Falhas do tipo CWE-200

4.922 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2023-25057MEDIUMWordPress Libsyn Publisher Hub Plugin <= 1.3.2 is vulnerable to Sensitive Data ExposureEPSS 0.6%CVE-2026-43646HIGHApache Wicket: crafted URLs can bypass PackageResourceGuardEPSS 0.6%CVE-2022-41862LOWIn PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption.EPSS 0.6%CVE-2026-60023HIGHApache Answer: Unauthorized disclosure of deleted or pending answer contentEPSS 0.6%CVE-2025-7654HIGHMultiple Plugins By FunnelKit <= (Various Versions) - Authenticated (Contributor+) Sensitive Information Exposure to Privilege Escalation via Woofunnel LibraryEPSS 0.6%CVE-2023-42490HIGH EisBaer Scada - CWE-200: Exposure of Sensitive Information to an Unauthorized ActorEPSS 0.6%CVE-2022-46355HIGHA vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALAEPSS 0.6%CVE-2025-47969MEDIUMWindows Virtualization-Based Security (VBS) Information Disclosure VulnerabilityEPSS 0.6%CVE-2023-39053—An information leak in Hattoriya v13.6.1 allows attackers to obtain the channel access token and send crafted messages.EPSS 0.6%CVE-2023-39051—An information leak in VISION MEAT WORKS Track Diner 10/10mbl v13.6.1 allows attackers to obtain the channel access token and send crafted mEPSS 0.6%CVE-2025-22612CRITICALCoolify Vulnerable to Private Key Enumeration on Onboarding resulting in Remote Command Execution (RCE)EPSS 0.6%CVE-2023-39050—An information leak in Daiky-value.Fukueten v13.6.1 allows attackers to obtain the channel access token and send crafted messages.EPSS 0.6%CVE-2023-39048—An information leak in Tokudaya.honten v13.6.1 allows attackers to obtain the channel access token and send crafted messages.EPSS 0.6%CVE-2023-39042—An information leak in Gyouza-newhushimi v13.6.1 allows attackers to obtain the channel access token and send crafted messages.EPSS 0.6%CVE-2023-39057—An information leak in hirochanKAKIwaiting v13.6.1 allows attackers to obtain the channel access token and send crafted messages.EPSS 0.6%CVE-2024-54467MEDIUMA cookie management issue was addressed with improved state management. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS SequoiEPSS 0.6%CVE-2023-39054—An information leak in Tokudaya.ekimae_mc v13.6.1 allows attackers to obtain the channel access token and send crafted messages.EPSS 0.6%CVE-2023-25913HIGHAuthentication Bypass in Danfoss AK-SM800AEPSS 0.6%CVE-2026-54489CRITICALDell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerEPSS 0.6%CVE-2024-7697HIGHLogical vulnerability in com.transsion.carlcareEPSS 0.6%