Falhas do tipo CWE-200

4.927 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2026-37452HIGHInsecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via EPSS 0.5%CVE-2026-52482HIGHAn issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote attacker to obtain sensitive information via the inetd service spaEPSS 0.5%CVE-2026-71626HIGHAn issue in Invoice Ninja v5.13.24 allows a remote attacker to obtain sensitive information via the StoreWebhookRequest.php, UpdateWebhookReEPSS 0.5%CVE-2026-51078HIGHAn issue in Dede CMS v.5.7.118 allows a remote attacker to obtain sensitive information via the str parameter of the file_manage_control.phpEPSS 0.5%CVE-2024-9546MEDIUMWPIDE <= 3.4.9 - Unauthenticated Full Path DislcosureEPSS 0.5%CVE-2026-52021HIGHAn issue in code100xDevs 100xdevs CMS v.1.0 (2026-04-30) allows a remote attacker to obtain sensitive information via the src/middleware.ts,EPSS 0.5%CVE-2024-7416MEDIUMReveal Template <= 3.7 - Unauthenticated Full Path DisclosureEPSS 0.5%CVE-2021-45475MEDIUMInformation disclosure in Yordam Library Information Document Automation ProgramEPSS 0.5%CVE-2024-24825CRITICALTokenManager not checking permissions on cached tokens in DIRACEPSS 0.5%CVE-2023-6459MEDIUMPublic endpoint /metrics of Calls plugin reveals channel IDsEPSS 0.5%CVE-2026-34215HIGHParse Server: Auth data exposed via verify password endpointEPSS 0.5%CVE-2023-43041MEDIUMIBM QRadar information disclosureEPSS 0.5%CVE-2026-8028MEDIUMFlowiseAI Flowise Endpoint account.service.ts verify information disclosureEPSS 0.5%CVE-2023-23622MEDIUMDiscourse: Presence of read restricted topics may be leaked if tagged with a tag that is visible to all usersEPSS 0.5%CVE-2026-61891HIGHIn Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download endpoints (`GET /file`, `GEEPSS 0.5%CVE-2026-32631HIGHGit for Windows: `git clone` from manipulated repositories can leak NTLM hashes to arbitrary serversEPSS 0.5%CVE-2025-57437CRITICALThe Blackmagic Web Presenter HD firmware version 3.3 exposes sensitive information via an unauthenticated Telnet service on port 9977. When EPSS 0.5%CVE-2018-6559—The Linux kernel, as used in Ubuntu 18.04 LTS and Ubuntu 18.10, allows local users to obtain names of files in which they would not normallyEPSS 0.5%CVE-2026-6492MEDIUMarnobt78 Hotel Booking Management System Health Check Endpoint detailed information disclosureEPSS 0.5%CVE-2022-30737MEDIUMImplicit Intent hijacking vulnerability in Samsung Account prior to version 13.2.00.6 allows attackers to get email ID.EPSS 0.5%