Weaknesses of type CWE-200

4,940 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2022-3501LOWInformation exposure of template content due to missing check of permissionsEPSS 0.5%CVE-2022-41944LOWDiscourse users can see notifications for topics they no longer have access toEPSS 0.5%CVE-2026-30852MEDIUMCaddy: vars_regexp double-expands user input, leaking env vars and filesEPSS 0.5%CVE-2026-58157MEDIUMApache Traffic Server: Improper server-session reuse can expose data across client connectionsEPSS 0.5%CVE-2026-73304MEDIUMBudibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role UsersEPSS 0.5%CVE-2024-12896MEDIUMIntelbras VIP S4320 G2 Web Interface webCapsConfig information disclosureEPSS 0.5%CVE-2026-28962HIGHThis issue was addressed with improved access restrictions. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iEPSS 0.5%CVE-2026-1175MEDIUMbirkir prime GraphQL Directive graphql information exposureEPSS 0.5%CVE-2024-10050MEDIUMElementor Header & Footer Builder <= 1.6.43 - Authenticated (Contributor+) Information Disclosure via ShortcodeEPSS 0.5%CVE-2026-72670HIGHExposure of Sensitive Information to an Unauthorized Actor in Kibana Leading to Disclosure of Fleet Proxy CredentialsEPSS 0.5%CVE-2020-11843MEDIUMPotential information leakage in administrator enabled debug modeEPSS 0.5%CVE-2026-53923MEDIUMvLLM GGUF Kernels: int64_t to int truncation of tensor dimensions causes GPU buffer overflowEPSS 0.5%CVE-2026-8033MEDIUMPicoTronica e-Clinic Healthcare System ECHS Response Header v2 information disclosureEPSS 0.5%CVE-2026-59155MEDIUMNezha Monitoring: DDNS and Notification credential exposure via unredacted list APIEPSS 0.5%CVE-2026-33981HIGHChangedetection.io Discloses Environment Variables via jq env Builtin in Include FiltersEPSS 0.5%CVE-2011-4917—In the Linux kernel through 3.1 there is an information disclosure issue via /proc/stat.EPSS 0.5%CVE-2026-5601MEDIUMAcrel Electrical Prepaid Cloud Platform Backup File bin.rar information disclosureEPSS 0.5%CVE-2026-86672MEDIUMningzichun Student Management System Backup example.7z information disclosureEPSS 0.5%CVE-2026-28559MEDIUMwpForo Forum 2.4.14 Information Disclosure via Global RSS FeedEPSS 0.5%CVE-2025-6980HIGHCaptive Portal can expose sensitive informationEPSS 0.5%