Falhas do tipo CWE-200

4.992 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2025-11634LOWTomofun Furbo 360/Furbo Mini UART information disclosureEPSS 0.2%CVE-2023-46115HIGHUpdater Private Keys Possibly Leaked via Vite Environment Variables in tauri-cliEPSS 0.2%CVE-2026-60449HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are EPSS 0.2%CVE-2026-54565MEDIUMrhwp browser extension performs SSRF / private-network requests and leaks HWP preview data to untrusted pagesEPSS 0.2%CVE-2025-66290MEDIUMOrangeHRM is Vulnerable to Improper Authorization Allowing Unauthorized Access to Candidate AttachmentsEPSS 0.2%CVE-2023-30841MEDIUMIronic and ironic-inspector deployed within Baremetal Operator may expose as ConfigMapsEPSS 0.2%CVE-2026-22251MEDIUMwlc may leak API keys due to an insecure API key configurationEPSS 0.2%CVE-2022-20497MEDIUMIn updatePublicMode of NotificationLockscreenUserManagerImpl.java, there is a possible way to reveal sensitive notifications on the lockscreEPSS 0.2%CVE-2026-54785MEDIUMgemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline modeEPSS 0.2%CVE-2026-73047HIGHsiyuan before v3.7.4 Server-Side Template Injection via attribute-viewEPSS 0.2%CVE-2026-61082MEDIUMVulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.7.0-9.7.EPSS 0.2%CVE-2019-3767HIGHDell ImageAssist versions prior to 8.7.15 contain an information disclosure vulnerability. Dell ImageAssist stores some sensitive encrypted EPSS 0.2%CVE-2022-36835LOWImplicit Intent hijacking vulnerability in Samsung Internet Browser prior to version 17.0.7.34 allows attackers to access arbitrary files.EPSS 0.2%CVE-2024-39314MEDIUMtoy-blog administrative token leaked through the command line parameterEPSS 0.2%CVE-2024-45039MEDIUMgnark's Groth16 commitment extension unsound for more than one commitmentEPSS 0.2%CVE-2026-54689MEDIUMmcp-searxng hardened-mode SSRF bypasses permit internal URL accessEPSS 0.2%CVE-2022-38654MEDIUMHCL Domino is susceptible to an information disclosure vulnerabilityEPSS 0.2%CVE-2025-31236MEDIUMAn information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.5. An app may be able EPSS 0.2%CVE-2025-30222LOWShescape has potential environment variable exposure on Windows with CMDEPSS 0.2%CVE-2026-96526LOWMCP Server for WordPress < 1.8.2 - Contributor+ Arbitrary Post Title Disclosure via workflows/run REST RouteEPSS 0.2%