Falhas do tipo CWE-200

4.986 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2026-76089HIGHFormie: Missing authorization on sent notification resend modal exposes submission PIIEPSS 0.2%CVE-2021-4023—A flaw was found in the io-workqueue implementation in the Linux kernel versions prior to 5.15-rc1. The kernel can panic when an improper caEPSS 0.2%CVE-2022-23157MEDIUMWyse Device Agent version 14.6.1.4 and below contain a sensitive data exposure vulnerability. A authenticated malicious user could potentialEPSS 0.2%CVE-2025-20624MEDIUMExposure of sensitive information to an unauthorized actor for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow aEPSS 0.2%CVE-2025-52631LOWHCL AION is affected by a Missing or Insecure HTTP Strict-Transport-Security (HSTS) Header vulnerability.EPSS 0.2%CVE-2025-52634LOWHCL AION is susceptible to Spring Boot Actuator Endpoints ExposedEPSS 0.2%CVE-2025-52630LOWHCL AION is susceptible to Missing or insecure "X-Content-Type-Options" header vulnerabilityEPSS 0.2%CVE-2026-101092MEDIUMSiYuan before v3.8.4 Information Disclosure via getCurrentAttrViewImagesEPSS 0.2%CVE-2026-100719HIGHFroxlor before 2.3.12 Credential Disclosure via DirProtections APIEPSS 0.2%CVE-2025-59019MEDIUMInformation Disclosure via CSV DownloadEPSS 0.2%CVE-2024-0340MEDIUMKernel: information disclosure in vhost/vhost.c:vhost_new_msg()EPSS 0.2%CVE-2025-52372MEDIUMAn issue in hMailServer v.5.8.6 allows a local attacker to obtain sensitive information via the hmailserver/installation/hMailServerInnoExteEPSS 0.2%CVE-2026-2244HIGHSensitive Data Exposure in Google Cloud Vertex AI WorkbenchEPSS 0.2%CVE-2025-4426MEDIUMSetupAutomationSmm : SMRAM memory contents leak / information disclosure vulnerability in SMM moduleEPSS 0.2%CVE-2025-61885MEDIUMVulnerability in the Oracle Life Sciences InForm product of Oracle Health Sciences Applications (component: Web Server). The supported verEPSS 0.2%CVE-2026-67104MEDIUMHCL BigFix Service Management is affected by multiple security vulnerabilities.EPSS 0.2%CVE-2026-79207MEDIUMInformation leak in Passwords in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to obtain sensitive information viaEPSS 0.2%CVE-2026-78981MEDIUMInformation leak in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to potentially obtain sensitive informEPSS 0.2%CVE-2025-11639MEDIUMTomofun Furbo 360/Furbo Mini Debug Log S3 Bucket collect_logs.sh sensitive informationEPSS 0.2%CVE-2021-21536MEDIUMDell Hybrid Client versions prior to 1.5 contain an information exposure vulnerability. A local unauthenticated attacker may exploit this vuEPSS 0.2%