Falhas do tipo CWE-200

4.980 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2025-26711MEDIUMThere is an unauthorized access vulnerability in ZTE T5400. Due to improper permission control of the Web module interface, an unauthorized EPSS 0.3%CVE-2024-42208LOWHCL Connections is vulnerable to an information disclosure vulnerabilityEPSS 0.3%CVE-2026-78908MEDIUMInformation leak in Canvas in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML EPSS 0.3%CVE-2025-11717CRITICALThe password edit screen was not hidden in Android card viewEPSS 0.3%CVE-2022-37909MEDIUMAruba has identified certain configurations of ArubaOS that can lead to sensitive information disclosure from the configured ESSIDs. The sceEPSS 0.3%CVE-2026-78987MEDIUMInformation leak in Canvas in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML EPSS 0.3%CVE-2026-78895MEDIUMInformation leak in Paint in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML pEPSS 0.3%CVE-2023-21067—Product: AndroidVersions: Android kernelAndroid ID: A-254114726References: N/AEPSS 0.3%CVE-2026-60371HIGHVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.3%CVE-2025-40757MEDIUMA vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All versions), TALON TC SEPSS 0.3%CVE-2025-24134MEDIUMAn information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.3. An app may be able EPSS 0.3%CVE-2021-25331LOWImproper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to balance information over the lockscreEPSS 0.3%CVE-2021-25332LOWImproper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to contacts information over the lockscrEPSS 0.3%CVE-2024-1949LOWA race condition in Mattermost versions 8.1.x before 8.1.9, and 9.4.x before 9.4.2 allows an authenticated attacker to gain unauthorized accEPSS 0.3%CVE-2021-25333LOWImproper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to balance information over the lockscreEPSS 0.3%CVE-2023-21237MEDIUMIn applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service notification due to misleading orEPSS 0.3%KEVCVE-2025-27387HIGHOPPO Clone Phone uses weak WPA passphrase as only means of securityEPSS 0.3%CVE-2022-32875MEDIUMA logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, watchOS 9, EPSS 0.3%CVE-2026-60589LOWVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: SecuritEPSS 0.3%CVE-2026-14049MEDIUMInappropriate implementation in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer proceEPSS 0.3%