Falhas do tipo CWE-200

4.974 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2026-46841MEDIUMVulnerability in Oracle REST Data Services (component: General). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitableEPSS 0.3%CVE-2026-71087MEDIUMVulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that isEPSS 0.3%CVE-2026-60156MEDIUMVulnerability in Oracle APEX (component: General). Supported versions that are affected are 24.1, 24.2 and 26.1. Easily exploitable vulneraEPSS 0.3%CVE-2026-60237MEDIUMVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.EPSS 0.3%CVE-2026-60260MEDIUMVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.EPSS 0.3%CVE-2026-60394MEDIUMVulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 21.3-21.21 and 23.4-23.2EPSS 0.3%CVE-2026-55403LOWdatamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemasEPSS 0.3%CVE-2025-40645HIGHExposure of sensitive information in VidayEPSS 0.3%CVE-2023-7031MEDIUMAvaya Experience Portal Manager Insecure Direct Object Reference VulnerabilitiesEPSS 0.3%CVE-2022-0516—A vulnerability was found in kvm_s390_guest_sida_op in the arch/s390/kvm/kvm-s390.c function in KVM for s390 in the Linux kernel. This flaw EPSS 0.3%CVE-2022-42866MEDIUMThe issue was addressed with improved handling of caches. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, waEPSS 0.3%CVE-2026-32620MEDIUMDiscourse: Missing post-level authorization allows whisper metadata disclosureEPSS 0.3%CVE-2024-33880MEDIUMAn issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. It discloses full pathnames via Virto.SharePoiEPSS 0.3%CVE-2026-32951MEDIUMDiscourse: Authorization bypass in oneboxer via user-controlled category idEPSS 0.3%CVE-2024-22200LOWvantage6-UI docker image leaks software version informationEPSS 0.3%CVE-2023-49292MEDIUMPossible private key restoration in go package github.com/ecies/goEPSS 0.3%CVE-2026-32618MEDIUMDiscourse: Unauthorized channel membership inference via excluded_memberships_channel_idEPSS 0.3%CVE-2026-76041MEDIUMInformation leak in Skia in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to potentially bypass web origin policy via a crEPSS 0.3%CVE-2025-36759HIGHSensitive Information Disclosure in SolaX CloudEPSS 0.3%CVE-2026-34318MEDIUMVulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). Supported versions that are affected are 8.0.0-8.EPSS 0.3%