Falhas do tipo CWE-200

4.898 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2023-30804MEDIUMSangfor Next-Gen Application Firewall Authenticated File DisclosureEPSS 12.8%CVE-2017-12373—A vulnerability in the TLS protocol implementation of legacy Cisco ASA 5500 Series (ASA 5505, 5510, 5520, 5540, and 5550) devices could alloEPSS 12.8%CVE-2022-46650MEDIUMAcemanager in ALEOS before version 4.16 allows a user with valid credentials to reconfigure the device to expose the ACEManager credentials EPSS 12.3%CVE-2022-20821MEDIUMCisco IOS XR Software Health Check Open Port VulnerabilityEPSS 11.5%KEVCVE-2025-60344HIGHA path traversal (directory traversal) vulnerability in D-Link DSR series routers allows unauthenticated remote attackers to manipulate inpuEPSS 10.9%CVE-2022-0281HIGHExposure of Sensitive Information to an Unauthorized Actor in microweber/microweberEPSS 10.5%CVE-2024-54188MEDIUMInfoblox NETMRI before 7.6.1 has a vulnerability allowing remote authenticated users to read arbitrary files with root access.EPSS 9.0%CVE-2024-33603MEDIUMThe LevelOne WBR-6012 router has an information disclosure vulnerability in its web application, which allows unauthenticated users to accesEPSS 8.6%CVE-2018-3646MEDIUMSystems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residEPSS 8.6%CVE-2023-34261—Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow identification of valid user accounts via username enumeration because they EPSS 8.1%CVE-2018-15964HIGHAdobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a use of a component with EPSS 7.9%CVE-2017-12163MEDIUMAn information leak flaw was found in the way SMB1 protocol was implemented by Samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.EPSS 7.6%CVE-2021-40690—Bypass of the secureValidation propertyEPSS 7.4%CVE-2026-20805MEDIUMDesktop Window Manager Information Disclosure VulnerabilityEPSS 7.2%KEVCVE-1999-0511CRITICALIP forwarding is enabled on a machine which is not a router or firewall.EPSS 7.0%CVE-2021-30638—An Information Disclosure due to insufficient input validation exists in Apache Tapestry 5.4.0 and laterEPSS 6.6%CVE-2017-15099—INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table contentEPSS 6.3%CVE-2019-1681HIGHCisco Network Convergence System 1000 Series TFTP Directory Traversal VulnerabilityEPSS 6.3%CVE-2017-6621—A vulnerability in the web interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to access senEPSS 6.2%CVE-2021-37704MEDIUMExposed phpinfo() in PhpFastCacheEPSS 6.1%