Falhas do tipo CWE-200

4.999 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2026-75587LOWPlaintext pre-auth secret exposure via Desktop App diagnostics reportEPSS 0.1%CVE-2026-17966MEDIUMInappropriate implementation in Views in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to obtain potentially sensitivEPSS 0.1%CVE-2026-95295MEDIUMInformation leak in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a local attacker to leak sensitive information via physEPSS 0.1%CVE-2026-20678MEDIUMAn authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOEPSS 0.1%CVE-2026-20680MEDIUMThe issue was addressed with additional restrictions on the observability of app states. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5EPSS 0.1%CVE-2026-4823LOWEnter Software Iperius Backup NTLM2 information disclosureEPSS 0.1%CVE-2025-52649LOWHCL AION is affected by a vulnerability where certain identifiers may be predictable in natureEPSS 0.1%CVE-2022-46825MEDIUMIn JetBrains IntelliJ IDEA before 2022.3 the built-in web server leaked information about open projects.EPSS 0.1%CVE-2026-18011LOWInappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a local attacker to obtain potentiallyEPSS 0.1%CVE-2025-2879MEDIUMMali GPU Kernel Driver allows improper GPU processing operationsEPSS 0.1%CVE-2026-49302MEDIUMPermission control vulnerability in the notification service module. Impact: Successful exploitation of this vulnerability may affect servicEPSS 0.1%CVE-2026-100708HIGHFroxlor before 2.3.13 Private Key Disclosure via Certificates APIEPSS 0.1%CVE-2026-49307MEDIUMPermission control vulnerability in the multi-mode input module. Impact: Successful exploitation of this vulnerability may affect service coEPSS 0.1%CVE-2026-17973MEDIUMInappropriate implementation in Views in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to obtain potentially sensitivEPSS 0.1%CVE-2026-4218LOWmyAEDES App aedes.me.beta EngageBayUtils.java information disclosureEPSS 0.1%CVE-2026-83414LOWVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 15.EPSS 0.1%CVE-2026-60896LOWVulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that arEPSS 0.1%CVE-2022-39897MEDIUMExposure of Sensitive Information vulnerability in kernel prior to SMR Dec-2022 Release 1 allows attackers to access the kernel address infoEPSS 0.1%CVE-2026-11985LOWCross-thread FPU register leak on ARM when FPU enabled without register sharingEPSS 0.1%CVE-2021-25364MEDIUMA pendingIntent hijacking vulnerability in Secure Folder prior to SMR APR-2021 Release 1 allows unprivileged applications to access contact EPSS 0.1%