Weaknesses of type CWE-200

4,939 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2024-6612MEDIUMCSP violation leakage when using devtoolsEPSS 0.5%CVE-2024-25130MEDIUMTuleap's mass update clears the permissions on artifact fieldEPSS 0.5%CVE-2026-2976MEDIUMFastApiAdmin Download Endpoint controller.py download_controller information disclosureEPSS 0.5%CVE-2024-7418MEDIUMThe Post Grid <= 7.7.11 - Authenticated (Contributor+) Information DisclosureEPSS 0.5%CVE-2026-75918HIGHphpMyFAQ before 4.1.7 Authentication Bypass via Tracking FileEPSS 0.5%CVE-2025-24263CRITICALA privacy issue was addressed by moving sensitive data to a protected location. This issue is fixed in macOS Sequoia 15.4. An app may be ablEPSS 0.5%CVE-2022-41946MEDIUMTemporaryFolder on unix-like systems does not limit access to created files in pgjdbcEPSS 0.5%CVE-2023-6922MEDIUMUnder Construction / Maintenance Mode from Acurax <= 2.6 - Authenticated (Subscriber+) Sensitive Information ExposureEPSS 0.5%CVE-2026-46910CRITICALVulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). SupportedEPSS 0.5%CVE-2024-28242MEDIUMDisclosure of the existence of secret categories with custom backgrounds in DiscourseEPSS 0.5%CVE-2024-2966MEDIUMElement Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.5.6 - Sensitive Information Exposure via element_pack_ajax_searchEPSS 0.5%CVE-2023-49261HIGHSensitive authentication-related value accessible publiclyEPSS 0.5%CVE-2026-32098MEDIUMParse Server has a protected fields bypass via LiveQuery subscription WHERE clauseEPSS 0.5%CVE-2024-22141MEDIUMWordPress Profile Builder Pro Plugin <= 3.10.0 is vulnerable to Sensitive Data ExposureEPSS 0.5%CVE-2024-27090MEDIUMDecidim vulnerable to data disclosure through the embed featureEPSS 0.5%CVE-2022-43930MEDIUMIBM Db2 for Linux, UNIX and Windows information disclosureEPSS 0.5%CVE-2024-6395MEDIUMGitHub Enterprise Server Information Disclosure Vulnerability Exposes Private Repository Names via Deploy KeysEPSS 0.5%CVE-2024-21624MEDIUMPotential Information Leak in User-Constructed Message Templates in nonebot2EPSS 0.5%CVE-2025-34064CRITICALOneLogin AD Connector Log S3 Bucket Hijack Leading to Cross-Tenant Data LeakageEPSS 0.5%CVE-2024-47922HIGHPriority – CWE-200: Exposure of Sensitive Information to an Unauthorized ActorEPSS 0.5%