Falhas do tipo CWE-200

4.993 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2025-20158MEDIUMCisco Video Phone 8875 and Desk Phone 9800 Series Information Disclosure VulnerabilityEPSS 0.2%CVE-2024-1591LOWPrivilege Management for Windows < 24.1 Information LeakEPSS 0.2%CVE-2026-60318LOWVulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Patchset Assistant). Supported versions that arEPSS 0.2%CVE-2024-57096MEDIUMAn issue in wps office before v.19302 allows a local attacker to obtain sensitive information via a crafted file.EPSS 0.2%CVE-2025-43360MEDIUMThe issue was addressed with improved UI. This issue is fixed in iOS 26 and iPadOS 26. Password fields may be unintentionally revealed.EPSS 0.2%CVE-2026-24198MEDIUMNVIDIA GPU Display Driver for Linux contains a vulnerability where an advanced attacker could use a race condition to leak sensitive memoryEPSS 0.2%CVE-2024-23563LOWHCL Connections Docs is vulnerable to a sensitive information disclosureEPSS 0.2%CVE-2026-60405LOWVulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The suppoEPSS 0.2%CVE-2026-44276MEDIUMDell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Exposure of Sensitive Information to an Unauthorized Actor vulneraEPSS 0.2%CVE-2026-83277HIGHVulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that isEPSS 0.2%CVE-2026-20166MEDIUMSensitive Information Disclosure in Discover Splunk Observability Cloud app for Splunk EnterpriseEPSS 0.2%CVE-2026-84626LOWAn information disclosure issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPEPSS 0.2%CVE-2026-65371LOWThis issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15EPSS 0.2%CVE-2026-46406MEDIUMClaude Code: Insecure Temporary File in /copy Command Enables Response Disclosure and Symlink-Based File WriteEPSS 0.2%CVE-2026-86883MEDIUMA privacy issue was addressed with improved handling of files. This issue is fixed in iOS 27 and iPadOS 27, visionOS 27. An app may be able EPSS 0.2%CVE-2025-61679HIGHAnyquery Unauthenticated Access Vulnerability Exposes Private Integration DataEPSS 0.2%CVE-2026-15642LOWInsertion of sensitive information into a file in the Recovery Kit response file generation feature in Devolutions Server 2026.1.22.0, 2026.EPSS 0.2%CVE-2025-31982LOWHCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed directlEPSS 0.2%CVE-2026-28877MEDIUMAn authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOEPSS 0.2%CVE-2026-49356LOWBabel: Arbitrary File Read via sourceMappingURL Comment in @babel/coreEPSS 0.2%