Falhas do tipo CWE-200

5.020 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2023-23588MEDIUMA vulnerability has been identified in SIMATIC IPC1047 (All versions), SIMATIC IPC1047E (All versions with maxView Storage Manager < 4.09.00EPSS 0.1%CVE-2025-68965MEDIUMPermission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect service confidentiaEPSS 0.1%CVE-2025-26453MEDIUMIn isContentUriForOtherUser of BluetoothOppSendFileInfo.java, there is a possible cross user data leak due to a logic error in the code. ThiEPSS 0.1%CVE-2022-38686MEDIUMIn wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.EPSS 0.1%CVE-2022-47367MEDIUMIn bluetooth driver, there is a missing permission check. This could lead to local information disclosure with no additional execution priviEPSS 0.1%CVE-2025-63729CRITICALAn issue was discovered in Syrotech SY-GPON-1110-WDONT SYRO_3.7L_3.1.02-240517 allowing attackers to exctract the SSL Private Key, CA CertifEPSS 0.1%CVE-2025-64311MEDIUMPermission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect service confidentiaEPSS 0.1%CVE-2022-47324MEDIUMIn wlan driver, there is a possible missing permission check. This could lead to local information disclosure.EPSS 0.1%CVE-2022-47325MEDIUMIn wlan driver, there is a possible missing permission check. This could lead to local information disclosure.EPSS 0.1%CVE-2022-47328MEDIUMIn wlan driver, there is a possible missing permission check. This could lead to local information disclosure.EPSS 0.1%CVE-2022-47329MEDIUMIn wlan driver, there is a possible missing permission check. This could lead to local information disclosure.EPSS 0.1%CVE-2022-47326MEDIUMIn wlan driver, there is a possible missing permission check. This could lead to local information disclosure.EPSS 0.1%CVE-2026-41520HIGHCillium exposes sensitive information included in the cilium-bugtool debug archiveEPSS 0.1%CVE-2023-4164HIGHThere is a possible information disclosure due to a missing permission check in Pixel WatchEPSS 0.1%CVE-2023-40108MEDIUMIn multiple locations, there is a possible way to access media content belonging to another user due to a missing permission check. This couEPSS 0.1%CVE-2024-49733MEDIUMIn reload of ServiceListing.java , there is a possible way to allow a malicious app to hide an NLS from Settings due to a logic error in theEPSS 0.1%CVE-2026-62364LOWwlc may disclose API tokens to project-configured URLsEPSS 0.1%CVE-2025-47369MEDIUMInformation Exposure in Computer VisionEPSS 0.1%CVE-2026-0197MEDIUMIn VPU, there is a possible information dislclosure due to a logic error in the code. This could lead to local information disclosure with SEPSS 0.1%CVE-2025-58279MEDIUMPermission control vulnerability in the media library module. Impact: Successful exploitation of this vulnerability may affect service confiEPSS 0.1%