Falhas do tipo CWE-200

4.979 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2025-11644LOWTomofun Furbo 360/Furbo Mini UART sensitive informationEPSS 0.3%CVE-2024-49734HIGHIn multiple functions of ConnectivityService.java, there is a possible way for a Wi-Fi AP to determine what site a device has connected to tEPSS 0.3%CVE-2025-68436MEDIUMCraft CMS vulnerable to potential information disclosure via unchecked asset relocationEPSS 0.3%CVE-2024-53858MEDIUMRecursive repository cloning can leak authentication tokens to non-GitHub submodule hosts in the gh cliEPSS 0.3%CVE-2026-69212MEDIUMHttp4s: FollowRedirect middleware leaks credentials over https->http same-authority redirectEPSS 0.3%CVE-2020-25836MEDIUMPotential information leakage resulting in unauthorized accessEPSS 0.3%CVE-2026-35140LOWHCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerabilityEPSS 0.3%CVE-2026-0411MEDIUMA Sensitive Information Disclosure Vulnerability in NETGEAR Orbi SatellitesEPSS 0.3%CVE-2025-11151HIGHInformation Disclosure in Beyaz Computer's CityPLusEPSS 0.3%CVE-2023-5551LOWMoodle: forum summary report shows students from other groups when in separate groups modeEPSS 0.3%CVE-2022-42815MEDIUMThis issue was addressed with improved data protection. This issue is fixed in macOS Ventura 13. An app may be able to access user-sensitiveEPSS 0.3%CVE-2026-39372MEDIUMInvoicePlane: Sensitive Information Disclosure via Unstripped EXIF Metadata in AttachmentsEPSS 0.3%CVE-2024-32051MEDIUMInsertion of sensitive information into log file issue exists in RoamWiFi R10 prior to 4.8.45. If this vulnerability is exploited, a networkEPSS 0.3%CVE-2026-67406MEDIUMRabbitMQ: Federation and Shovel Gen-Servers Lack format_status Callback — Plaintext Credentials Exposed in Crash Dumps and sys:get_statusEPSS 0.3%CVE-2026-76692HIGHUnauthenticated Adjacent Information Disclosure and Denial-of-Service Vulnerability in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.3%CVE-2025-31207HIGHA logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5. An app may be able to enumerate a user's EPSS 0.3%CVE-2026-12111MEDIUMAppointment Booking Calendar <= 1.4.01 - Authenticated (Contributor+) Sensitive Information Exposure via 'id' ParameterEPSS 0.3%CVE-2026-24487MEDIUMOpenEMR has FHIR Patient Compartment Bypass in CareTeam ResourceEPSS 0.3%CVE-2026-82385MEDIUMApache Roller: Weblog template include escapes the Velocity sandbox and reads classpath filesEPSS 0.3%CVE-2025-30443MEDIUMA privacy issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4, macOS Sequoia 15.5, macOS Sonoma 1EPSS 0.3%