Falhas do tipo CWE-200

4.926 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2024-35171MEDIUMWordPress Academy LMS plugin <= 1.9.25 - Sensitive Data Exposure vulnerabilityEPSS 0.6%CVE-2024-7414MEDIUMPDF Builder for WPForms <= 1.2.116 - Unauthenticated Full Path DisclosureEPSS 0.6%CVE-2024-6562MEDIUMaffiliate-toolkit <= 3.5.5 - Unauthenticated Full Path DislcosureEPSS 0.6%CVE-2024-34388HIGHWordPress GDPR Compliance plugin <= 1.2.5 - Sensitive Data Exposure vulnerabilityEPSS 0.6%CVE-2023-39739HIGHThe leakage of the client secret in REGINA SWEETS&BAKERY Line 13.6.1 allows attackers to obtain the channel access token and send crafted brEPSS 0.6%CVE-2026-44881HIGHPortainer: Arbitrary File Read via Git Symlink Injection in Stack Auto-UpdateEPSS 0.6%CVE-2023-39736HIGHThe leakage of the client secret in Fukunaga_memberscard Line 13.6.1 allows attackers to obtain the channel access token and send crafted brEPSS 0.6%CVE-2023-39737HIGHThe leakage of the client secret in Matsuya Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messaEPSS 0.6%CVE-2023-39735HIGHThe leakage of the client secret in Uomasa_Saiji_news Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadEPSS 0.6%CVE-2022-36777MEDIUMIBM Cloud Pak for Security information disclosureEPSS 0.6%CVE-2024-0242HIGHUnauthorized access to settings in Qolsys IQ Panel 4 and IQ4 HubEPSS 0.6%CVE-2024-44152HIGHA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15. An app may be aEPSS 0.6%CVE-2023-1858MEDIUMSourceCodester Earnings and Expense Tracker App index.php information disclosureEPSS 0.6%CVE-2024-8326HIGHs2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions <= 241114 - Authenticated (Contributor+) Sensitive Information ExposureEPSS 0.6%CVE-2024-8884CRITICALCWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause exposure of credentials when attacEPSS 0.6%CVE-2025-63094HIGHXiangShan Nanhu V2 and XiangShan Kunmighu V3 were discovered to use speculative execution and indirect branch prediction, allowing attackersEPSS 0.6%CVE-2026-55870LOWGoCD is vulnerable to credential exposure when admins insecurely configure material URLsEPSS 0.6%CVE-2023-22580MEDIUMSequalize - Bad query filtering leading to SQL errorsEPSS 0.6%CVE-2022-2408MEDIUMGuest accounts can list all public channelsEPSS 0.6%CVE-2025-23387MEDIUMRancher's SAML-based login via CLI can be denied by unauthenticated usersEPSS 0.6%