Falhas do tipo CWE-200

4.959 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2024-12584MEDIUM140+ Widgets | Xpro Addons For Elementor – FREE <= 1.4.6.2 - Authenticated (Contributor+) Post Disclosure via Post DuplicationEPSS 0.4%CVE-2026-55496MEDIUMCloudreve: Inactive/banned account emails leaked via GET /api/v4/user/search because SearchActive() omits the active-status predicateEPSS 0.4%CVE-2020-1739LOWA flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svEPSS 0.4%CVE-2025-59454MEDIUMApache CloudStack: Lack of user permission validation leading to data leak for few APIsEPSS 0.4%CVE-2026-9183MEDIUM24liveblog <= 2.2 - Authenticated (Contributor+) Exposure of Sensitive Information via Block Editor Script LocalizationEPSS 0.4%CVE-2025-39204HIGHA vulnerability exists in the Web interface of the MicroSCADA X SYS600 product. The filtering query in the Web interface can be malformed, sEPSS 0.4%CVE-2026-41183MEDIUMFreeScout allows non-folder conversation queries to disclose assigned-only hidden conversationsEPSS 0.4%CVE-2026-34600MEDIUMJoplin Server delta API returns note content after share access is revokedEPSS 0.4%CVE-2025-8852MEDIUMWuKongOpenSource WukongCRM API Response upload information exposureEPSS 0.4%CVE-2025-58589LOWInformation Disclosure Through StacktraceEPSS 0.4%CVE-2025-54468MEDIUMRancher sends sensitive information to external services through the `/meta/proxy` endpointEPSS 0.4%CVE-2023-43997MEDIUMAn issue in Yoruichi hobby base mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channelEPSS 0.4%CVE-2023-5160MEDIUMFull name disclosure via team top membership with Show Full Name option disabledEPSS 0.4%CVE-2023-43994MEDIUMAn issue in Cleaning_makotoya mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel aEPSS 0.4%CVE-2023-43995MEDIUMAn issue in picot.golf mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access tEPSS 0.4%CVE-2026-61782HIGH@rsdoctor/rspack-plugin has Unauthenticated HTTP API that Exposes Project Source Code and Build MetadataEPSS 0.4%CVE-2023-43992MEDIUMAn issue in STOCKMAN GROUP mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel acceEPSS 0.4%CVE-2025-13526HIGHOneClick Chat to Order <= 1.0.8 - Insecure Direct Object Reference to Unauthenticated Sensitive Information ExposureEPSS 0.4%CVE-2026-45739LOWStrawberry GraphQL: Default GraphiQL may expose HTTP headers in URLsEPSS 0.4%CVE-2024-12329MEDIUMEssential Real Estate <= 5.1.6 - Missing Authorization to Authenticated (Contributor+) Information ExposureEPSS 0.4%