Weaknesses of type CWE-200

4,898 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2017-6645—A vulnerability in the web interface of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to accesEPSS 2.7%CVE-2017-6646—A vulnerability in the web interface of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to accesEPSS 2.7%CVE-2026-5032HIGHW3 Total Cache <= 2.9.3 - Unauthenticated Security Token Exposure via User-Agent HeaderEPSS 2.7%CVE-2014-0786—Ecava IntegraXor Information ExposureEPSS 2.6%CVE-2023-39508HIGHApache Airflow: Airflow "Run task" feature allows execution with unnecessary priviledgesEPSS 2.6%CVE-2026-39363HIGHVite Affected by Arbitrary File Read via Vite Dev Server WebSocketEPSS 2.6%CVE-2018-0288—A vulnerability in Cisco WebEx Recording Format (WRF) Player could allow an unauthenticated, remote attacker to access sensitive data about EPSS 2.6%CVE-2004-2320MEDIUMThe default configuration of BEA WebLogic Server and Express 8.1 SP2 and earlier, 7.0 SP4 and earlier, 6.1 through SP6, and 5.1 through SP13EPSS 2.6%CVE-2022-24853MEDIUMFile system exposure in MetabaseEPSS 2.5%CVE-2026-27886CRITICALStrapi may leak sensitive data via relational filtering due to lack of query sanitizationEPSS 2.5%CVE-2021-39857MEDIUMAdobe Acrobat Reader DC Information Disclosure via ActiveX LoadFileEPSS 2.5%CVE-2022-1077MEDIUMTEM FLEX-1080/FLEX-1085 Log information disclosureEPSS 2.5%CVE-2022-22547—Simple Diagnostics Agent - versions 1.0 (up to version 1.57.), allows an attacker to access information which would otherwise be restricted EPSS 2.5%CVE-2018-16876LOWansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on that can lead to leEPSS 2.5%CVE-2026-41492CRITICALUnauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars in DgraphEPSS 2.5%CVE-2022-0725—A flaw was found in keepass. The vulnerability occurs due to logging the plain text passwords in system log and leads to an Information ExpoEPSS 2.5%CVE-2023-32561HIGHA previously generated artifact by an administrator could be accessed by an attacker. The contents of this artifact could lead to authenticaEPSS 2.4%CVE-2019-7619—Elasticsearch versions 7.0.0-7.3.2 and 6.7.0-6.8.3 contain a username disclosure flaw was found in the API Key service. An unauthenticated aEPSS 2.4%CVE-2014-2347—AMTELCO miSecure Information ExposureEPSS 2.4%CVE-2024-1209MEDIUMLearnDash LMS <= 4.10.1 - Sensitive Information Exposure via assignmentsEPSS 2.4%