Falhas do tipo CWE-200

4.980 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2023-45816LOWUnread bookmark reminder notifications that the user cannot access can be seenEPSS 0.3%CVE-2024-44685MEDIUMTitan SFTP and Titan MFT Server 2.0.25.2426 and earlier have a vulnerability a vulnerability where sensitive information, including passwordEPSS 0.3%CVE-2026-9656MEDIUMHubSpot All-In-One Marketing <= 11.3.62 - Authenticated (Contributor+) Sensitive Information Exposure via Block Editor Localized ScriptEPSS 0.3%CVE-2020-6653LOWSensitive date stored in logcat fileEPSS 0.3%CVE-2026-105120MEDIUMOpenAM before 16.1.3 Cross-Realm Session Disclosure via Sessions REST EndpointEPSS 0.3%CVE-2026-14049MEDIUMInappropriate implementation in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer proceEPSS 0.3%CVE-2026-61214LOWVulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are EPSS 0.3%CVE-2021-21512HIGHDell EMC PowerProtect Cyber Recovery, version 19.7.0.1, contains an Information Disclosure vulnerability. A locally authenticated high priviEPSS 0.3%CVE-2022-0987—A flaw was found in PackageKit in the way some of the methods exposed by the Transaction interface examines files. This issue allows a localEPSS 0.3%CVE-2023-38296HIGHVarious software builds for the following TCL 30Z and TCL A3X devices leak the ICCID to a system property that can be accessed by any local EPSS 0.3%CVE-2023-36476HIGH`calamares-nixos-extensions` LUKS keyfile exposureEPSS 0.3%CVE-2021-32007LOWMissing security header: Referrer-Policy URLEPSS 0.3%CVE-2026-60950LOWVulnerability in the Oracle HRMS (Ireland) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that areEPSS 0.3%CVE-2025-13804MEDIUMnutzam NutzBoot Ethereum Wallet EthModule.java information disclosureEPSS 0.3%CVE-2026-62525MEDIUMVulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Quality Workbench HTML system). Supported versions that EPSS 0.3%CVE-2026-61304MEDIUMVulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations). Supported versions that aEPSS 0.3%CVE-2025-11406MEDIUMkaifangqian kaifangqian-base SysUserController.java getAllUsers information disclosureEPSS 0.3%CVE-2026-62524MEDIUMVulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll - General). Supported versions that are affEPSS 0.3%CVE-2026-91992HIGHTornado before 6.5.7 Credential Leak via Handle ReuseEPSS 0.3%CVE-2025-65957HIGHCore Bot is Leaking Sensitive Credentials in Logs, Errors, and MessagesEPSS 0.3%