Falhas do tipo CWE-200

4.960 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2026-41182MEDIUMLangSmith SDK: Streaming token events bypass output redactionEPSS 0.4%CVE-2026-8058MEDIUMThis Power System update is being released to address a sensitive information disclosureEPSS 0.4%CVE-2026-37069MEDIUMAbsolute Path Disclosure in /vfm-admin/assets/zipstream/grandt/relativepath/RelativePath.Example1.php in Veno File Manager Project 4.4.9 allEPSS 0.4%CVE-2025-63212MEDIUMGatesAir Flexiva-LX devices on firmware 1.0.13 and 2.0, including models LX100, LX300, LX600, and LX1000, expose sensitive session identifieEPSS 0.4%CVE-2026-61454HIGHGrav before 2.0.4 Information Disclosure via __GRAV_CONFIG__EPSS 0.4%CVE-2025-26604HIGHPossibility to retrieve bot token by malicious module developers in Discord-Bot-Framework-KernelEPSS 0.4%CVE-2026-6801MEDIUMContext Blog <= 1.3.5 - Unauthenticated Sensitive Information Exposure via 'postID' ParameterEPSS 0.4%CVE-2026-57994MEDIUMphpMyFAQ - Information Disclosure of Inactive FAQ Content via Public API EndpointsEPSS 0.4%CVE-2022-4862MEDIUMXSS vulnerability in M-Files WebEPSS 0.4%CVE-2024-47060MEDIUMUnauthorized Access After Organization or Project Deactivation in ZitadelEPSS 0.4%CVE-2019-1731MEDIUMCisco NX-OS Software SSH Key Information Disclosure VulnerabilityEPSS 0.4%CVE-2026-47264MEDIUMDiscourse: Don't leak restricted tag group names via tag infoEPSS 0.4%CVE-2017-12284—A vulnerability in the web interface of Cisco Jabber for Windows Client could allow an authenticated, local attacker to retrieve user profilEPSS 0.4%CVE-2024-56526HIGHAn issue was discovered in OXID eShop before 7. CMS pages in combination with Smarty may display user information if a CMS page contains a SEPSS 0.4%CVE-2025-7573MEDIUMLB-LINK BL-WR9000 lighttpd.cgi bs_GetManPwd information disclosureEPSS 0.4%CVE-2025-66625MEDIUMUmbraco Vulnerable to Improper File Access and Credential Exposure through Dictionary Import FunctionalityEPSS 0.4%CVE-2025-27399MEDIUMMastodon's domain blocks & rationales ignore user approval when visibility set as "users"EPSS 0.4%CVE-2025-7572MEDIUMLB-LINK BL-WR9000 lighttpd.cgi bs_GetHostInfo information disclosureEPSS 0.4%CVE-2023-50872HIGHThe API in Accredible Credential.net December 6th, 2023 allows an Insecure Direct Object Reference attack that discloses partial informationEPSS 0.4%CVE-2026-47263MEDIUMDiscourse: Prevent webhook payload disclosure on event redeliveryEPSS 0.4%