Weaknesses of type CWE-200

4,940 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2011-4917—In the Linux kernel through 3.1 there is an information disclosure issue via /proc/stat.EPSS 0.5%CVE-2026-72915HIGHMastodon: Personally-identifying information disclosure due to incorrect access control validationEPSS 0.5%CVE-2026-19357MEDIUMMingSoft MCMS ms-mdiy get information disclosureEPSS 0.5%CVE-2026-28559MEDIUMwpForo Forum 2.4.14 Information Disclosure via Global RSS FeedEPSS 0.5%CVE-2026-9352MEDIUMNousResearch hermes-agent Messaging Gateway local.py _make_run_env information disclosureEPSS 0.5%CVE-2026-25038HIGHGitea private organization labels are visible to unauthorized usersEPSS 0.5%CVE-2026-71862HIGHCheckmate: Sensitive Bearer Token Exposure via Public Status Pages When showURL Setting is EnabledEPSS 0.5%CVE-2024-7413MEDIUMObfuscate Email <= 3.8.1 - Unauthenticated Full Path DisclosureEPSS 0.5%CVE-2026-8995MEDIUMPoll Maker by AYS <= 6.3.7 - Authenticated (Subscriber+) Sensitive Information Exposure in 'ays_poll_get_user_information' AJAX ActionEPSS 0.5%CVE-2024-0616MEDIUMPassster – Password Protect Pages and Content <= 4.2.6.2 - Missing Authorization to Sensitive Information ExposureEPSS 0.5%CVE-2022-20776MEDIUMCisco TelePresence Collaboration Endpoint and RoomOS Software VulnerabilitiesEPSS 0.5%CVE-2024-0620MEDIUMPPWP – Password Protect Pages <= 1.8.9 - Protection Mechanism BypassEPSS 0.5%CVE-2024-7410MEDIUMMy Custom CSS PHP & ADS <= 3.3 - Unauthenticated Full Path DisclosureEPSS 0.5%CVE-2024-7382MEDIUMLinkify Text <= 1.9.1 - Unauthenticated Full Path DisclosureEPSS 0.5%CVE-2024-7412MEDIUMNo Update Nag <= 1.4.12 - Unauthenticated Full Path DisclosureEPSS 0.5%CVE-2026-92947CRITICALvm2 before 3.11.7 Memory Disclosure via Buffer PoolEPSS 0.5%CVE-2026-24451HIGHGitea fork synchronization can expose private parent repository dataEPSS 0.5%CVE-2023-52187MEDIUMWordPress Image Source Control Plugin <= 2.17.0 is vulnerable to Sensitive Data ExposureEPSS 0.5%CVE-2026-40490MEDIUMAsyncHttpClient leaks authorization credentials to untrusted domains on cross-origin redirectsEPSS 0.5%CVE-2024-42657HIGHAn issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the lack of encryEPSS 0.5%