Falhas do tipo CWE-200

4.898 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2024-0717MEDIUMD-Link Good Line Router v2 HTTP GET Request devinfo information disclosureEPSS 18.2%CVE-2021-25122—Apache Tomcat h2c request mix-upEPSS 18.1%CVE-2024-21626HIGHrunc container breakout through process.cwd trickery and leaked fdsEPSS 18.1%CVE-2023-35636MEDIUMMicrosoft Outlook Information Disclosure VulnerabilityEPSS 17.7%CVE-2025-27225HIGHTRUfusion Enterprise through 7.10.4.0 exposes the /trufusionPortal/jsp/internal_admin_contact_login.jsp endpoint to unauthenticated users. TEPSS 17.2%CVE-2022-45925HIGHAn issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The action xmlexport accepts the parameter requestContext. IEPSS 16.9%CVE-2023-5642CRITICALAdvantech R-SeeNet Unauthenticated Read/WriteEPSS 16.7%CVE-2024-30269MEDIUMDataEase has database configuration information exposure vulnerabilityEPSS 15.9%CVE-2021-4428LOWwhat3words Autosuggest Plugin Setting class-w3w-autosuggest-public.php enqueue_scripts information disclosureEPSS 15.8%CVE-2021-32820—File disclosure in Express HandlebarsEPSS 15.7%CVE-2015-0310HIGHAdobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not pEPSS 15.1%KEVCVE-2023-28765CRITICALInformation Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Promotion Management )EPSS 14.9%CVE-2024-46987HIGHArbitrary path traversal in Camaleon CMSEPSS 14.6%CVE-2024-30571HIGHAn information leak in the BRS_top.html component of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without any auEPSS 13.8%CVE-2025-4902MEDIUMD-Link DI-7003GV2 versionupdate.data sub_48F4F0 information disclosureEPSS 13.5%CVE-2022-45124HIGHAn information disclosure vulnerability exists in the User authentication functionality of WellinTech KingHistorian 35.01.00.05. A speciallyEPSS 13.4%CVE-2024-7156MEDIUMTOTOLINK A3700R apmib Configuration ExportSettings.sh information disclosureEPSS 13.3%CVE-2020-5330HIGHDell EMC Networking X-Series firmware versions 3.0.1.2 and older, Dell EMC Networking PC5500 firmware versions 4.1.0.22 and older and Dell EEPSS 13.3%CVE-2025-4270MEDIUMTOTOLINK A720R Config cstecgi.cgi information disclosureEPSS 13.1%CVE-2023-31185HIGHROZCOM server frameworkEPSS 12.8%