Falhas do tipo CWE-200

4.898 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2022-2462MEDIUMTransposh WordPress Translation <= 1.0.9.6 - Sensitive Information DisclosureEPSS 3.7%CVE-2016-6548—Zizai Tech Nut mobile application makes requests using HTTP, which includes the users session tokenEPSS 3.7%CVE-2025-49741HIGHMicrosoft Edge (Chromium-based) Information Disclosure VulnerabilityEPSS 3.6%CVE-2019-5016CRITICALAn exploitable arbitrary memory read vulnerability exists in the KCodes NetUSB.ko kernel module which enables the ReadySHARE Printer functioEPSS 3.6%CVE-2018-15919MEDIUMRemotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be used by remote attackers to detect existence of users on a targEPSS 3.6%CVE-2020-8169—curl 7.62.0 through 7.70.0 is vulnerable to an information disclosure vulnerability that can lead to a partial password being leaked over thEPSS 3.5%CVE-2018-5407—Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel EPSS 3.4%CVE-2018-0425—Cisco RV110W, RV130W, and RV215W Routers Management Interface Information Disclosure VulnerabilityEPSS 3.4%CVE-2026-22240CRITICALPlaintext Passwords Vulnerability in BLUVOYIXEPSS 3.4%CVE-2017-7520—OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-service and/or possibly sensitive memory leak triggered by man-iEPSS 3.4%CVE-2014-2356—Innominate mGuard Exposure of Sensitive Information to an Unauthorized ActorEPSS 3.4%CVE-2025-59434CRITICALCritical Multi-Tenant Variable Disclosure in Flowise Cloud via Custom JavaScript FunctionEPSS 3.4%CVE-2018-0442HIGHCisco Wireless LAN Controller Software Control and Provisioning of Wireless Access Points Protocol Information Disclosure VulnerabilityEPSS 3.3%CVE-2024-50338HIGHCarriage-return character in remote URL allows malicious repository to leak credentials in Git Credential ManagerEPSS 3.2%CVE-1999-0468HIGHInternet Explorer 5.0 allows a remote server to read arbitrary files on the client's file system using the Microsoft Scriptlet Component.EPSS 3.2%CVE-2017-6752—A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) 9.3(3) and 9.6(2) could allow an unauthenticated, remoteEPSS 3.2%CVE-2025-55976HIGHIntelbras IWR 3000N 1.9.8 exposes the Wi-Fi password in plaintext via the /api/wireless endpoint. Any unauthenticated user on the local netwEPSS 3.2%CVE-2022-27775HIGHAn information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connectEPSS 3.2%CVE-2023-34092HIGHVite Server Options (server.fs.deny) can be bypassed using double forward-slash (//)EPSS 3.1%CVE-2018-10911MEDIUMA flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaEPSS 3.1%