Falhas do tipo CWE-200

4.959 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2020-1698MEDIUMA flaw was found in keycloak in versions before 9.0.0. A logged exception in the HttpMethod class may leak the password given as parameter. EPSS 0.4%CVE-2026-83437HIGHVulnerability in the Oracle Engineering product of Oracle E-Business Suite (component: Change Management). Supported versions that are affeEPSS 0.4%CVE-2025-3403MEDIUMVivotek NVR ND8422P/NVR ND9525P/NVR ND9541P HTML Form sensitive information in sourceEPSS 0.4%CVE-2026-14928MEDIUMJS Help Desk < 3.1.4 - Subscriber+ Sensitive Information Disclosure via checkAIReplyTicketsBySubjectEPSS 0.4%CVE-2026-47124MEDIUMNezha WebSocket server stream discloses cross-tenant server telemetry to authenticated membersEPSS 0.4%CVE-2026-18943MEDIUMWPC Admin Columns < 2.3.4 - Subscriber+ Arbitrary User/Post/Term Meta DisclosureEPSS 0.4%CVE-2026-12976MEDIUMLearnPress < 4.4.4 - Subscriber+ Sensitive Information Exposure via AI AssistantEPSS 0.4%CVE-2026-16541MEDIUMSimply Schedule Appointments < 1.6.12.17 - Team Member+ User Email Disclosure via Users and Customers REST EndpointsEPSS 0.4%CVE-2026-58027MEDIUMQueryAbuseFilter API can be used to see the hit count of private filters, which is hidden in the UIEPSS 0.4%CVE-2026-83287HIGHVulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Presentation Services). SupporEPSS 0.4%CVE-2026-16968MEDIUMGeoDirectory < 2.8.168 - Contributor+ User Email Disclosure via geodir_json_search_usersEPSS 0.4%CVE-2026-83116HIGHVulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions tEPSS 0.4%CVE-2020-7284HIGHNetwork Security Management (NSM) - Exposure of Sensitive InformationEPSS 0.4%CVE-2026-83443MEDIUMVulnerability in the Oracle Assets product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affecteEPSS 0.4%CVE-2026-19613MEDIUMECS < 4.3.10 - Contributor+ Arbitrary Post Meta Disclosure via Dynamic Repeater ACF SourceEPSS 0.4%CVE-2026-16562MEDIUMWP Statistics < 14.16.10 - Subscriber+ Sensitive Data Disclosure via Metabox AJAX HandlersEPSS 0.4%CVE-2026-13168MEDIUMEventin < 4.1.20 - Contributor+ Customer PII Disclosure via REST APIEPSS 0.4%CVE-2026-42092MEDIUMGlobal Settings Publication Exposes Sensitive Configuration to Any Authenticated User in TitraEPSS 0.4%CVE-2026-46427HIGHBudibase: Snowflake private key returned unmasked from datasource API to BASIC usersEPSS 0.4%CVE-2026-16590MEDIUMWP Directory Kit < 1.5.5 - Subscriber+ Contact Message and User Data DisclosureEPSS 0.4%