Falhas do tipo CWE-200

4.989 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2021-21534MEDIUMDell Hybrid Client versions prior to 1.5 contain an information exposure vulnerability. A local unauthenticated attacker may exploit this vuEPSS 0.2%CVE-2026-11424HIGHServer-Side Request Forgery in Altium Platform Design GraphQL Service Allows Information DisclosureEPSS 0.2%CVE-2026-1307MEDIUMNinja Forms <= 3.14.1 - Authenticated (Contributor+) Sensitive Information Disclosure via Block Editor TokenEPSS 0.2%CVE-2024-24891MEDIUMInformation Leakage in kernelEPSS 0.2%CVE-2025-55272LOWHCL Aftermarket DPC is affected by Banner Disclosure vulnerabilityEPSS 0.2%CVE-2024-24898MEDIUMInformation Leakage in kernelEPSS 0.2%CVE-2022-32824—The issue was addressed with improved memory handling. This issue is fixed in tvOS 15.6, watchOS 8.7, iOS 15.6 and iPadOS 15.6. An app may bEPSS 0.2%CVE-2025-54548MEDIUMOn affected platforms, restricted users could view sensitive portions of the config database via a debug API (e.g., user password hashes)EPSS 0.2%CVE-2025-64324HIGHKubeVirt Vulnerable to Arbitrary Host File Read and WriteEPSS 0.2%CVE-2026-79147MEDIUMInformation leak in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potenEPSS 0.2%CVE-2022-33181MEDIUMAn information disclosure vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5, 7.4.2.j could aEPSS 0.2%CVE-2023-22307MEDIUMSite-Passwords in GET parametersEPSS 0.2%CVE-2024-54119MEDIUMCross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service EPSS 0.2%CVE-2025-6461MEDIUMCubeWP – All-in-One Dynamic Content Framework <= 1.1.27 - Unauthenticated Post Disclosure in class-cubewp-search-ajax-hooks.phpEPSS 0.2%CVE-2024-32754LOWJohnson Controls Kantech KT1, KT2, and KT400 Door Controllers - Exposure of Sensitive InformationEPSS 0.2%CVE-2026-94185MEDIUMnvm alias resolution follows `..` and discloses files outside $NVM_DIR/aliasEPSS 0.2%CVE-2026-1867MEDIUMWP Front User Submit < 5.0.6 - Unauthenticated Sensitive Information ExposureEPSS 0.2%CVE-2026-67448MEDIUMMailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689)EPSS 0.2%CVE-2021-36341MEDIUMDell Wyse Device Agent version 14.5.4.1 and below contain a sensitive data exposure vulnerability. A local authenticated user with low priviEPSS 0.2%CVE-2025-25370MEDIUMAn issue in realme GT 2 (RMX3311) running Android 14 with realme UI 5.0 allows a physically proximate attacker to obtain sensitive informatiEPSS 0.2%