Falhas do tipo CWE-200

4.989 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2026-87531LOWInformation leak in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtaiEPSS 0.2%CVE-2025-10281MEDIUMInsecure URL Handling in git_clone Leading to Leaked API KeyEPSS 0.2%CVE-2025-24220MEDIUMA permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.9. An app may bEPSS 0.2%CVE-2026-11168MEDIUMInappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the rendereEPSS 0.2%CVE-2024-39527MEDIUMJunos OS: SRX Series: Low privileged user able to access sensitive information on file systemEPSS 0.2%CVE-2026-11209MEDIUMInappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the rendererEPSS 0.2%CVE-2024-40838LOWA privacy issue was addressed by moving sensitive data to a protected location. This issue is fixed in macOS Sequoia 15. A malicious app mayEPSS 0.2%CVE-2026-11180MEDIUMInappropriate implementation in SVG in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafteEPSS 0.2%CVE-2026-11271MEDIUMInappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage iEPSS 0.2%CVE-2026-11203MEDIUMInappropriate implementation in GPU in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via aEPSS 0.2%CVE-2026-50169MEDIUMAngular Service Worker Policy-Bypass & Credential-Stripping VulnerabilitiesEPSS 0.2%CVE-2026-20164MEDIUMSensitive Information Disclosure through Improper Access Control in Splunk EnterpriseEPSS 0.2%CVE-2026-25135MEDIUMOpenEMR's location resource for Group.$export operation returns entire patient/user population contact informationEPSS 0.2%CVE-2024-42179LOWHCL MyXalytics is affected by sensitive information disclosure vulnerabilityEPSS 0.2%CVE-2025-11377MEDIUMList category posts <= 0.92.0 - Authenticated (Contributor+) Information ExposureEPSS 0.2%CVE-2022-36878LOWExposure of Sensitive Information in Find My Mobile prior to version 7.2.25.14 allows local attacker to access IMEI via log.EPSS 0.2%CVE-2026-100703HIGHKyverno before 1.19.1 Cross-Namespace Data Access via globalcontext.LibEPSS 0.2%CVE-2025-24144MEDIUMAn information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.EPSS 0.2%CVE-2021-21534MEDIUMDell Hybrid Client versions prior to 1.5 contain an information exposure vulnerability. A local unauthenticated attacker may exploit this vuEPSS 0.2%CVE-2025-43215MEDIUMThe issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafted image may result iEPSS 0.2%