Falhas do tipo CWE-200

4.796 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2026-20847MEDIUMMicrosoft Windows File Explorer Spoofing VulnerabilityEPSS 1.4%CVE-2021-22913—Nextcloud Deck before 1.2.7, 1.4.1 suffers from an information disclosure vulnerability when searches for sharees utilize the lookup server EPSS 1.4%CVE-2021-22912—Nextcloud iOS before 3.4.2 suffers from an information disclosure vulnerability when searches for sharees utilize the lookup server by defauEPSS 1.4%CVE-2018-10859MEDIUMgit-annex is vulnerable to an Information Exposure when decrypting files. A malicious server for a special remote could trick git-annex intoEPSS 1.4%CVE-2022-27667—Under certain conditions, SAP BusinessObjects Business Intelligence platform, Client Management Console (CMC) - version 430, allows an attacEPSS 1.4%CVE-2021-32711CRITICALLeak of information via Store-APIEPSS 1.4%CVE-2023-38158LOWMicrosoft Edge (Chromium-based) Information Disclosure VulnerabilityEPSS 1.3%CVE-2025-26263MEDIUMGeoVision ASManager Windows desktop application with the version 6.1.2.0 or less (fixed in 6.2.0), is vulnerable to credentials disclosure dEPSS 1.3%CVE-2022-2221—Information Exposure vulnerability in My Account Settings of Devolutions Remote Desktop Manager before 2022.1.8 allows authenticated users tEPSS 1.3%CVE-2024-29291—An issue in Laravel Framework 8 through 11 might allow a remote attacker to discover database credentials in storage/logs/laravel.log. NOTE:EPSS 1.3%CVE-2026-45332HIGHAutomad Broken Access Control: unauthenticated exposure of administrator bcrypt password hashes and TOTP secrets via public API endpointEPSS 1.3%CVE-2022-39201MEDIUMData source and plugin proxy endpoints could leak the authentication cookie to some destination pluginsEPSS 1.3%CVE-2018-1090MEDIUMIn Pulp before version 2.16.2, secrets are passed into override_config when triggering a task and then become readable to all users with reaEPSS 1.3%CVE-2016-7047MEDIUMA flaw was found in the CloudForms API before 5.6.3.0, 5.7.3.1 and 5.8.1.2. A user with permissions to use the MiqReportResults capability wEPSS 1.3%CVE-2014-0778—Progea Movicon SCADA Exposure of Sensitive Information to an Unauthorized ActorEPSS 1.3%CVE-2022-25602HIGHWordPress Responsive Menu plugin <= 4.1.7 - Nonce token leak leading to arbitrary file upload, theme deletion, plugin settings change vulnerabilityEPSS 1.3%CVE-2018-16477—A bypass vulnerability in Active Storage >= 5.2.0 for Google Cloud Storage and Disk services allow an attacker to modify the `content-disposEPSS 1.3%CVE-2018-13290MEDIUMInformation exposure vulnerability in SYNO.Core.ACL in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote authenticated users tEPSS 1.3%CVE-2018-13292MEDIUMInformation exposure vulnerability in /usr/syno/etc/mount.conf in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote authenticaEPSS 1.3%CVE-2020-7506—A CWE-200: Information Exposure vulnerability exists in Easergy T300, Firmware V1.5.2 and prior, which could allow an attacker to pack or unEPSS 1.3%