Falhas do tipo CWE-200

4.990 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2026-11464LOWJeecgBoot User List Endpoint SysUserController.java queryPageList information disclosureEPSS 0.2%CVE-2025-25370MEDIUMAn issue in realme GT 2 (RMX3311) running Android 14 with realme UI 5.0 allows a physically proximate attacker to obtain sensitive informatiEPSS 0.2%CVE-2025-43530MEDIUMThis issue was addressed with improved checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, macOS Sequoia 15.7.3, macOS Sonoma 14.8.EPSS 0.2%CVE-2024-28963MEDIUMTelemetry Dashboard v1.0.0.7 for Dell ThinOS 2402 contains a sensitive information disclosure vulnerability. An unauthenticated user with loEPSS 0.2%CVE-2025-43495MEDIUMThe issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1. An app may be aEPSS 0.2%CVE-2024-40863MEDIUMThis issue was addressed with improved data protection. This issue is fixed in iOS 18 and iPadOS 18. An app may be able to leak sensitive usEPSS 0.2%CVE-2026-100286MEDIUMMissing authorization in the data source settings API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated non-administrativEPSS 0.2%CVE-2025-13997MEDIUMKing Addons for Elementor <= 51.1.49 - Unauthenticated API Keys DisclosureEPSS 0.2%CVE-2025-24155MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.6, macOS Ventura 13.7.6.EPSS 0.2%CVE-2026-93528LOWNP Quote Request for WooCommerce < 2.4.16 - Unauthenticated Order Data Disclosure via Quote Request PageEPSS 0.2%CVE-2025-52473MEDIUMliboqs secret-dependent branching in HQC reference implementation when compiled with Clang 17-20EPSS 0.2%CVE-2022-48319MEDIUMHost secret disclosed in Checkmk logsEPSS 0.2%CVE-2026-44940MEDIUMService token exposure and potential privilege escalation in SUSE ObservabilityEPSS 0.2%CVE-2025-43367MEDIUMA privacy issue was addressed by moving sensitive data. This issue is fixed in macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to acceEPSS 0.2%CVE-2023-1075LOWA flaw was found in the Linux Kernel. The tls_is_tx_ready() incorrectly checks for list emptiness, potentially accessing a type confused entEPSS 0.2%CVE-2023-28723LOWExposure of sensitive information to an unauthorized actor in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticatEPSS 0.2%CVE-2022-32855—A logic issue was addressed with improved state management. This issue is fixed in iOS 15.6 and iPadOS 15.6. A user may be able to view restEPSS 0.2%CVE-2025-12559MEDIUMInformation Disclosure in Common Teams APIEPSS 0.2%CVE-2026-19708MEDIUMFile Manager 7.2.2 - 8.0.4 - Unauthenticated Database Backup DisclosureEPSS 0.2%CVE-2023-42936MEDIUMThis issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.EPSS 0.2%