Falhas do tipo CWE-200

4.931 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2024-10316MEDIUMStratum – Elementor Widgets <= 1.4.4 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor TemplatesEPSS 0.5%CVE-2022-2394MEDIUMSensitive Parameter Exposure in Puppet Bolt prior to 3.24EPSS 0.5%CVE-2022-22337MEDIUMIBM Sterling B2B Integrator Standard Edition information disclosureEPSS 0.5%CVE-2026-64874CRITICALJoomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extensionEPSS 0.5%CVE-2023-0020HIGHSAP BusinessObjects Business Intelligence platform - versions 420, 430, allows an authenticated attacker to access sensitive information whiEPSS 0.5%CVE-2025-62188HIGHApache DolphinScheduler: Users can access sensitive information through the actuator endpoint.EPSS 0.5%CVE-2026-45737MEDIUMArgo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotationsEPSS 0.5%CVE-2025-48808MEDIUMWindows Kernel Information Disclosure VulnerabilityEPSS 0.5%CVE-2025-23212HIGHTandoor Recipes - Local file disclosure - Users can read the content of any file on the serverEPSS 0.5%CVE-2025-12492MEDIUMUltimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.11.0 - Unauthenticated Sensitive Information ExposureEPSS 0.5%CVE-2024-2931MEDIUMWPFront User Role Editor <= 3.2.1.11184 - Limited Information ExposureEPSS 0.5%CVE-2026-54316MEDIUMClaude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetchEPSS 0.5%CVE-2024-22154HIGHWordPress SalesKing Plugin <= 1.6.15 is vulnerable to Sensitive Data ExposureEPSS 0.5%CVE-2026-33888MEDIUMApostropheCMS: publicApiProjection Bypass via `project` Query Builder in Piece-Type REST APIEPSS 0.5%CVE-2019-1645MEDIUMCisco Connected Mobile Experiences Information Disclosure VulnerabilityEPSS 0.5%CVE-2024-32086HIGHWordPress Citadela Listing plugin <= 5.18.1 - Unauth. Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2024-48797HIGHAn issue in PCS Engineering Preston Cinema (com.prestoncinema.app) 0.2.0 allows a remote attacker to obtain sensitive information via the fiEPSS 0.5%CVE-2026-30845MEDIUMWekan Exposes Sensitive Data through Lack of Field Filtering During Board PublicationEPSS 0.5%CVE-2024-48799HIGHAn issue in LOREX TECHNOLOGY INC com.lorexcorp.lorexping 1.4.22 allows a remote attacker to obtain sensitive information via the firmware upEPSS 0.5%CVE-2024-48798HIGHAn issue in Hubble Connected (com.hubbleconnected.vervelife) 2.00.81 allows a remote attacker to obtain sensitive information via the firmwaEPSS 0.5%