Falhas do tipo CWE-200

4.980 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2026-61304MEDIUMVulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations). Supported versions that aEPSS 0.3%CVE-2026-62525MEDIUMVulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Quality Workbench HTML system). Supported versions that EPSS 0.3%CVE-2025-24281MEDIUMThis issue was addressed with improved data protection. This issue is fixed in macOS Sequoia 15.4. An app may be able to access sensitive usEPSS 0.3%CVE-2026-62519MEDIUMVulnerability in the Oracle Succession planning product of Oracle E-Business Suite (component: Succession plan). Supported versions that arEPSS 0.3%CVE-2026-91992HIGHTornado before 6.5.7 Credential Leak via Handle ReuseEPSS 0.3%CVE-2026-12117MEDIUMImproper access control in the social login connection endpoint in Devolutions Server 2026.2.5 allows an authenticated vault member to enuEPSS 0.3%CVE-2025-62524MEDIUMPILOS Exposes PHP versionEPSS 0.3%CVE-2025-30435MEDIUMThis issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.4. A sandboxed app may beEPSS 0.3%CVE-2025-53840LOWIcinga DB Web Exposure of Sensitive Information to an Unauthorized Actor vulnerabilityEPSS 0.3%CVE-2025-51643LOWMeitrack T366G-L GPS Tracker devices contain an SPI flash chip (Winbond 25Q64JVSIQ) that is accessible without authentication or tamper protEPSS 0.3%CVE-2021-20320—A flaw was found in s390 eBPF JIT in bpf_jit_insn in arch/s390/net/bpf_jit_comp.c in the Linux kernel. In this flaw, a local attacker with sEPSS 0.3%CVE-2025-24282MEDIUMA library injection issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4. An app may be able to modifEPSS 0.3%CVE-2024-11994MEDIUMAPM Server Insertion of Sensitive Information into Log FileEPSS 0.3%CVE-2026-23597MEDIUMUnauthenticated Information Disclosure in application API allows sensitive system information exposureEPSS 0.3%CVE-2022-32825MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tEPSS 0.3%CVE-2022-27575LOWInformation exposure vulnerability in One UI Home prior to SMR April-2022 Release 1 allows to access currently launched foreground app inforEPSS 0.3%CVE-2026-84127MEDIUMInformation disclosure in the WebExtensions component in Firefox for AndroidEPSS 0.3%CVE-2026-78896MEDIUMInformation leak in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a craEPSS 0.3%CVE-2026-9955MEDIUMInappropriate implementation in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via EPSS 0.3%CVE-2026-7999MEDIUMInappropriate implementation in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtain potentially sensitive informaEPSS 0.3%