Falhas do tipo CWE-200

4.985 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2026-19439HIGHUltimate Gift Cards for WooCommerce 3.0.3 - 3.2.9 - Unauthenticated Gift Card Code and Customer PII Disclosure via wps_uwgc_report_detailsEPSS 0.3%CVE-2025-61639LOWSuppressed blocked IP is visible in Special:BlockList, RC, and other placesEPSS 0.3%CVE-2022-39043LOWJuiker app - Information LeakageEPSS 0.3%CVE-2026-100687HIGHBudibase Server before 3.45.0 Credential Exposure via External Table BroadcastEPSS 0.3%CVE-2024-31799MEDIUMInformation Disclosure in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to read the WiFi passphrase via thEPSS 0.3%CVE-2025-24262MEDIUMA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.4. A sandboxed aEPSS 0.3%CVE-2026-16405HIGHInformation disclosure in the Networking: WebSockets componentEPSS 0.3%CVE-2025-12677MEDIUMKiotViet Sync <= 1.8.5 - Unauthenticated Webhook Key ExposureEPSS 0.3%CVE-2026-100244HIGHCentralAuth exposes locally suppressed block information via globaluserinfo API and Special:CentralAuth (incomplete fix for CVE-2025-62669)EPSS 0.3%CVE-2025-12141LOWGrafana Alerting Editors can edit destination of webhooks they did not createEPSS 0.3%CVE-2024-23104MEDIUMAn exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.8, FortiNEPSS 0.3%CVE-2025-20377MEDIUMCisco Unified Intelligence Center API Information Disclosure VulnerabilityEPSS 0.3%CVE-2022-32849MEDIUMAn information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big SuEPSS 0.3%CVE-2025-13215MEDIUMShortcodes and extra features for Phlox theme <= 2.17.13 - Unauthenticated Draft Posts Information ExposureEPSS 0.3%CVE-2024-4220MEDIUMInformation Disclosure in BeyondInsightEPSS 0.3%CVE-2025-61164HIGHCohere North AI v1.1.5 was discovered to contain an information leak via the WebSocket Endpoint.EPSS 0.3%CVE-2025-12098MEDIUMAcademy LMS Pro <= 3.3.8 - Unauthenticated Sensitive Information Exposure via 'enqueue_social_login_script'EPSS 0.3%CVE-2025-12584MEDIUMQuick View for WooCommerce <= 2.2.17 - Unauthenticated Private Product DisclosureEPSS 0.3%CVE-2025-24280MEDIUMAn access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app mEPSS 0.3%CVE-2024-23236MEDIUMA correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5. An app may be able to read arbitrary filesEPSS 0.3%