Falhas do tipo CWE-200

4.994 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2026-47165MEDIUMImageMagick: Information Disclosure in distributed pixel cache server because it is not using a challenge–response authentication modelEPSS 0.1%CVE-2025-61482HIGHImproper handling of OTP/TOTP/HOTP values in NetKnights GmbH privacyIDEA Authenticator v.4.3.0 on Android allows local attackers with root aEPSS 0.1%CVE-2026-34268LOWVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: SecuritEPSS 0.1%CVE-2026-20647MEDIUMThis issue was addressed with improved data protection. This issue is fixed in macOS Tahoe 26.3. An app may be able to access sensitive userEPSS 0.1%CVE-2026-20641HIGHA privacy issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS SeqEPSS 0.1%CVE-2025-23290LOWNVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a guest could get global GPU metrics which may be influencedEPSS 0.1%CVE-2026-20606HIGHThis issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macEPSS 0.1%CVE-2025-11697HIGHStudio 5000 ® Simulation Interface Local Code ExecutionEPSS 0.1%CVE-2026-0245MEDIUMPrisma Access Agent: Information Disclosure VulnerabilitiesEPSS 0.1%CVE-2025-24090LOWA permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3. An app may be able to enumeEPSS 0.1%CVE-2026-20623MEDIUMA permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.4, macOS Tahoe 26.3. An app mayEPSS 0.1%CVE-2026-22101MEDIUMSensitive information leak through hidden menuEPSS 0.1%CVE-2023-5339MEDIUMMattermost Desktop logs all keystrokes during initial run after fresh installation EPSS 0.1%CVE-2024-34684LOWInformation Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Scheduling)EPSS 0.1%CVE-2026-33448MEDIUMFormat string vulnerability in MacOS clients prior to 14.50EPSS 0.1%CVE-2026-16973MEDIUMVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.1%CVE-2024-38798MEDIUMUncleared password keystrokes in circular queue can lead to information disclosure or escalation of privilegeEPSS 0.1%CVE-2026-20612MEDIUMA privacy issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An aEPSS 0.1%CVE-2020-9089LOWThere is an information vulnerability in Huawei smartphones. A function in a module can be called without verifying the caller's access. AttEPSS 0.1%CVE-2025-67499MEDIUMCNI Plugins Portmap nftables backend intercepts non-local trafficEPSS 0.1%