Falhas do tipo CWE-200

4.975 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2026-84926LOWEmbedPress 4.6.0 - 4.6.3 - Contributor+ Administrator Email Disclosure via Google Reviews REST RouteEPSS 0.3%CVE-2026-19858HIGHJetFormBuilder < 3.6.5.2 - Unauthenticated Password Hash and Arbitrary Metadata Disclosure via Dynamic PresetEPSS 0.3%CVE-2026-87836LOWComments Import & Export 2.1.11 - 2.5.3 - Author+ Comment PII Disclosure via ExportEPSS 0.3%CVE-2026-19406LOWEasy Appointments < 4.0.1 - Contributor+ Sensitive Information Disclosure via REST Appointments ListingEPSS 0.3%CVE-2026-59180LOWApprise forwards configured auth headers across cross-origin HTTP redirectsEPSS 0.3%CVE-2022-0851—There is a flaw in convert2rhel. When the --activationkey option is used with convert2rhel, the activation key is subsequently passed to subEPSS 0.3%CVE-2025-20270MEDIUMCisco Evolved Programmable Network Manager Information Disclosure VulnerabilityEPSS 0.3%CVE-2026-63432MEDIUMHorilla: Server-Side Template Injection (SSTI) in Mail Preview Endpoints Allows Authenticated Users to Disclose Password Hashes and Server MetadataEPSS 0.3%CVE-2024-58256MEDIUMEnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary command execution.EPSS 0.3%CVE-2026-101083MEDIUMPMWeb encryptionhelper.dll information disclosureEPSS 0.3%CVE-2026-20360HIGHCisco Nexus Dashboard Software Security Hardening Release September 2026 - Information Exposure & Insecure HandlingEPSS 0.3%CVE-2023-50346LOWAn information disclosure affects DRYiCE MyXalyticsEPSS 0.3%CVE-2026-65758HIGHJoomla Extension - tassos.gr - Sensitive data exposure in Convert Forms extension 2.5.0-5.2.2EPSS 0.3%CVE-2024-27731MEDIUMCross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via the lack of file typeEPSS 0.3%CVE-2025-26485MEDIUMA vulnerability in Beta80 Life 1st enables the retrieval of different error messages for failed authentication attempts (in case of the usaEPSS 0.3%CVE-2025-11760MEDIUMeRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams <= 1.5.6 - Unauthenticated Sensitive Information ExposureEPSS 0.3%CVE-2026-60888MEDIUMVulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that arEPSS 0.3%CVE-2025-8484MEDIUMCode Quality Control Tool <= 2.1 - Unauthenticated Information Exposure via Log FilesEPSS 0.3%CVE-2026-61050MEDIUMVulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: User Interface). Supported versions that aEPSS 0.3%CVE-2026-62490MEDIUMVulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions tEPSS 0.3%