Falhas do tipo CWE-200

4.985 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2021-3736—A flaw was found in the Linux kernel. A memory leak problem was found in mbochs_ioctl in samples/vfio-mdev/mbochs.c in Virtual Function I/O EPSS 0.2%CVE-2024-54463MEDIUMThis issue was addressed with improved entitlements. This issue is fixed in macOS Sequoia 15. An app may be able to access removable volumesEPSS 0.2%CVE-2025-55342MEDIUMQuipux 4.0.1 through e1774ac allows enumeration of usernames, and accessing the Ecuadorean identification number for all registered users viEPSS 0.2%CVE-2026-20682MEDIUMA logic issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. AEPSS 0.2%CVE-2026-30613MEDIUMAn information disclosure vulnerability exists in AZIOT 1 Node Smart Switch (16amp)- WiFi/Bluetooth Enabled Software Version: 1.1.9 due to iEPSS 0.2%CVE-2026-100710MEDIUMFroxlor before 2.3.12 DKIM Private Key Disclosure via APIEPSS 0.2%CVE-2025-5281MEDIUMInappropriate implementation in BFCache in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially obtain user informaEPSS 0.2%CVE-2026-95312LOWInformation leak in Passwords in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to EPSS 0.2%CVE-2026-21999MEDIUMVulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.1. Difficult tEPSS 0.2%CVE-2026-100528MEDIUMOpenClaw before 2026.8.1 Credential Disclosure via Provider EndpointEPSS 0.2%CVE-2026-36615MEDIUMMercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 exposes an undocumented /agileconfigreset endpoint that returns internal buffer conEPSS 0.2%CVE-2024-36955HIGHALSA: hda: intel-sdw-acpi: fix usage of device_get_named_child_node()EPSS 0.2%CVE-2026-22015MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions that are affected areEPSS 0.2%CVE-2026-36602MEDIUMMercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 discloses kernel memory layout via the UPnP GetStatusInfo action. An unautheEPSS 0.2%CVE-2026-55824LOWContao crawler leaks auth credentials to external hostsEPSS 0.2%CVE-2025-43455MEDIUMA privacy issue was addressed with improved checks. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOEPSS 0.2%CVE-2025-64427HIGHZimaOS is vulnerable to Server-Side Request Forgery (SSRF)EPSS 0.2%CVE-2026-64892MEDIUM- Exposure of Sensitive Information vulnerability in Johnson Controls Easy IO Neo allows Collect Data from Common Resource Locations. This EPSS 0.2%CVE-2026-21784MEDIUMHCL IntelliOps Event Management is affected by multiple security vulnerabilities.EPSS 0.2%CVE-2025-65278HIGHAn issue was discovered in file users.json in GroceryMart commit 21934e6 (2020-10-23) allowing unauthenticated attackers to gain sensitive iEPSS 0.2%