Falhas do tipo CWE-200

4.975 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2025-61220HIGHThe incomplete verification mechanism in the AutoBizLine com.mysecondline.app 1.2.91 allows attackers to log in as other users and gain unauEPSS 0.3%CVE-2021-3602—An information disclosure flaw was found in Buildah, when building containers using chroot isolation. Running processes in container builds EPSS 0.3%CVE-2020-3541MEDIUMCisco Webex Meetings Client for Windows, Webex Meetings Desktop App, and Webex Teams Information Disclosure VulnerabilityEPSS 0.3%CVE-2026-9129CRITICALPath Traversal in Altium Enterprise Server Viewer StorageController Allows Arbitrary File ReadEPSS 0.3%CVE-2026-34244MEDIUMWeblate: SSRF via Project-Level Machinery ConfigurationEPSS 0.3%CVE-2017-12315—A vulnerability in system logging when replication is being configured with the Cisco HyperFlex System could allow an authenticated, local aEPSS 0.3%CVE-2026-25125MEDIUMOctober CMS: Environment Variable Exfiltration via INI Parser InterpolationEPSS 0.3%CVE-2024-28164MEDIUMInformation Disclosure vulnerability in SAP NetWeaver AS Java (Guided Procedures)EPSS 0.3%CVE-2026-28506MEDIUMOutline's Information Disclosure in Activity Logs allows User Enumeration of Private DraftsEPSS 0.3%CVE-2026-34092LOWBlock UI elements in 'tools'-sidebar shows presence of an autoblocked IPEPSS 0.3%CVE-2026-18486HIGHIBM ContextForge MCP Gateway is affected by credential disclosure and privilege escalation via jq filter executionEPSS 0.3%CVE-2025-3104MEDIUMWP Staging Pro <= 6.1.2 - Unauthenticated Information Exposure via getOutdatedPluginsRequest FunctionEPSS 0.3%CVE-2025-12585MEDIUMMxChat – AI Chatbot for WordPress <= 2.5.5 - Unauthenticated Information ExposureEPSS 0.3%CVE-2026-21928MEDIUMVulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exEPSS 0.3%CVE-2025-29992HIGHMahara before 24.04.9 exposes database connection information if the database becomes unreachable, e.g., due to the database server being teEPSS 0.3%CVE-2024-39335CRITICALSupported versions of Mahara 24.04 before 24.04.1 and 23.04 before 23.04.6 are vulnerable to information being disclosed to an institution aEPSS 0.3%CVE-2026-20298MEDIUMSensitive Information Disclosure through the storage/passwords REST Endpoint in Splunk EnterpriseEPSS 0.3%CVE-2026-100377MEDIUMRevision-deleted pages can be viewed through WikiLambda's action=edit and Special:ViewAbstractEPSS 0.3%CVE-2026-60349MEDIUMVulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Java Business Objects). Supported versions that are EPSS 0.3%CVE-2025-60858HIGHReolink Video Doorbell Wi-Fi DB_566128M5MP_W stores and transmits DDNS credentials in plaintext within its configuration and update scripts,EPSS 0.3%