Falhas do tipo CWE-200

4.959 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2026-33041MEDIUMAVideo has an Unauthenticated Password Hash Oracle via encryptPass.json.phpEPSS 0.4%CVE-2026-2207MEDIUMWeKan Activity Publication activities.js LinkedBoardActivitiesBleed information disclosureEPSS 0.4%CVE-2024-37924MEDIUMWordPress WP2Speed Faster – Optimize PageSpeed Insights Score 90-100 plugin <= 1.0.1 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2020-15704MEDIUMpppd arbitrary file read information disclosure vulnerabilityEPSS 0.4%CVE-2024-38756MEDIUMWordPress Coming Soon Page – Responsive Coming Soon & Maintenance Mode plugin <= 1.6.3 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2025-54586HIGHGitProxy is susceptible to a hidden commits injection attackEPSS 0.4%CVE-2025-12297MEDIUMatjiu pybbs UserApiController.java information disclosureEPSS 0.4%CVE-2024-22260MEDIUMVMware Workspace One UEM update addresses an information exposure vulnerability.  A malicious actor with network access to the Workspace OneEPSS 0.4%CVE-2024-51769HIGHAn information disclosure vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.EPSS 0.4%CVE-2025-60805HIGHAn issue was discovered in BESSystem BES Application Server thru 9.5.x allowing unauthorized attackers to gain sensitive information via theEPSS 0.4%CVE-2026-101143MEDIUMEleveo Quality Management QMBODownload information disclosureEPSS 0.4%CVE-2026-71433MEDIUMLangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite storesEPSS 0.4%CVE-2024-25119MEDIUMInformation Disclosure of Encryption Key in TYPO3 Install ToolEPSS 0.4%CVE-2025-2786MEDIUMTempo-operator: serviceaccount token exposure leading to token and subject access reviews in openshift tempo operatorEPSS 0.4%CVE-2025-14980MEDIUMBetterDocs <= 4.3.3 - Authenticated (Contributor+) Sensitive Information ExposureEPSS 0.4%CVE-2025-57433MEDIUMThe 2wcom IP-4c 2.15.5 device's web interface includes an information disclosure vulnerability. By sending a crafted POST request to a speciEPSS 0.4%CVE-2026-76206MEDIUMphpMyFAQ before 4.1.7 Information Disclosure via PDF ExportEPSS 0.4%CVE-2025-69822HIGHAn issue in Atomberg Atomberg Erica Smart Fan Firmware Version: V1.0.36 allows an attacker to obtain sensitive information and escalate privEPSS 0.4%CVE-2025-2228MEDIUMResponsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates <= 1.6.8 - Authenticated (Contributor+) Sensitive Information ExposureEPSS 0.4%CVE-2024-12584MEDIUM140+ Widgets | Xpro Addons For Elementor – FREE <= 1.4.6.2 - Authenticated (Contributor+) Post Disclosure via Post DuplicationEPSS 0.4%