Falhas do tipo CWE-200

5.017 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2024-53011HIGHPermissions, Privileges, and Access Controls in Video Analytics and ProcessingEPSS 0.1%CVE-2026-81322LOWCloaked plaintext leaks through a non-sensitive action argument in AshCloakEPSS 0.1%CVE-2025-71280MEDIUMXenForo Local Account Page Caching Information DisclosureEPSS 0.1%CVE-2024-27277MEDIUMIBM Storage Protect Plus Server information disclosureEPSS 0.1%CVE-2026-20730LOWBIG-IP Edge Client for Windows vulnerabilityEPSS 0.1%CVE-2022-42782MEDIUMIn wlan driver, there is a possible missing permission check, This could lead to local information disclosure.EPSS 0.1%CVE-2017-18306HIGHInformation Exposure in Camera DriverEPSS 0.1%CVE-2023-25536MEDIUM Dell PowerScale OneFS 9.4.0.x contains exposure of sensitive information to an unauthorized actor. A malicious authenticated local user couEPSS 0.1%CVE-2017-18307HIGHInformation Exposure in KernelEPSS 0.1%CVE-2022-39913MEDIUMExposure of Sensitive Information to an Unauthorized Actor in Persona Manager prior to Android T(13) allows local attacker to access user prEPSS 0.1%CVE-2022-40525HIGHInformation Exposure in Linux Networking FirmwareEPSS 0.1%CVE-2022-42766MEDIUMIn wlan driver, there is a possible missing permission check, This could lead to local information disclosure.EPSS 0.1%CVE-2023-21624MEDIUMInformation Exposure in DSP ServicesEPSS 0.1%CVE-2022-40523HIGHInformation exposure in KernelEPSS 0.1%CVE-2024-43046MEDIUMInformation Exposure in TZ Secure OSEPSS 0.1%CVE-2024-5464MEDIUMVulnerability of insufficient permission verification in the NearLink module Impact: Successful exploitation of this vulnerability may affecEPSS 0.1%CVE-2026-43942MEDIUMelecterm: Full process.env exposed to renderer via window.pre.env in electermEPSS 0.1%CVE-2026-58554MEDIUMPermission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiEPSS 0.1%CVE-2023-21267—In multiple functions of KeyguardViewMediator.java, there is a possible way to bypass lockdown mode with screen pinning due to a logic errorEPSS 0.1%CVE-2025-68467LOWDark Reader gives users the ability to request style sheets from local web serversEPSS 0.1%