) & names for SEO using AI <= 3.1.1 - Unauthenticated Full Path DisclosureEPSS 0.4%CVE-2024-6548MEDIUMAdd Admin JavaScript <= 2.0 - Unauthenticated Full Path DislcosureEPSS 0.4%CVE-2024-6553MEDIUMWP Meteor Website Speed Optimization Addon <= 3.4.3 - Unauthenticated Full Path DisclosureEPSS 0.4%CVE-2024-6545MEDIUMAdmin Trim Interface <= 3.5.1 - Unauthenticated Full Path DisclosureEPSS 0.4%CVE-2025-55008HIGHAuthKit React Router: Sensitive auth data rendered in HTMLEPSS 0.4%CVE-2025-55009HIGHAuthKit: Sensitive auth data rendered in HTMLEPSS 0.4%CVE-2024-6559MEDIUMXCloner <= 4.7.3 - Unauthenticated Full Path DisclosureEPSS 0.4%CVE-2026-87017MEDIUMOpen WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backendsEPSS 0.4%CVE-2026-67339MEDIUMguzzlehttp/guzzle before 7.14.2 Proxy-Authorization Header DisclosureEPSS 0.4%CVE-2025-11026MEDIUMgivanz Vvveb Configuration File information disclosureEPSS 0.4%CVE-2025-62699MEDIUMSpecial:Translate tool does not use the correct IP and User-Agent in the CheckUser toolEPSS 0.4%CVE-2025-26009HIGHTelesquare TLR-2005KSH 1.1.4 has an Information Disclosure vulnerability when requesting systemutilit.cgi.EPSS 0.4%CVE-2026-92933MEDIUMvm2 before 3.11.8 Information Disclosure via util.getCallSitesEPSS 0.4%CVE-2026-71293MEDIUMStatamic CMS Unguarded Exposure of 2FA Recovery Codes via Antlers current_user VariableEPSS 0.4%CVE-2026-58027MEDIUMQueryAbuseFilter API can be used to see the hit count of private filters, which is hidden in the UIEPSS 0.4%CVE-2026-16541MEDIUMSimply Schedule Appointments < 1.6.12.17 - Team Member+ User Email Disclosure via Users and Customers REST EndpointsEPSS 0.4%