Falhas do tipo CWE-200

4.853 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2023-31133HIGHGhost vulnerable to disclosure of private API fieldsEPSS 45.7%CVE-2019-3993—ELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. A remote unauthenticated attacker can recover a user's EPSS 45.7%CVE-2024-6646MEDIUMNetgear WN604 Web Interface downloadFile.php information disclosureEPSS 45.7%CVE-2025-31486MEDIUMVite allows server.fs.deny to be bypassed with .svg or relative pathsEPSS 40.5%CVE-2026-4020HIGHGravity SMTP <= 2.1.4 - Unauthenticated Sensitive Information Exposure via REST APIEPSS 40.0%CVE-2008-0655HIGHMultiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors.EPSS 38.9%KEVCVE-2022-45354MEDIUMWordPress Download Monitor Plugin <= 4.7.60 is vulnerable to Sensitive Data ExposureEPSS 38.1%CVE-2022-22733—Access-Token in ElasticJob UI causes password disclosureEPSS 37.6%CVE-2020-7387MEDIUMSage X3 AdxAdmin Exposure of Sensitive Information to an Unauthorized ActorEPSS 36.4%CVE-2025-52488HIGHDNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user inputEPSS 35.8%CVE-2023-41323MEDIUMUsers login enumeration by unauthenticated user in GLPIEPSS 33.9%CVE-2024-3274MEDIUMD-Link DNS-320L/DNS-320LW/DNS-327L HTTP GET Request info.cgi information disclosureEPSS 33.5%CVE-2021-21816MEDIUMAn information disclosure vulnerability exists in the Syslog functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request cEPSS 32.4%CVE-2023-39677—MyPrestaModules Prestashop Module v6.2.9 and UpdateProducts Prestashop Module v3.6.9 were discovered to contain a PHPInfo information discloEPSS 32.3%CVE-1999-0524MEDIUMICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts.EPSS 32.2%CVE-2024-7339MEDIUMTVT DVR TD-2104TS-CL queryDevInfo information disclosureEPSS 32.0%CVE-2026-20133MEDIUMA vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affectEPSS 31.4%KEVCVE-2025-50154MEDIUMMicrosoft Windows File Explorer Spoofing VulnerabilityEPSS 30.2%CVE-2025-68686MEDIUMAn Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1,EPSS 29.6%KEVCVE-2021-38314MEDIUMGutenberg Template Library & Redux Framework <= 4.2.11 Sensitive Information DisclosureEPSS 29.0%