Falhas do tipo CWE-200

4.960 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2026-61112MEDIUMVulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions tEPSS 0.4%CVE-2026-62567HIGHVulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are EPSS 0.4%CVE-2023-43123—Apache Storm: Local Information Disclosure Vulnerability in Storm-core on Unix-Like systems due temporary filesEPSS 0.4%CVE-2026-44460HIGHFileRise: TOTP Bypass via Setup Endpoint Disclosing Existing SecretEPSS 0.4%CVE-2023-52238LOWA vulnerability has been identified in RUGGEDCOM RST2228 (All versions < V5.9.0), RUGGEDCOM RST2228P (All versions < V5.9.0). The web serverEPSS 0.4%CVE-2025-66027HIGHRallly Information Disclosure Vulnerability in Participant API Leaks Names and Emails Despite Pro Privacy SettingsEPSS 0.4%CVE-2026-44506HIGHMedplum - Exposure of OAuth client secret via dynamic registration endpoint in self-hosted configurationsEPSS 0.4%CVE-2026-62556MEDIUMVulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affeEPSS 0.4%CVE-2026-53643HIGHFOSSBilling allows low-privileged staff accounts to perform unauthorized actions via admin API endpointsEPSS 0.4%CVE-2026-16960HIGHLoops & Logic < 4.3.0 - Unauthenticated User Data and Site Option DisclosureEPSS 0.4%CVE-2025-31964LOWHCL BigFix IVR is impacted by an improper service binding configurationEPSS 0.4%CVE-2026-53640LOWFOSSBilling missing authorization checks on read-only admin API endpoints expose sensitive staff, client, and redirect dataEPSS 0.4%CVE-2024-11299MEDIUMMemberpress <= 1.11.37 - Unauthenticated Content Restriction Bypass to Sensitive Information ExposureEPSS 0.4%CVE-2026-2268HIGHNinja Forms <= 3.14.0 - Unauthenticated Information Disclosure in nf_ajax_submit AJAX ActionEPSS 0.4%CVE-2025-40662MEDIUMAbsolute path disclosure vulnerability in DM Corporative CMSEPSS 0.4%CVE-2024-43319MEDIUMWordPress HTML5 Video Player plugin <= 2.5.31 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2024-48900MEDIUMMoodle: idor when accessing list of badge recipientsEPSS 0.4%CVE-2026-44408MEDIUMUnauthorized access vulnerability in ZTE MU5250EPSS 0.4%CVE-2023-44112HIGHOut-of-bounds access vulnerability in the device authentication module. Successful exploitation of this vulnerability may affect confidentiaEPSS 0.4%CVE-2025-6432HIGHDNS Requests leaked outside of a configured SOCKS proxyEPSS 0.4%