Weaknesses of type CWE-200

4,939 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2024-29842HIGHBroken Access control on DESKTOP_EDIT_USER_GET_ABACARD_FIELDS in Evolution Controller allows unauthenticated attackers to retrieve ABACARD values EPSS 0.5%CVE-2026-89248MEDIUMAVideo WebRTC Plugin Information Disclosure via status.json.phpEPSS 0.5%CVE-2024-29839HIGHBroken Access control on DESKTOP_EDIT_USER_GET_CARD in Evolution Controller allows unauthenticated attackers to retrieve card data values.EPSS 0.5%CVE-2024-29841HIGHBroken Access control on DESKTOP_EDIT_USER_GET_KEYS_FIELDS in Evolution Controller allows unauthenticated attackers to retrieve keys values EPSS 0.5%CVE-2024-29840HIGHBroken Access control on DESKTOP_EDIT_USER_GET_PIN_FIELDS in Evolution Controller allows unauthenticated attackers to retrieve PIN field valuesEPSS 0.5%CVE-2024-29843HIGHBroken Access control on MOBILE_GET_USERS_LIST in Evolution Controller allows unauthenticated user enumerationEPSS 0.5%CVE-2026-67435MEDIUMlinuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirectEPSS 0.5%CVE-2026-28878MEDIUMA privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macEPSS 0.5%CVE-2023-1683MEDIUMXunrui CMS system_log.html information disclosureEPSS 0.5%CVE-2025-0472HIGHInformation exposure vulnerability in PMB platformEPSS 0.5%CVE-2026-45780MEDIUMDiscourse: Private event sample invitees are serialized to non-invited event viewersEPSS 0.5%CVE-2024-3733MEDIUMEssential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.15 - Information ExposureEPSS 0.5%CVE-2025-29089HIGHAn issue in TP-Link AX10 Ax1500 v.1.3.10 Build (20230130) allows a remote attacker to obtain sensitive informationEPSS 0.5%CVE-2026-53507HIGHoasdiff actions resolve external $refs by default, enabling SSRF and disclosure of structured files on pull-request runsEPSS 0.5%CVE-2023-24505MEDIUMMilesight NCR/Camera CWE-200: Exposure of Sensitive InformationEPSS 0.5%CVE-2026-87842HIGHZonify < 1.0.5 - Unauthenticated Account Login Token DisclosureEPSS 0.5%CVE-2024-2920MEDIUMWP-Members Membership Plugin <= 3.4.9.3 - Unprotected Storage of Potentially Sensitive FilesEPSS 0.5%CVE-2024-25121HIGHImproper Access Control Persisting File Abstraction Layer Entities via Data Handler in TYPO3EPSS 0.5%CVE-2024-2974MEDIUMEssential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.13 - Unauthenticated Sensitive Information ExposureEPSS 0.5%CVE-2026-16578HIGHAdmin Safety Guard < 1.4.0 - Unauthenticated User Data Disclosure via 2fa/app/users REST RouteEPSS 0.5%