Falhas do tipo CWE-200

4.985 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2026-84026MEDIUMDirectorist 8.1 - 8.9.4 - Unauthenticated Sensitive Data Disclosure via REST Users EndpointEPSS 0.3%CVE-2026-84741MEDIUMThe Events Calendar 4.5 - 6.17.4.1 - Unauthenticated Non-Public Venue and Organizer Disclosure via REST APIEPSS 0.3%CVE-2026-84168MEDIUMEasy Hide Login < 1.7 - Login Page Protection Bypass / Hidden URL DisclosureEPSS 0.3%CVE-2025-24261MEDIUMThe issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app mEPSS 0.3%CVE-2026-2205MEDIUMWeKan Meteor Publication cards.js CardPubSubBleed information disclosureEPSS 0.3%CVE-2026-83417HIGHVulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPEPSS 0.3%CVE-2026-76907MEDIUMLaSuite Doc: Public Documents EnumerationEPSS 0.3%CVE-2026-56597LOWHCL BigFix Service Management is affected by multiple security vulnerabilities.EPSS 0.3%CVE-2023-2820MEDIUMAn information disclosure vulnerability in the faye endpoint in Proofpoint Threat Response / Threat Response Auto-Pull (PTR/TRAP) could be uEPSS 0.3%CVE-2026-100568HIGHOpenClaw before 2026.8.1 Unauthorized Command Job AccessEPSS 0.3%CVE-2026-100548MEDIUMOpenClaw before 2026.8.1 Credential Exposure via Embedding FallbackEPSS 0.3%CVE-2022-32835LOWThis issue was addressed with improved entitlements. This issue is fixed in iOS 16, watchOS 9. An app may be able to read a persistent devicEPSS 0.3%CVE-2025-24276MEDIUMThis issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7EPSS 0.2%CVE-2026-31370MEDIUMInformation Leak Vulnerability in Honor EEPSS 0.2%CVE-2024-44139LOWThe issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18. An attacker with physical access may be able to aEPSS 0.2%CVE-2021-47403HIGHipack: ipoctal: fix module reference leakEPSS 0.2%CVE-2026-21974MEDIUMVulnerability in the Oracle Life Sciences Central Designer product of Oracle Health Sciences Applications (component: Platform). The suppoEPSS 0.2%CVE-2025-12129MEDIUMCubeWP – All-in-One Dynamic Content Framework <= 1.1.27 - Unauthenticated Information ExposureEPSS 0.2%CVE-2020-14335—A flaw was found in Red Hat Satellite, which allows a privileged attacker to read OMAPI secrets through the ISC DHCP of Smart-Proxy. This flEPSS 0.2%CVE-2023-39393—Vulnerability of insecure signatures in the ServiceWifiResources module. Successful exploitation of this vulnerability may cause ServiceWifiEPSS 0.2%