Falhas do tipo CWE-200

4.922 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2019-3016MEDIUMIn a Linux KVM guest that has PV TLB enabled, a process in the guest kernel may be able to read memory locations from another process in theEPSS 0.6%CVE-2023-22847MEDIUMInformation disclosure vulnerability exists in pg_ivm versions prior to 1.5.1. An Incrementally Maintainable Materialized View (IMMV) createEPSS 0.6%CVE-2026-9289MEDIUMWordLift <= 3.54.10 - Unauthenticated Sensitive Information Exposure in JSON-LD REST API EndpointsEPSS 0.6%CVE-2023-27894MEDIUMSensitive Information Disclosure in the SAP BusinessObjects Business Intelligence platformEPSS 0.6%CVE-2025-23173HIGHThe Versa Director SD-WAN orchestration platform provides direct web-based access to uCPE virtual machines through the Director GUI. By defaEPSS 0.6%CVE-2024-10285CRITICALCE21 Suite <= 2.2.0 - JWT Token DisclosureEPSS 0.6%CVE-2024-13110MEDIUMBeijing Yunfan Internet Technology Yunfan Learning Examination System Exam Answer PaperController.java, information disclosureEPSS 0.6%CVE-2014-125102MEDIUMBestwebsoft Relevant Plugin Thumbnail information disclosureEPSS 0.6%CVE-2021-25649MEDIUMAvaya Utility Services Sensitive Information Disclosure VulnerabilityEPSS 0.6%CVE-2023-2792MEDIUMEphemeral messages return private channel contents in permalink previewsEPSS 0.6%CVE-2023-36507MEDIUMWordPress BookingPress Plugin <= 1.0.64 is vulnerable to Sensitive Data ExposureEPSS 0.6%CVE-2026-51027CRITICALAn issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the ft2.php component.EPSS 0.6%CVE-2022-31046MEDIUMInformation Disclosure via Export Module in TYPO3 CMSEPSS 0.6%CVE-2023-40002MEDIUMWordPress Booster for WooCommerce Plugin <= 7.1.1 is vulnerable to Sensitive Data ExposureEPSS 0.6%CVE-2026-31909HIGHApache OFBiz: Unauthenticated Shipment Label Image DisclosureEPSS 0.6%CVE-2023-30993MEDIUMIBM Cloud Pak for Security information disclosureEPSS 0.6%CVE-2026-70478CRITICALFlowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected serviceEPSS 0.6%CVE-2026-72548HIGHOpenSignLabs OpenSign - Information DisclosureEPSS 0.6%CVE-2024-11265MEDIUMWp Maximum Upload File Size <= 1.1.3 - Authenticated (Author+) Full Path DisclosureEPSS 0.6%CVE-2023-6214HIGHHT Mega – Absolute Addons For Elementor <= 2.4.6 - Sensitive Information Exposure via purchased_productsEPSS 0.6%