Falhas do tipo CWE-200

4.919 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2023-47029CRITICALAn issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via a crafted PEPSS 0.7%CVE-2023-26533MEDIUMWordPress Zippy Plugin <= 1.6.1 is vulnerable to Sensitive Data ExposureEPSS 0.7%CVE-2023-0659MEDIUMBDCOM 1704-WGL Backup File param.file.tgz information disclosureEPSS 0.7%CVE-2022-29916MEDIUMFirefox behaved slightly differently for already known resources when loading CSS resources involving CSS variables. This could have been usEPSS 0.7%CVE-2024-20019MEDIUMIn wlan driver, there is a possible memory leak due to improper input handling. This could lead to remote denial of service with no additionEPSS 0.7%CVE-2025-26795HIGHApache IoTDB JDBC driver: Exposure of Sensitive Information in IoTDB JDBC driverEPSS 0.7%CVE-2025-26864HIGHApache IoTDB: Exposure of Sensitive Information in IoTDB OpenID AuthenticationEPSS 0.7%CVE-2022-35246MEDIUMA NoSQL-Injection information disclosure vulnerability vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 in the getS3FileUrl MeteEPSS 0.7%CVE-2013-10024LOWExit Strategy Plugin exitpage.php information disclosureEPSS 0.7%CVE-2022-34329MEDIUMIBM CICS TX information disclosureEPSS 0.7%CVE-2023-29106MEDIUMA vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC716 (All versiEPSS 0.7%CVE-2023-37868MEDIUMWordPress Premium Addons PRO Plugin <= 2.9.0 is vulnerable to Sensitive Data ExposureEPSS 0.7%CVE-2023-41259—Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Disclosure via fake or spoofed RT email headers in EPSS 0.7%CVE-2019-14820MEDIUMIt was found that keycloak before version 8.0.0 exposes internal adapter endpoints in org.keycloak.constants.AdapterConstants, which can be EPSS 0.7%CVE-2024-28236HIGHInsecure Variable Substitution in VelaEPSS 0.7%CVE-2024-47532HIGHRestrictedPython information leakage via `AttributeError.obj` and the `string` moduleEPSS 0.7%CVE-2023-34093MEDIUMStrapi allows actors to make all attributes on a content-type public without noticing itEPSS 0.7%CVE-2026-41610MEDIUMVisual Studio Code Security Feature Bypass VulnerabilityEPSS 0.7%CVE-2022-26423HIGHMISSING AUTHORIZATION CWE-862EPSS 0.7%CVE-2023-35625MEDIUMAzure Machine Learning Compute Instance for SDK Users Information Disclosure VulnerabilityEPSS 0.7%