Falhas do tipo CWE-200

4.992 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2022-3745MEDIUMA potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevatEPSS 0.2%CVE-2026-82850MEDIUMMasteriyo LMS < 3.4.2 - Subscriber+ Quiz Answer Key DisclosureEPSS 0.2%CVE-2026-10864MEDIUMMISP Dashboard widget field selection may expose restricted user and organisation dataEPSS 0.2%CVE-2026-70916MEDIUMVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.2%CVE-2021-26281MEDIUMInformation disclosure vulnerability in Alarm clock moduleEPSS 0.2%CVE-2026-90953MEDIUMImage Optimizer by Elementor < 1.7.7 - Subscriber+ Attachment Metadata and Site Statistics Disclosure via Discarded REST Permission CallbacksEPSS 0.2%CVE-2026-16557MEDIUMNimble Builder <= 3.3.8 - Subscriber+ Non-Public Content Disclosure via sek_get_nimble_content_for_seo_pluginsEPSS 0.2%CVE-2022-38689MEDIUMIn telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privEPSS 0.2%CVE-2026-70917MEDIUMVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.2%CVE-2026-86602MEDIUMWP Recipe Maker 10.3.0 - 10.8.1 - Subscriber+ Draft and Private Recipe Content Disclosure via wprm_shortcode_previewEPSS 0.2%CVE-2026-93662MEDIUMEvents Manager 7.4.1 - 7.4.4 - Subscriber+ Unpublished Event and Location Disclosure via 'owner' ParameterEPSS 0.2%CVE-2026-86603MEDIUMWP Recipe Maker < 10.8.2 - Subscriber+ Non-Public List Title Disclosure via wprm_search_listsEPSS 0.2%CVE-2022-43540MEDIUMA vulnerability exists in the ClearPass OnGuard macOS agent that allows for an attacker with local macOS instance access to potentially obtaEPSS 0.2%CVE-2026-10854MEDIUMUnauthorized exposure of private galaxies in MISP event template creationEPSS 0.2%CVE-2025-40646MEDIUMExposure of sensitive information in VidayEPSS 0.2%CVE-2023-45219MEDIUMBIG-IP tmsh vulnerabilityEPSS 0.2%CVE-2026-45683LOWOpenTelemetry eBPF Instrumentation: Java TLS ioctl kprobe allows kernel memory disclosureEPSS 0.2%CVE-2025-57837LOWTileservice module is affected by information leak vulnerability, successful exploitation of this vulnerability may affect service confidentEPSS 0.2%CVE-2025-22895MEDIUMExposure of sensitive information to an unauthorized actor for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow aEPSS 0.2%CVE-2025-40803LOWA vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions). The affected device exposes certain non-critical iEPSS 0.2%