Falhas do tipo CWE-200

4.991 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2025-13653MEDIUMUnauthorized access to documents in data streams with specially crafted requestsEPSS 0.2%CVE-2026-0747LOWExposure of sensitive information in the TeamViewer entry dashboard component in Devolutions Remote Desktop Manager 2025.3.24.0 through 2025EPSS 0.2%CVE-2026-77321MEDIUMTREK MCP trip summary bypasses delegated OAuth read scopesEPSS 0.2%CVE-2021-3923LOWA flaw was found in the Linux kernel's implementation of RDMA over infiniband. An attacker with a privileged local account can leak kernel sEPSS 0.2%CVE-2022-43901MEDIUMIBM WebSphere Automation for IBM Cloud Pak for Watson AIOps information disclosureEPSS 0.2%CVE-2023-40368MEDIUMIBM Storage Protect information disclosureEPSS 0.2%CVE-2025-8448LOWCWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause unauthorized access to sensitive cEPSS 0.2%CVE-2025-56463MEDIUMMercusys MW305R 3.30 and below is has a Transport Layer Security (TLS) certificate private key disclosure.EPSS 0.2%CVE-2023-31413MEDIUMFilebeat versions through 7.17.9 and 8.6.2 have a flaw in httpjson input that allows the http request Authorization or Proxy-Authorization hEPSS 0.2%CVE-2021-21591MEDIUMDell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerability. A local maliciouEPSS 0.2%CVE-2026-53467MEDIUMImageMagick: Information Disclosure in MNG decoder because allocated memory is left unchangedEPSS 0.2%CVE-2021-21590MEDIUMDell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerability. A local maliciouEPSS 0.2%CVE-2022-48610MEDIUMThis issue was addressed through improved state management. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2EPSS 0.2%CVE-2025-64703MEDIUMMaxKB has Information Leak in sandboxEPSS 0.2%CVE-2025-29316MEDIUMAn issue in DataPatrol Screenshot watermark, printing watermark agent v.3.5.2.0 allows a physically proximate attacker to obtain sensitive iEPSS 0.2%CVE-2023-46669MEDIUMElastic Agent / Elastic Endpoint Security local API key disclosureEPSS 0.2%CVE-2026-97317MEDIUMGiveaways and Contests by RafflePress < 1.12.27 - Unauthenticated reCAPTCHA Secret Key Disclosure via Giveaway PageEPSS 0.2%CVE-2026-92070MEDIUMInformation disclosure in the Networking componentEPSS 0.2%CVE-2026-15075HIGHIn Eclipse Vert.x versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), DefaultRedirectHandler (vertx-core) propagates alEPSS 0.2%CVE-2024-54475LOWA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma EPSS 0.2%