Falhas do tipo CWE-200

4.975 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2026-100241HIGHPrivate change tags exposed to anonymous users via revision-tags-change eventsEPSS 0.3%CVE-2025-11760MEDIUMeRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams <= 1.5.6 - Unauthenticated Sensitive Information ExposureEPSS 0.3%CVE-2026-62490MEDIUMVulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions tEPSS 0.3%CVE-2025-26485MEDIUMA vulnerability in Beta80 Life 1st enables the retrieval of different error messages for failed authentication attempts (in case of the usaEPSS 0.3%CVE-2026-33004MEDIUMJenkins LoadNinja Plugin 2.1 and earlier does not mask LoadNinja API keys displayed on the job configuration form, increasing the potential EPSS 0.3%CVE-2026-42865LOWInbox Zero: Cross-account cleaner email stream exposureEPSS 0.3%CVE-2026-84658MEDIUMJenkins Script Security Plugin 1412.v7737b_3405f86 and earlier uses the `@DataBoundConstructor` annotation on a constructor that loads scripEPSS 0.3%CVE-2026-34093LOWSpecial:UserRights allows viewing user rights from private wikiEPSS 0.3%CVE-2021-0212MEDIUMContrail Networking: Administrator credentials are exposed in a plaintext fileEPSS 0.3%CVE-2023-48644MEDIUMAn issue was discovered in the Archibus app 4.0.3 for iOS. There is an XSS vulnerability in the create work request feature of the maintenanEPSS 0.3%CVE-2026-93385MEDIUMInformation leak in Paint in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain sensitive information via a crafted HTEPSS 0.3%CVE-2024-10321MEDIUMAll-in-One Addons for Elementor – WidgetKit <= 2.5.5 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor TemplatesEPSS 0.3%CVE-2024-7091MEDIUMExposure of Sensitive Information to an Unauthorized Actor in GitLabEPSS 0.3%CVE-2025-61688HIGHOmni leaks information via the APIEPSS 0.3%CVE-2024-42493MEDIUMDorsett Controls InfoScan Exposure of Sensitive Information To An Unauthorized ActorEPSS 0.3%CVE-2022-39210LOWAccess to internal files of the Nextcloud Android appEPSS 0.3%CVE-2026-103763MEDIUMSiYuan before v3.8.5 Information Disclosure via /api/notebook/getNotebookInfoEPSS 0.3%CVE-2025-10535HIGHInformation disclosure, mitigation bypass in the Privacy component in Firefox for AndroidEPSS 0.3%CVE-2026-69549HIGHVirtual Hard Disk (VHD) Miniport Driver Elevation of Privilege VulernabilityEPSS 0.3%CVE-2024-41733MEDIUMInformation Disclosure Vulnerability in SAP CommerceEPSS 0.3%