Falhas do tipo CWE-200

5.018 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2024-20292MEDIUMA vulnerability in the logging component of Cisco Duo Authentication for Windows Logon and RDP could allow an authenticated, local attacker EPSS 0.1%CVE-2026-79055MEDIUMInformation leak in Sharing in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker leveraging social engineering to EPSS 0.1%CVE-2026-78806MEDIUMAn issue in Matter Standard Specification-Implementation gap v1.5.1 Matter Project Chip V1.5.1 allows a local attacker to obtain sensitive iEPSS 0.1%CVE-2025-54615MEDIUMVulnerability of insufficient information protection in the media library module. Impact: Successful exploitation of this vulnerability may EPSS 0.1%CVE-2024-20503MEDIUMCisco Duo Epic for Hyperdrive Information Disclosure VulnerabilityEPSS 0.1%CVE-2024-0020MEDIUMIn onActivityResult of NotificationSoundPreference.java, there is a possible way to hear audio files belonging to a different user due to a EPSS 0.1%CVE-2021-25357MEDIUMA pendingIntent hijacking vulnerability in Create Movie prior to SMR APR-2021 Release 1 in Android O(8.x) and P(9.0), 3.4.81.1 in Android Q(EPSS 0.1%CVE-2025-58278MEDIUMIdentity authentication bypass vulnerability in the Gallery app. Successful exploitation of this vulnerability may affect service confidentiEPSS 0.1%CVE-2025-48635HIGHIn multiple functions of TaskFragmentOrganizerController.java, there is a possible activity token leak due to a logic error in the code. ThiEPSS 0.1%CVE-2026-11459MEDIUMSecureAge CatchPulse IOCTL saappctl.sys information disclosureEPSS 0.1%CVE-2026-102709HIGHImproper validation of non-secure (NS) pointers in multiple TrustZone-M non-secure callable (NSC) entry functions allows an attacker executiEPSS 0.1%CVE-2026-0025HIGHIn hasImage of Notification.java, there is a possible way to reveal information across users due to a permissions bypass. This could lead toEPSS 0.1%CVE-2018-9384MEDIUMIn multiple locations, there is a possible way to bypass KASLR due to an unusual root cause. This could lead to local information disclosureEPSS 0.1%CVE-2024-58047MEDIUMPermission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service cEPSS 0.1%CVE-2024-58049MEDIUMPermission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service cEPSS 0.1%CVE-2021-25392MEDIUMImproper protection of backup path configuration in Samsung Dex prior to SMR MAY-2021 Release 1 allows local attackers to get sensitive infoEPSS 0.1%CVE-2022-33686LOWExposure of Sensitive Information in GsmAlarmManager prior to SMR Jul-2022 Release 1 allows local attacker to access iccid via log.EPSS 0.1%CVE-2025-48527MEDIUMIn multiple locations, there is a possible way to leak hidden work profile notifications due to a logic error in the code. This could lead tEPSS 0.1%CVE-2024-56193MEDIUMThere is a possible disclosure of Bluetooth adapter details due to a permissions bypass. This could lead to local information disclosure witEPSS 0.1%CVE-2026-0305MEDIUMPrisma Access Agent: Information Disclosure Vulnerability on LinuxEPSS 0.1%